Create and manage CrossCountry’s privacy management program
Partner with Cybersecurity and Technology to define data management framework, policies, and procedures
Monitor and track global and domestic privacy regulations (e.g., GDPR, CPRA) and assess applicability
Create, update, and maintain internal privacy policies and external privacy notices
Lead and coordinate Privacy Risk Assessments, PIAs, and DPIAs; respond to Data Subject Requests (DSRs)
Own privacy recordkeeping such as Records of Processing Activities (ROPA); develop retention, minimization, and destruction workflows
Plan and execute privacy audits and remediation; develop privacy reporting dashboard with KPIs
Establish and maintain third-party risk management framework; conduct vendor due diligence, classification, continuous monitoring, and contractual review
Serve as primary liaison for privacy matters and deliver firm-wide privacy training and awareness
Requirements
8+ years of experience managing or consulting on privacy, data protection, or third-party risk management programs or serving on a privacy operational role
At least one privacy certification such as CIPP/US, CIPP/EU, CIPM, CIPT, or CDPSE required
Extensive and working knowledge of global privacy and regulatory frameworks, including GDPR and CPRA
Proficiency of the components of a comprehensive privacy program, including governance, privacy principles, awareness and training, third party risk management, consent management, etc.
Experience with privacy risk assessment, audits, and privacy-related tools and applications
Ability to lead and work as part of a team
Polished verbal and written communication skills
Excellent organization, time, and project management skills
Professionalism and discretion in interacting with executives and clients
Strong attention to detail
A great sense of humor and passionate about privacy