
Director, Privacy
Posted 17 hours ago

Posted 17 hours ago
This is a fully remote position, open to applicants in Ohio, +1 more state.
• Oversee the roadmap, priorities, and maturity strategy for the enterprise privacy program.
• Facilitate scalable governance processes that promote privacy-by-design throughout the organization.
• Continuously enhance Cengage’s coordinated, risk-based enterprise privacy program.
• Implement and optimize the privacy management platform utilized by the company.
• Offer practical privacy mentorship and convert regulatory requirements into scalable business processes.
• Collaborate with Technology, Cybersecurity, Product, Sales, Government Affairs, Legal, Contract Management, and Commercial Legal teams.
• Ensure that technical controls are in alignment with privacy governance requirements and integrate privacy-by-design into roadmaps, systems, and products.
• Interpret privacy regulations and legal guidance into actionable technical requirements for both technical and non-technical stakeholders.
• Evaluate privacy risks and execute mitigation measures and controls.
• Track legislative developments, assess their business impact, and assist in advocacy efforts.
• Develop and maintain contractual language related to privacy and provide necessary training.
• Support the assessment, investigation, and response to cybersecurity, data privacy, and information security incidents.
• Act as the primary Privacy and Legal contact for relevant legal, regulatory, contractual, and notification responsibilities.
• Lead privacy impact assessments and data protection impact assessments.
• Maintain Records of Processing Activities (RoPA).
• Aid in privacy-by-design, risk assessment, compliance, data retention, data mapping, and governance of third-party privacy.
• Provide leadership in privacy for AI governance, responsible data usage, and initiatives involving emerging technologies.
• Bachelor's degree or equivalent experience.
• Over 10 years of experience leading privacy, compliance, governance, or related enterprise programs.
• Practical knowledge of GDPR, CCPA/CPRA, U.S. state privacy laws, and other relevant privacy regulations.
• Understanding of student privacy requirements, including FERPA.
• Proven experience in building and managing enterprise privacy programs.
• Strong skills in cross-functional leadership, program management, and communication.
• Ability to convert regulatory requirements into actionable business processes and evaluate technical solutions.
• Preferred: experience in education, publishing, SaaS, or technology sectors.
• Preferred: knowledge of international privacy regulations, especially in Canada, Mexico, Brazil, the EU, China, India, and Australia.
• Preferred: CIPP/US, CIPP/E, CIPM, or similar certification.
• Preferred: experience in implementing or leading a privacy management platform such as Transcend.io or MineOS.
• Discretionary incentive bonus program with a 25% annual individual target.
• Comprehensive Total Rewards package.
• Reasonable accommodations for qualified individuals with disabilities, including during the job application process.
Unitarian Universalist Association
Health Plans, Inc.
Novo Nordisk
Get handpicked remote jobs straight to your inbox weekly.