
Technical Privacy Specialist
Posted 9 hours ago

Posted 9 hours ago
This is a fully remote position, open to applicants in Colombia.
• Lead the privacy and personal data protection program of Bold in Colombia and Peru from the Information Security team.
• Define the strategy, roadmap, and operational model of the privacy program, including objectives, responsibilities, metrics, risks, and delivery timelines.
• Manage a portfolio of cross-cutting initiatives, overseeing scope, milestones, dependencies, and remediation plans.
• Communicate progress and decisions to technical and business leaders.
• Maintain the inventory of personal data, flow maps, RNBD in Colombia, and applicable records in Peru.
• Integrate privacy by design and by default into products, applications, integrations, payment flows, and registration processes.
• Lead PIA and DPIA assessments for products, treatments, vendors, international transfers, and AI use cases.
• Define classification, minimization, retention, deletion, anonymization, encryption, logging, and access controls in collaboration with Legal, Engineering, and Security.
• Coordinate requests and claims from data subjects, including ARCO rights, PQR, and deletion requests.
• Oversee the privacy response to incidents and data breaches.
• Maintain policies, notices, authorizations, standards, and data treatment guidelines.
• Address audits and requirements from SIC, SFC, and equivalent authorities; prepare evidence and follow up on findings.
• Support PCI DSS, ISO 27001, ISO 27701, and SOC 2 frameworks.
• Design training, guides, and support mechanisms.
• Utilize automation and responsible AI to enhance inventories, assessments, evidence, monitoring, and reporting.
• Formalize and follow up on data treatment contracts with processors, verifying scope, international transfers, subcontracting, and final data destinations.
• At least 5 years of experience in privacy, data protection, GRC, information security, or technology compliance.
• Management of complex programs with scope, roadmap, risks, dependencies, milestones, and executive reporting.
• Practical knowledge of the applicable data protection regime in Colombia and Peru, including Law 1581 of 2012 and Law No. 29733 along with their current regulatory provisions.
• Experience with data inventories, RoPA, PIA and DPIA, data subject rights, privacy by design, incident management, and remediation plans.
• Technical competence to discuss data flows, APIs, cloud services, data architectures, identity and access, encryption, logging, retention, and deletion with Engineering and Security.
• Software development is not required.
• Ability to translate legal or regulatory requirements into clear controls and tasks.
• Excellent interpersonal skills, influence without formal authority, rigorous organization, continuous follow-up, and autonomy.
• Sound judgment for designing controls proportional to risk and operational burden.
• Professional education or equivalent experience in technology, security, risk management, privacy, or related areas.
• A plus: experience in fintech, payments, financial services, or high data volume environments.
• A plus: experience with audits, authority requirements, and programs related to PCI DSS, ISO 27001, ISO 27701, or SOC 2.
• A plus: experience with privacy tools, GRC platforms, flow automation, or responsible AI governance.
• Advanced English will be a plus.
• Certifications such as CIPM, CIPP, CIPT, ISO 27701, PMP, or equivalents will be a plus.
• Indefinite-term contract.
• Full-time remote work.
• Health insurance/benefit.
• Annual bonus for achieving business objectives (equity or cash).
• Competitive salary.
• Financial support for education.
• World-class technologies and processes.
• Additional days off beyond vacation.
• Visual health bonus.
• Emotional well-being support.
Behavioral Health Works, Inc.
Sodexo
Sodexo
EVERSANA
Get handpicked remote jobs straight to your inbox weekly.