
University Privacy Officer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Alabama, +31 more states.
• Lead the creation, governance, and ongoing enhancement of a scalable, risk-oriented university privacy program.
• Chair Privacy Committee(s) and engage in cross-functional working groups.
• Develop, maintain, and oversee the implementation of privacy policies, standards, procedures, and communication strategies.
• Integrate privacy oversight into compliance, audit, and risk management processes.
• Prepare annual reports on the privacy program for senior leadership.
• Direct and enhance privacy risk assessments, including Data Protection Impact Assessments (DPIAs) and enterprise-wide evaluations.
• Identify risk mitigation strategies in collaboration with the Information Security Management Office and other stakeholders.
• Evaluate the effectiveness and maturity of the privacy program and support remediation and continuous improvement efforts.
• Oversee third-party privacy assessments, audits, and remediation activities.
• Assist in cyber insurance review and selection processes.
• Monitor developments in privacy-related regulations and translate requirements into actionable institutional practices.
• Collaborate with Legal, Compliance, and Information Security teams.
• Support privacy incident response by coordinating with ISMO, Legal, and other stakeholders.
• Develop processes for identifying, managing, escalating, and resolving privacy issues and incidents.
• Design, implement, and maintain privacy training and awareness initiatives.
• Act as the University's privacy subject matter expert, providing guidance on privacy requirements, data usage, analytics, emerging technologies, and institutional initiatives.
• Bachelor's Degree.
• 10 years of experience in privacy, compliance, risk management, or a related field.
• Relevant privacy-related professional certifications such as CIPP/US, CIPM, CIPT, or similar.
• Proven experience in building or significantly contributing to privacy or compliance programs.
• Strong understanding of U.S. privacy laws and regulations, including FERPA, GLBA, and HIPAA.
• Familiarity with global privacy frameworks, such as GDPR, UK GDPR, DPDPA, PIPL, and PIPEDA.
• Experience working in complex, decentralized organizations of considerable scale.
• Experience handling large volumes of personal data, multi-state or multi-jurisdictional regulatory obligations, or enterprise-wide technology platforms is highly preferred.
• Demonstrated analytical and problem-solving abilities.
• Sound ethical judgment and discretion with sensitive information.
• Skills in collaboration, adaptability, initiative, diplomacy, and practical learning agility.
• Must reside in and work from one of the approved states.
• Reliable internet connection and a dedicated, appropriately equipped workspace free of distractions.
• High-quality, low-deductible medical insurance.
• Low to no-cost dental and vision plans.
• 5 weeks of paid time off.
• Nearly a dozen paid holidays.
• Employer-funded retirement plan.
• Free tuition program.
• Parental leave.
• Mental health and wellbeing resources.
• Remote work option available in approved states.
• Requirement for a dedicated, properly equipped distraction-free workspace for remote employees.
Behavioral Health Works, Inc.
Sodexo
Sodexo
EVERSANA
Get handpicked remote jobs straight to your inbox weekly.