VP Privacy Compliance
Jersey, NJ - USA
Department:
Job Summary
As a Vice President in the Compliance Conduct and Operational Risk (CCOR) Data & AI team you will be part of an innovative and talented team providing second line oversight and challenge of the Firmwide Privacy Office. This role reports to the CCOR Global Privacy & Data Use Lead and is part of a team of SMEs that provides firmwide second line privacy and data use risk coverage driving compliance and operational risk management at scale.
This position requires deep subject matter expertise in privacy and experience advising stakeholders and counterparts on the implementation and governance of key privacy laws rules regulations and principles. The role provides vertical coverage andhorizontal support on the most material complex and novel privacy risk matters across the firms Lines of Business Corporate Functions and Regionally-aligned CCOR teams to supply comprehensive independent 2LOD advice and oversight of 1LOD business and functional activities.
Job Responsibilities:
- Provide independent 2LOD oversight and credible challenge of 1LOD privacy risk management activities including incident management PIAs control design/testing governing documentation and issue identification/remediation.
- Conduct risk-based coverage and thematic reviews of 1LOD privacy processes and controls; document observations challenges and required corrective actions through established issue and action-plan governance.
- Define and monitor risk metrics (KRIs and KPIs) and deliver clear metrics-driven reporting and timely escalation to senior management on material privacy risks control gaps incidents emerging themes and overdue remediation actions.
- Develop and maintain 2LOD privacy compliance policies; review and challenge 1LOD standards and procedures for alignment and effective operationalization.
- Monitor the regulatory environment and independently assess impact of new/changed privacy requirements; challenge 1LOD implementation plans and control updates and track remediation to completion.
- Assess and challenge privacy risk impacts from emerging internal/external drivers including material process changes significant incidents/events third-party/vendor changes and new products/data uses.
- Provide 2LOD oversight and credible challenge for emerging-technology use cases impacting personal data (including AI/ML); ensure evolving regulatory expectations and minimum control requirements are embedded into delivery and ongoing monitoring.
- Support privacy-related regulatory exams and supervisory engagements by coordinating and reviewing responses/submissions and providing independent risk perspective on remediation commitments.
- Advise on develop and deliver privacy training and awareness; identify training needs define content expectations and target audiences create/update course materials partner with stakeholders to address gaps and drive continuous improvement.
- Provide high-value practical independent risk advice and credible challenge to the Firmwide Privacy Office CCOR leadership and key stakeholders on complex material and novel privacy risk matters.
Sustained delivery of impact in the above duties will result in development of important skills and create opportunities for career progression and promotion.
Required qualifications capabilities and skills
5 years of experience in privacy compliance/risk data risk management or audit.
Experience in the Financial Services Sector developing and maintaining privacy- and/or data-related policies/standards/procedures control expectations training/awareness materials management reporting and regulator-facing documentation.
Knowledge of key privacy laws and regulatory expectations (e.g. GDPR GLBA CCPA) and ability to monitor and assess emerging requirements impacting data use and AI.
Demonstrated ability to work independently and manage relationships across businesses functions and regions including technology product data governance and risk stakeholders.
- Excellent analytical problem-solving and communication skills including the ability to synthesize complex topics (privacy technology risk) into clear executive-level messages.
- Demonstrated intellectual curiosity capability to learn quickly and ability to prioritize and manage multiple competing demands across a global business.
- Experience with or demonstrated ability to learn risk management principles and techniques includingproviding oversight and credible challenge to assessments of risk and control environments and second line of defense coverage activities.
Highly motivated energetic self-starter who takes ownership and manages deliverables with a strong attention to detail and completes deliverables in a timely manner.
Required Experience:
Exec
About Company
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world’s most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans ov ... View more