Lead data privacy and security assessments for systems managing PII, evaluate controls, identify gaps, and prepare detailed reports to ensure compliance with privacy laws.
Job Description SummaryGE is seeking a qualified professional with expertise in data privacy regulations to support global compliance initiatives. This role involves leading and conducting data privacy risk assessments, security assessments and information security audits across systems processing personally identifiable information (PII), using established frameworks to evaluate privacy and security controls, identify gaps, and prepare detailed assessment reports. The candidate will work closely with business teams to address and remediate issues, ensuring compliance with international and emerging privacy laws such as GDPR, HIPAA, DPDP, and LGPD.Job Description
Roles and Responsibilities:
- Lead and perform data privacy assessments for systems managing personally identifiable information.
- Evaluate the design and operational effectiveness of privacy / security controls by partnering with control owners and stakeholders.
- Identify control deficiencies, support remediation efforts through resolution, and report non-conformances in a timely manner.
- Prepare and deliver comprehensive summary reports for each data privacy / security assessment or review.
- Align all activities with the Unified Control Framework (UCF) to maintain consistency and compliance across processes.
- Maintain clear and proactive communication with application teams regarding assessment scope, expectations, and timelines.
- Drive initiatives to improve processes and enhance efficiency through automation and streamlined controls.
- Educate project teams on privacy regulations and related IT control requirements to promote awareness and ensure regulatory compliance.
- Establish operating rhythm to report out on key metrics including status of assessments and issue management.
- Ensure audit readiness, provide audit support, and manage audit-related activities to facilitate successful outcomes.
Qualifications & Skills:
- Bachelor’s degree in information security, Computer Science, Information Technology, Law, or a related field.
- Some years of experience in data privacy, information security, IT audit, compliance, or risk management.
- Strong knowledge of global data privacy laws and frameworks (e.g., GDPR, LGPD, DPDP) and U.S. health data regulations (HIPAA).
- Solid understanding of the concept of personally identifiable information (PII) and its protection requirements.
- Familiarity with IT security concepts, IT controls: including access management, infrastructure, encryption, and cybersecurity practices.
- Ability to identify appropriate testing procedures and assess the effectiveness of technology and privacy controls.
- Strong communication skills with the ability to explain complex issues to both technical and non-technical audiences, including engineering, legal, and project teams, focusing on risk and impact.
- Critical thinking and analytical skills to interpret data, identify trends, and assess privacy risks.
- Self-driven with the ability to independently plan and manage assessment schedules.
- Proficiency in English, both written and verbal.
Desired Characteristics
- Internationally recognized information security/information system audit certification/qualifications such as CISA, CISM, CISSP or CIA (IAPP)
- Experience with GRC tools (e.g., Archer, ServiceNow GRC).
- Experience conducting risk assessments, identifying gaps, and recommending mitigation strategies.
- Experience supporting audits and managing audit readiness activities.
Relocation Assistance Provided: No
Top Skills
Archer
Dpdp
Gdpr
Grc Tools
Hipaa
Lgpd
Servicenow Grc
Similar Jobs
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Portfolio Manager will shape and scale ServiceNow Impact accelerators, driving customer success through strategic thought leadership and innovation in digital transformation.
Top Skills:
Agile MethodologiesAICmdbCRMCsdmItomItsmMlServicenow
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Client Director will manage relationships with key clients, lead virtual teams, drive strategic sales initiatives, and ensure client satisfaction to achieve financial targets.
Top Skills:
AICustomer ServiceIt Operations ManagementIt Service ManagementSecurity Operations
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
The Senior Director will lead teams in developing and evaluating machine learning models, focusing on innovation and collaboration across functions to enhance AI capabilities.
Top Skills:
AIDeep LearningMachine LearningPyTorchTensorFlow
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories