Lead data privacy and security assessments for systems managing PII, evaluate controls, identify gaps, and prepare detailed reports to ensure compliance with privacy laws.
Job Description SummaryGE is seeking a qualified professional with expertise in data privacy regulations to support global compliance initiatives. This role involves leading and conducting data privacy risk assessments, security assessments and information security audits across systems processing personally identifiable information (PII), using established frameworks to evaluate privacy and security controls, identify gaps, and prepare detailed assessment reports. The candidate will work closely with business teams to address and remediate issues, ensuring compliance with international and emerging privacy laws such as GDPR, HIPAA, DPDP, and LGPD.Job Description
Roles and Responsibilities:
- Lead and perform data privacy assessments for systems managing personally identifiable information.
- Evaluate the design and operational effectiveness of privacy / security controls by partnering with control owners and stakeholders.
- Identify control deficiencies, support remediation efforts through resolution, and report non-conformances in a timely manner.
- Prepare and deliver comprehensive summary reports for each data privacy / security assessment or review.
- Align all activities with the Unified Control Framework (UCF) to maintain consistency and compliance across processes.
- Maintain clear and proactive communication with application teams regarding assessment scope, expectations, and timelines.
- Drive initiatives to improve processes and enhance efficiency through automation and streamlined controls.
- Educate project teams on privacy regulations and related IT control requirements to promote awareness and ensure regulatory compliance.
- Establish operating rhythm to report out on key metrics including status of assessments and issue management.
- Ensure audit readiness, provide audit support, and manage audit-related activities to facilitate successful outcomes.
Qualifications & Skills:
- Bachelor’s degree in information security, Computer Science, Information Technology, Law, or a related field.
- Some years of experience in data privacy, information security, IT audit, compliance, or risk management.
- Strong knowledge of global data privacy laws and frameworks (e.g., GDPR, LGPD, DPDP) and U.S. health data regulations (HIPAA).
- Solid understanding of the concept of personally identifiable information (PII) and its protection requirements.
- Familiarity with IT security concepts, IT controls: including access management, infrastructure, encryption, and cybersecurity practices.
- Ability to identify appropriate testing procedures and assess the effectiveness of technology and privacy controls.
- Strong communication skills with the ability to explain complex issues to both technical and non-technical audiences, including engineering, legal, and project teams, focusing on risk and impact.
- Critical thinking and analytical skills to interpret data, identify trends, and assess privacy risks.
- Self-driven with the ability to independently plan and manage assessment schedules.
- Proficiency in English, both written and verbal.
Desired Characteristics
- Internationally recognized information security/information system audit certification/qualifications such as CISA, CISM, CISSP or CIA (IAPP)
- Experience with GRC tools (e.g., Archer, ServiceNow GRC).
- Experience conducting risk assessments, identifying gaps, and recommending mitigation strategies.
- Experience supporting audits and managing audit readiness activities.
Relocation Assistance Provided: No
Top Skills
Archer
Dpdp
Gdpr
Grc Tools
Hipaa
Lgpd
Servicenow Grc
Similar Jobs
Consumer Web • Digital Media • Edtech • Information Technology • Social Impact • Software
The Data Analyst will analyze data to identify growth opportunities, inform product strategy, and collaborate with cross-functional teams.
Top Skills:
AirbyteDbtExcelGoogle SheetsModePythonRRedshiftSQL
HR Tech • Information Technology • Software
Manage US payroll functions, support compensation strategies, including payroll processing, salary adjustments, and compliance audits. Collaborate with HR for accurate employee compensation management.
Top Skills:
AdpNetSuitePaychexRippling
Fintech • HR Tech
The Staff Product Designer will shape Gusto's top-of-funnel experience, driving design strategy, crafting user experiences, and collaborating with teams to optimize customer engagement.
Top Skills:
Cms
What you need to know about the Boston Tech Scene
Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.
Key Facts About Boston Tech
- Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
- Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
- Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
- Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories