Lead - Governance, Risk & Compliance
TEPHRA
Description:
Location: San Francisco, CA Responsibilities: 1. Develop Data Privacy and Ethics Strategies:
•Lead the development, implementation, and enforcement of data privacy and ethics compliance strategies across the organization.
•Align the company's operations with global data protection regulations (e.g., GDPR, CCPA, HIPAA, etc.) and ethical standards.
•Design and update policies to reflect changes in data protection laws, ethical best practices, and emerging risks in the industry.
2. Regulatory Compliance:
•Ensure that the organization's data handling, storage, processing, and sharing practices comply with relevant local and international data protection laws and regulations.
•Monitor and analyze changes in data privacy regulations and assist in adapting the organization's practices to remain compliant.
•Oversee the company's compliance with privacy rights, including handling data subject requests (e.g., access, correction, deletion requests).
•Conduct regular audits and assessments to identify potential compliance gaps and implement corrective actions.
3. Risk Management and Mitigation:
•Identify and assess data privacy risks across all business units, including internal and third-party data processing practices.
•Develop and implement risk mitigation strategies for handling sensitive information and personal data.
•Collaborate with the security team to ensure data protection measures are in place and effective.
4. Privacy Impact Assessments (PIAs) & Data Protection Impact Assessments (DPIAs):
•Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to evaluate the potential impact of new projects, systems, or processes on data privacy.
•Provide recommendations on how to minimize risks to personal data during the development of new products or services.
5. Internal Training and Awareness:
•Develop and deliver training programs to raise awareness of data privacy policies, ethics standards, and compliance requirements across the organization.
•Provide guidance to employees on the ethical handling of data, promoting a culture of compliance and responsibility.
•Foster awareness of the organization's ethical standards, ensuring employees understand the importance of data privacy in day-to-day operations.
6. Policy and Documentation:
•Create, maintain, and update data privacy and ethics policies, ensuring they meet legal requirements and are easily accessible to relevant stakeholders.
•Ensure clear documentation of data processing activities, including data collection, sharing, storage, and retention practices.
•Regularly review and revise policies to ensure they reflect best practices and align with current regulations.
7. Third-Party and Vendor Management:
•Ensure that third-party vendors, partners, and service providers adhere to the organization's data privacy and ethical standards.
•Conduct regular audits of third-party contracts, ensuring data privacy clauses are present and being followed.
•Negotiate and implement data protection agreements with third-party vendors and ensure that adequate safeguards are in place when transferring data.
8. Incident Management and Breach Reporting:
•Respond to data privacy incidents, breaches, or violations by leading investigations, reporting findings, and implementing corrective actions.
•Ensure compliance with breach notification requirements, including timely reporting to regulators and affected individuals when necessary.
•Work with legal and security teams to develop and implement incident response plans specific to data privacy breaches.
9. Stakeholder Communication:
•Act as the main point of contact for all data privacy-related issues within the organization, including communication with executives, employees, regulators, and external stakeholders.
•Prepare and present regular reports on compliance status, data privacy incidents, and strategic initiatives to senior leadership.
10. Ethical Business Practices:
•Advocate for and ensure that ethical considerations are integrated into business practices, particularly with regards to data usage, privacy, and security.
•Review the organization's operations and initiatives to ensure they align with corporate social responsibility (CSR) goals and ethical standards.
•Ensure the organization's use of data aligns with its stated values and commitment to protecting individuals' privacy rights.
11. Stay Informed and Up-to-Date:
•Keep up to date with evolving data privacy laws, regulations, and ethical standards to ensure ongoing compliance.
Participate in industry groups, attend conferences, and maintain professional certifications to stay ahead of trends and challenges in data privacy and ethics. Requirements: - *Minimum of 10 years of total experience 1.Educational Background:
Bachelor's or Master's degree in Law, Information Security, Business Administration, or a related field.
Certification in data privacy (e.g., CIPP, CIPM, or equivalent) or legal qualifications related to compliance (e.g., JD, LLM). 2.Technical Skills:
•In-depth knowledge of data privacy laws and regulations, including GDPR, CCPA, HIPAA, and other global data protection regulations.
•Experience with privacy and compliance tools, risk management platforms, and privacy impact assessments.
•Familiarity with security technologies and practices used in data protection (encryption, access controls, etc.).
•Understanding of ethical frameworks in business operations, including corporate social responsibility (CSR) and sustainability goals.
•Strong understanding of corporate ethics standards, data ethics, and the importance of responsible data handling.
•Knowledge of ethical AI and the implications of data usage in machine learning and AI models 3.Soft Skills:
•Excellent communication skills, both written and verbal, to clearly explain complex privacy concepts to both technical and non-technical stakeholders.
•Strong analytical and problem-solving skills to evaluate risks and create practical solutions
•Ability to manage sensitive and confidential information while maintaining the highest ethical standards.
•Strong organizational and project management skills, with the ability to manage multiple compliance initiatives and tasks simultaneously.
•Leadership and the ability to influence others to adopt a data privacy culture. 4.Experience:
•10+ years of experience in data privacy, compliance, legal, or ethics roles, ideally within a technology, finance, healthcare, or large enterprise environment.
•Experience with data protection frameworks, audits, and certifications (e.g., ISO 27001, SOC 2).
•Familiarity with data management and security best practices.
•Experience working in a cross-functional environment and interacting with various departments, including IT, legal, security, and operations 5.Preferred Qualifications:
•Experience with managing data privacy in a multi-jurisdictional, international environment.
•Expertise in handling data privacy in emerging technologies like AI, IoT, and blockchain.
•Certification or membership in professional organizations such as the International Association of Privacy Professionals (IAPP).
•Knowledge of privacy-enhancing technologies (PETs) and their application in data protection. 6.Work Environment:
•Collaborative and fast-paced work environment.
•Opportunity to work with state-of-the-art technologies.
•Supportive and dynamic team culture #LI-AD1
Location: San Francisco, CA Responsibilities: 1. Develop Data Privacy and Ethics Strategies:
•Lead the development, implementation, and enforcement of data privacy and ethics compliance strategies across the organization.
•Align the company's operations with global data protection regulations (e.g., GDPR, CCPA, HIPAA, etc.) and ethical standards.
•Design and update policies to reflect changes in data protection laws, ethical best practices, and emerging risks in the industry.
2. Regulatory Compliance:
•Ensure that the organization's data handling, storage, processing, and sharing practices comply with relevant local and international data protection laws and regulations.
•Monitor and analyze changes in data privacy regulations and assist in adapting the organization's practices to remain compliant.
•Oversee the company's compliance with privacy rights, including handling data subject requests (e.g., access, correction, deletion requests).
•Conduct regular audits and assessments to identify potential compliance gaps and implement corrective actions.
3. Risk Management and Mitigation:
•Identify and assess data privacy risks across all business units, including internal and third-party data processing practices.
•Develop and implement risk mitigation strategies for handling sensitive information and personal data.
•Collaborate with the security team to ensure data protection measures are in place and effective.
4. Privacy Impact Assessments (PIAs) & Data Protection Impact Assessments (DPIAs):
•Conduct Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) to evaluate the potential impact of new projects, systems, or processes on data privacy.
•Provide recommendations on how to minimize risks to personal data during the development of new products or services.
5. Internal Training and Awareness:
•Develop and deliver training programs to raise awareness of data privacy policies, ethics standards, and compliance requirements across the organization.
•Provide guidance to employees on the ethical handling of data, promoting a culture of compliance and responsibility.
•Foster awareness of the organization's ethical standards, ensuring employees understand the importance of data privacy in day-to-day operations.
6. Policy and Documentation:
•Create, maintain, and update data privacy and ethics policies, ensuring they meet legal requirements and are easily accessible to relevant stakeholders.
•Ensure clear documentation of data processing activities, including data collection, sharing, storage, and retention practices.
•Regularly review and revise policies to ensure they reflect best practices and align with current regulations.
7. Third-Party and Vendor Management:
•Ensure that third-party vendors, partners, and service providers adhere to the organization's data privacy and ethical standards.
•Conduct regular audits of third-party contracts, ensuring data privacy clauses are present and being followed.
•Negotiate and implement data protection agreements with third-party vendors and ensure that adequate safeguards are in place when transferring data.
8. Incident Management and Breach Reporting:
•Respond to data privacy incidents, breaches, or violations by leading investigations, reporting findings, and implementing corrective actions.
•Ensure compliance with breach notification requirements, including timely reporting to regulators and affected individuals when necessary.
•Work with legal and security teams to develop and implement incident response plans specific to data privacy breaches.
9. Stakeholder Communication:
•Act as the main point of contact for all data privacy-related issues within the organization, including communication with executives, employees, regulators, and external stakeholders.
•Prepare and present regular reports on compliance status, data privacy incidents, and strategic initiatives to senior leadership.
10. Ethical Business Practices:
•Advocate for and ensure that ethical considerations are integrated into business practices, particularly with regards to data usage, privacy, and security.
•Review the organization's operations and initiatives to ensure they align with corporate social responsibility (CSR) goals and ethical standards.
•Ensure the organization's use of data aligns with its stated values and commitment to protecting individuals' privacy rights.
11. Stay Informed and Up-to-Date:
•Keep up to date with evolving data privacy laws, regulations, and ethical standards to ensure ongoing compliance.
Participate in industry groups, attend conferences, and maintain professional certifications to stay ahead of trends and challenges in data privacy and ethics. Requirements: - *Minimum of 10 years of total experience 1.Educational Background:
Bachelor's or Master's degree in Law, Information Security, Business Administration, or a related field.
Certification in data privacy (e.g., CIPP, CIPM, or equivalent) or legal qualifications related to compliance (e.g., JD, LLM). 2.Technical Skills:
•In-depth knowledge of data privacy laws and regulations, including GDPR, CCPA, HIPAA, and other global data protection regulations.
•Experience with privacy and compliance tools, risk management platforms, and privacy impact assessments.
•Familiarity with security technologies and practices used in data protection (encryption, access controls, etc.).
•Understanding of ethical frameworks in business operations, including corporate social responsibility (CSR) and sustainability goals.
•Strong understanding of corporate ethics standards, data ethics, and the importance of responsible data handling.
•Knowledge of ethical AI and the implications of data usage in machine learning and AI models 3.Soft Skills:
•Excellent communication skills, both written and verbal, to clearly explain complex privacy concepts to both technical and non-technical stakeholders.
•Strong analytical and problem-solving skills to evaluate risks and create practical solutions
•Ability to manage sensitive and confidential information while maintaining the highest ethical standards.
•Strong organizational and project management skills, with the ability to manage multiple compliance initiatives and tasks simultaneously.
•Leadership and the ability to influence others to adopt a data privacy culture. 4.Experience:
•10+ years of experience in data privacy, compliance, legal, or ethics roles, ideally within a technology, finance, healthcare, or large enterprise environment.
•Experience with data protection frameworks, audits, and certifications (e.g., ISO 27001, SOC 2).
•Familiarity with data management and security best practices.
•Experience working in a cross-functional environment and interacting with various departments, including IT, legal, security, and operations 5.Preferred Qualifications:
•Experience with managing data privacy in a multi-jurisdictional, international environment.
•Expertise in handling data privacy in emerging technologies like AI, IoT, and blockchain.
•Certification or membership in professional organizations such as the International Association of Privacy Professionals (IAPP).
•Knowledge of privacy-enhancing technologies (PETs) and their application in data protection. 6.Work Environment:
•Collaborative and fast-paced work environment.
•Opportunity to work with state-of-the-art technologies.
•Supportive and dynamic team culture #LI-AD1
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Lead - Governance, Risk & Compliance in San Francisco, CA vacancy
- Brain Co. in San Francisco is seeking a GRC Lead to own the governance, risk, and compliance program. This high-ownership role involves defining principles and policies while directly collaborating with engineering and legal teams. The ideal candidate will have 8+ years...Suggested
- Zania is seeking a GRC Engineer in San Francisco to bridge product and customer needs in Governance, Risk, and Compliance. In this role, you will drive customer implementations, establish success goals upfront, and ensure engagements conclude successfully while contributing...SuggestedFlexible hours
$142k - $214k
...available to them in the digital world. We're looking for a Senior Lead, Ad Partnerships to join our Measurement and Signals team at... ...we demonstrate progress towards our environmental, social, and governance (ESG) goals, and we lay out our plans looking forward. The...SuggestedContract workWork experience placementLive inWork at officeLocal area$270k - $345k
...role Anthropic's Integrity & Compliance (I&C) function is building the... ...mission and position as one of the leading AI labs operating on the frontier. The Governance & Oversight pillar is the... ...system of record for I&C, including risk tracking, control documentation,...SuggestedInterim roleWork at officeVisa sponsorshipFlexible hours3 days per week$100 per hour
...across the organization. What You Will Work On Lead global HR projects, including M&A workforce integrations,... ...solving problems in the areas of Business Transformation, Governance, Risk and Compliance, and Technology and Digital Innovation. Our...SuggestedRemote workWorldwide- B Capital is seeking a Public Sector GRC Lead in San Francisco to manage FedRAMP compliance and drive security governance in cloud products. You will be responsible for maintaining key documents, engaging with auditors, and supporting sales in targeting public sector compliance...
$236k - $300k
A leading technology firm in San Francisco is looking for a Compliance Counsel Lead to build and manage a global compliance program. Responsibilities include advising teams on regulatory matters, conducting risk assessments, and maintaining compliance policies. Candidates...$125.9k - $150k
.... is hiring a Program Manager in San Francisco, CA to lead privacy, data protection, and AI governance initiatives. This role involves executing privacy programs, conducting risk assessments, and ensuring compliance across teams. The ideal candidate should have 3+ years...$150k - $210k
...process for new applicants. This role requires 5-10 years of experience in fraud strategy and strong expertise in managing identity risks, including first-party fraud vectors. The selected candidate will own the decision-making framework and report on the effectiveness...$180k - $270k
...Manager on Block's Global Freight & Trade Compliance team, you'll be responsible for managing... ...contract negotiations, service quality, risk mitigation, and compliance assurance. Working... ...through influence and partnership and lead complex negotiations, design scalable customs...Contract workLocal areaWorldwideFlexible hours$118k - $131k
Uber is seeking a Senior FCCS Consolidation Accountant in San Francisco to streamline consolidation processes and enhance data governance. The ideal candidate will manage monthly and annual consolidations, provide design recommendations for FCCS, and support financial...$127.3k - $240.1k
...Investigations & Enforcement team in San Francisco, California. This role supports ecosystem security and requires expertise in risk management, compliance, and data analytics. The ideal candidate will have strong analytical judgment and experience in driving effective...$211k - $234k
...Role We are hiring a Deal Desk Lead, Cloud Marketplaces &... ...the Deal Desk execution and governance layer that helps AWS‑related... ...creating unmanaged downstream risk across contracting, billing,... ...inquiries unrelated to job posting compliance. We are committed to providing...Full timeWork at officeLocal areaRelocation packageFlexible hours$130k - $180k
A financial technology company in San Francisco is looking for a Senior Content Manager to lead content strategy and governance. The role requires over 6 years of experience in content strategy and strong analytical skills. Responsibilities include building frameworks...Full time$119k - $299.93k
PwC is seeking a Senior Manager for its AI Governance team in San Francisco. This full‑time role involves enhancing project delivery with innovative methodologies, and leading teams to evaluate governance and risk frameworks. Candidates should have at least 8 years of...Full time$100k - $150k
...company scales. You will manage security operations, develop governance frameworks, and oversee IT processes. The ideal candidate will... ...operations and security roles, managing permissions, and ensuring compliance with necessary standards. This position comes with a...- A leading global consulting firm in San Francisco seeks an experienced IT Risk Consultant to manage client engagements and enhance internal control... ...discussions regarding cloud governance and transformation, ensuring regulatory compliance. A comprehensive benefits...Full time
$86 - $91 per hour
Crystal Equation Corporation is seeking a highly motivated Program Manager to join their Global Risk & Internal Audit team in San Francisco. The role involves managing complex, cross-functional programs and fostering collaboration across departments. The ideal candidate...Hourly pay- ...digital assets through custody, staking, trading, governance, settlement, and the industry’s leading security infrastructure. Home to Anchorage Digital... ...working effectively across multiple departments (Legal, Compliance, Risk, Operations, Technology) to deliver complex...
$193.8k - $228k
A leading technology company in San Francisco seeks a Senior GRC Analyst II. In this role, you will manage the Governance, Risk, and Compliance program, ensuring it aligns with security strategies. Candidates should have a strong knowledge of information security frameworks...- ...A pioneering AI governance company is looking for a Principal AI Security & Risk Researcher to join its remote-first team. This role offers the opportunity to build adaptive security frameworks that address evolving AI threats like jailbreaks and vulnerabilities. Ideal...Remote work
$139k - $260k
...Wells Fargo is seeking a Senior Lead Business Execution Consultant... ...business operations, risk and control oversight, and executive... ...strategy, execution, and governance across complex, cross-functional... ...across business, risk, compliance, and technology team Required...Work experience placement$200k - $250k
C&D Talent Advisory is seeking an Ecosystem Governance Operations professional to help shape the future of decentralized governance. This role involves designing, operationalizing, and improving governance workflows in a fully remote setting. Ideal candidates will have...Remote work- ...of interest reports, drafting engagement letters, and ensuring compliance with ethical standards. Ideal candidates will have bar licensure... .... The position offers an opportunity to play a key role in risk management and compliance efforts within the firm. #J-18808-Ljbffr...
- ...Federal Reserve Bank of New York in San Francisco seeks a Lead Specialist Examiner to enhance credit risk management practices. This role demands 10+ years in... ...comprehensive assessments for effective financial governance. Benefits include extensive medical, dental, and...
- ...read on. About the role We are seeking a Lead Commercial Counsel to serve as the... ...executive team in translating complex legal risk into clear business trade‑offs Design commercial... ...‑add in the market Develop a risk and compliance framework in partnership with our Head of...Local area
- ...OpenAI’s Equity Programs team designs and governs equity frameworks that align our people... ...Role We’re hiring an Executive Compensation Lead to help shape how OpenAI compensates its... ...align with disclosure, governance, and compliance requirements. Prepare clear, decision‑ready...Work at officeRemote workWork from homeRelocation package
- A remote-first AI governance company is seeking a Principal AI Security & Risk Researcher to lead security research and build frameworks for assessing AI risks. In this part-time role, you will design adaptive security systems, collaborate on automated testing tools, and...Part timeRemote workFlexible hours
- ...Jared Kushner and Elad Gil, and backed by leading Silicon Valley builders including... ...impact on real-world problems across governments, healthcare systems, and critical industries... ...GRC Lead, you’ll own the governance, risk, and compliance program end-to-end - and treat it as a...WorldwideDay shift
- ...Francisco seeks a Chief Operating Officer (COO) to oversee operational systems and ensure alignment with the school's mission. The COO will lead strategic planning, manage budgets, and work collaboratively with academic leadership. Candidates must have a strong background in...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead - Governance, Risk & Compliance. Be the first to apply!
Related searches
- risk underwriter San Francisco, CA
- risk assurance San Francisco, CA
- geopolitical risk San Francisco, CA
- technology risk San Francisco, CA
- governance risk & compliance analyst San Francisco, CA
- risk compliance San Francisco, CA
- risk compliance officer San Francisco, CA
- risk and compliance analyst San Francisco, CA
- toxicology risk assessment
- risk control trainee

