Director of Data Privacy and Compliance

Law School Admission Council

$140K — $157K *
Legal & Accounting
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • B.A. or B.S. degree required (M.S. preferred) with 5+ years related experience
  • Minimum 3 years' experience in records management with a focus on retention and compliance
  • Familiarity with data classification policies and protective measures
  • Experience with relational and unstructured data databases (e.g., Oracle, Azure SQL)
  • IAPP Certifications (e.g., CIPP, CIPM) highly preferred
  • Experience managing privacy and compliance functions
  • Knowledge of cybersecurity best practices for data protection

Responsibilities

  • Develops data privacy and compliance strategies with LSAC's General Counsel
  • Drives organizational change through cross-functional privacy initiatives
  • Maintains LSAC Privacy Roadmap and supports its implementation
  • Implements privacy management platform in line with roadmap priorities
  • Serves as process owner for timely management of DSAR requests
  • Oversees development of data inventory to ensure policy adherence
  • Conducts training campaigns to promote privacy best practices

Benefits

  • Remote work flexibility
  • Collaborative team environment
  • Professional growth opportunities
  • Engagement in innovative data privacy initiatives
  • No travel required for position
Full Job Description
Overview

Pay rate: $140,000 to $157,000, depending on experience

This is a remote position.

The Director of Data Privacy and Compliance is a leadership role responsible for implementing and overseeing LSAC's data privacy and compliance strategies. This role ensures LSAC adheres to global, regional and industry specific data protection regulations, mitigates privacy risks, and fosters a culture of ethical data management practices.

Responsibilities

Essential Job Functions

Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of this position. The individual employed in this position will be required to:
  • Work in close partnership with LSAC's Office of General Counsel, and specifically, the Senior Counsel - Privacy and Compliance, to develop data privacy and compliance strategies and initiatives.
  • Drives organizational change through privacy initiative and project leadership of cross-functional teams comprised of internal Privacy Team resources, business unit personnel, and technical/IT teams.
  • Guide and maintain the LSAC Privacy Roadmap through definition and ownership of its underpinning work program, working in collaboration with key stakeholders, particularly LSAC's Office of the General Counsel.
  • Guide and support privacy management platform implementation in line with Privacy Roadmap priorities.
  • Serve as Data Subject Access Rights (DSAR) process owner responsible for accurate and timely fulfillment of DSAR requests submitted by LSAC's range of customer types.
  • Contribute to the formation and ongoing support of Data Governance data protection policies, procedures, and data handling practices.
  • Oversee development and maintenance of data inventory to ensure adherence to privacy policies, standards, and regulations.
  • Develop and maintain LSAC's Record of Processing Activities (ROPA) as a log of how LSAC processes personal data.
  • Regularly conduct company-wide training campaigns to promote sound privacy practices into technical and business operations.
  • Serve as back-end (IT) Records Management/Retention processes owner assuring that customer records are maintained in accordance with LSAC Records Management Policy.
  • Identify, assess, and mitigate data protection risks across LSAC data estate.
  • Promote and deliver privacy tooling that meets internal and external customer expectations through collaboration with analysts, software developers, engineer leads, product managers, and business stakeholders.
  • Periodically prepare and present data privacy program and project status to senior management.


Competencies
  • Strong written and verbal communication skills.
  • Holds a strong sense of accountability for both individual and team objectives.
  • Embraces a forward-thinking mindset, contributing to a culture of continuous improvement and creativity.
  • Excellent time management, prioritization, attention to detail and organization skills
  • Strong analytical, problem solving, and decision-making skills.
  • Ability to manage cross-functional teams and drive organizational change. Candidate must have strong Project Management Skills
  • Continually seek methods and techniques to improve ways of working, particularly to optimize productivity of surrounding teams.
  • Excels at leading teams in an agile environment and overcoming professional challenges both personally and for involved teams.


Qualifications

Education and Experience
  • B.A. or B.S. degree (M.S. preferred) and 5+ years related experience.
  • Minimum 3 years' experience with records management as it pertains to retention and compliance requirements.
  • Exposure to an implemented and operational data classification policy in support of tailored data protection measures.
  • Experience with relational and unstructured data databases such as Oracle, CosmoDB, Azure SQL and document file systems.
  • Experience in the following areas is strongly preferred:
  • IAPP Certifications (e.g., CIPP, CIPM, CIPT).
  • Modern privacy platform implementation and operation such as with OneTrust and/or Microsoft data management and privacy offerings.
  • MS Azure (DevOps, Cloud Services, etc.)
  • Industry mainstream relational database product administration and concepts (Oracel/OCI, SQL Server, Azure SQL).
  • Contemporary Microsoft Azure data platform components.
  • Experience in managing staff
  • Experience in managing a Privacy & Compliance function
  • Experience in applying best Cybersecurity practices for data protection and compliance
  • Knowledge of inclusive design principles and digital accessibility standards.


Additional Information

Supervisory Responsibilities

This role does have people management responsibilities.

Position Type

The LSAC standard business hours are Monday-Friday, 8:30 a.m. - 4:45 p.m. ET. While these are the standard office hours for LSAC, as an exempt employee, the employee will be expected to work the hours necessary to satisfactorily complete their assignments in a responsible and professional manner.

Work Environment

This job operates in a remote and professional office environment. Whether remote or in-office, this role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.

Travel Requirements

There is no travel expected for this position.

Physical Demands

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee must regularly write, hear, read, and communicate effectively.

Additional Information:

Please note that this job description may not contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Job responsibilities may change at any time with or without notice.

Except as otherwise provided by law, all terms of employment are subject on an at-will basis and can change at any time.

Similar Jobs

More Jobs at Law School Admission Council

More Legal & Accounting Jobs

Find similar Director of Data Privacy and Compliance jobs: