Job Summary
The Director, Privacy will be responsible for leading and overseeing the Company's enterprise privacy program and ensuring compliance with applicable state and federal privacy laws and regulations for the company’s insurance distribution network. This position will provide strategic leadership for privacy governance, privacy risk management, data protection, consumer rights administration, incident response, and privacy-by-design initiatives.
The Director will serve as the primary subject matter expert as it relates to privacy regulation and will partner closely with Compliance, Legal, Information Technology, Data, Operations, Marketing, Human Resources, and Vendor Management to ensure the responsible collection, use, sharing, retention, and protection of personal information. This position will be primarily responsible for identifying, evaluating, and monitoring the company’s privacy risk across various operations and administering a program that is designed to adequately protect the personal information that the company has in its possession.
Job Description
Duties/Responsibilities
- Develop, maintain, and oversee the enterprise privacy program, ensuring the home office and affiliates have appropriate controls in place to manage the privacy concerns of their stakeholders.
- Establish privacy policies, standards, procedures, and controls to ensure compliance with applicable laws, rules, and regulations, including GLBA, HIPAA, Reg S-P, CMS privacy rules, CCPA, CPRA, and other state privacy rules and regulations.
- Lead periodic privacy risk assessments and privacy impact assessments.
- Establish key risk indicators and corresponding thresholds to help monitor acceptable levels of privacy risk.
- Serve as a central resource for privacy-related issues.
- Monitor regulatory developments in the privacy space and coordinate the implementation of any required new controls.
- Respond to privacy incidents and remediate any control gaps related to such incidents.
- Provide input into privacy program training to promote a risk-aware culture.
- Respond to questions about privacy that arise in connection with due diligence, carrier audits, or other third-party inquiries.
- Oversee process for privacy requests, including data deletion requests and opt-out requests.
- Provide periodic updates on privacy program to executive management and other governance committees.
Qualifications
Minimum Job Requirements
- Undergraduate degree or equivalent work experience
- 5-10 years relevant experience
- Background in the insurance and/or securities industry with privacy, compliance, or internal audit experience, preferred
- Skilled in using computer applications, including MS Office applications
- Deep understanding of privacy laws and regulations
Knowledge, Skills, and Abilities
- Strong knowledge of data governance and information lifecycle management
- Experience managing privacy incidents and regulatory inquiries
- Strong communication skills, both written and oral, with ability to communicate well to both senior management and sales professionals
- Analytical skills to work through issues related to the privacy considerations of the retail and wholesale sale of insurance and securities products.
- Ability to build business partnerships and work collaboratively with others to meet shared objectives.
- Ability to prioritize work appropriately to ensure we focus our resources on high-risk matters.
- Knowledge of data analytics and management reporting and ability to explain complex concepts through quantitative and qualitative reports.
What AmeriLife Offers
A comprehensive benefits package that includes PTO, medical, dental, vision, retirement savings, disability insurance, and life insurance.