Confiz is hiring a GRC Data Analyst / Program Management professional to support privacy assessment and compliance initiatives. This role will help advance the privacy program by partnering with business and IT teams, leading privacy-related projects, identifying risks and required controls, ensuring alignment with applicable privacy laws and company standards, and escalating complex issues when senior-level guidance is needed.
This is an opportunity to combine data analysis, project/program management, privacy, risk, and cross-functional stakeholder management in a high-impact environment.
This is a hybrid role, based in Seattle, WA.
Onsite presence of 4 days per week is expected Monday through Thursday, Remote Fridays
Responsibilities
- Lead end-to-end privacy impact assessments, including assessments of first- and third-party applications, systems and business processes, and identification of privacy and technological considerations and gaps based on applicable laws, regulations and business requirements
- Evaluate complex privacy risks and document recommended mitigation strategies for partner teams to execute. Collaborate with cross-functional teams to implement effective privacy controls
- Collaborate with Legal, IT, and Cybersecurity teams to ensure privacy controls are aligned and reflect ongoing changes to risk and compliance posture
- Identify opportunities for operational improvements in privacy assessment processes, data mapping tools, and documentation, escalating implementation decisions to leadership as appropriate
- Assist with audit or maturity assessment initiatives
- Respond to and fulfill complex data subject access requests (DSARs)
- Maintain and supplement data mapping and governance documentation
- Support rollout of privacy-enhancing technologies and tools
- Identify and escalate potential privacy risks or threats and recommend mitigation strategies
- Lead incident response processes for privacy-related events
Qualifications
- Education: Bachelor’s degree or master’s in information technology, Computer Science, Cybersecurity or related experience required.
- Experience: 2+ years of privacy or related experience
- Certifications: IAPP certification (CIPP/US, CIPM, or CIPT) strongly preferred
- Skills: Strong working knowledge of Canadian (PIPEDA) and U.S. state-level privacy regulations (CCPA, OCPA, Colorado AI Act, Illinois BIPA) and sectoral privacy laws (e.g. CASL, FCRA, HIPAA, CAN-SPAM, COPPA). Experience with privacy management platforms (e.g. OneTrust, TrustArc). Strong attention to detail, quality and consistency in both written and verbal communications
We have a global team of amazing indi