The Privacy Specialist serves as a key contributor to the enterprise privacy program for a FINRA-registered broker-dealer and SEC-registered investment adviser.
This role operates with a high degree of independence and judgement, leading assigned privacy workstreams and supporting compliance with applicable regulations, including GLBA and Regulation S-P. The Privacy Specialist partners cross-functionally to implement privacy practices, assess risk, and enhance program effectiveness.
The position works under the direction of the Principal Privacy Officer and is responsible for driving execution of core privacy activities, identifying opportunities for process improvement, and ensuring operational alignment with regulatory expectations and internal standards.
What You'll Do:
Privacy Program Execution & Governance
Data Inventory & Data Mapping
Vendor Risk & Third-Party Oversight
Lead privacy-related components of vendor risk assessments, including review of data protection documentation.
Evaluate vendor practices and identify gaps relative to regulatory and company standards.
Partner with Risk, Legal, and Procurement to ensure appropriate mitigation strategies are implemented.
Track and report on vendor-related privacy risks and remediation status.
Privacy Incident Management
Evaluate incident details and escalate issues as appropriate, applying judgment to assess risk and impact.
Vendor Risk & Third-Party Oversight
Lead privacy-related components of vendor risk assessments, including review of data protection documentation.
Evaluate vendor practices and identify gaps relative to regulatory and company standards.
Partner with Risk, Legal, and Procurement to ensure appropriate mitigation strategies are implemented.
Track and report on vendor-related privacy risks and remediation status.
Privacy Incident Management
Evaluate incident details and escalate issues as appropriate, applying judgment to assess risk and impact.
What You Need to Have:
Experience supporting or executing privacy programs, preferably in financial services or a regulated industry.
Strong analytical and problem-solving skills, with the ability to interpret regulatory requirements and apply them in practice.
Demonstrated ability to manage work independently and exercise sound judgment in decision-making.
What's Nice to Have:
Experience with privacy regulations such as GLBA, Regulation S-P, and state privacy laws (e.g., CCPA).
Professional certifications (e.g., CIPP, CIPM, CIPT).
Experience with privacy management tools (e.g., OneTrust).
Strong communication skills with the ability to influence stakeholders across functions.
#LI-Hybrid
Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.