Careers at SideAway
Data Protection Officer Director
- Status
- Full Time / Part Time / Employee's Choice
- Reports To
- Chief Technology Officer
- Location
- Los Angeles, CA
Purpose
The Data Protection Officer is an independent and autonomous position within the organization, charged with maintaining national privacy law compliance and other privacy guidelines. He or she maintains records and documents of how information is being processed, stored, collected, and destroyed. The Data Protection Officer is knowledgeable of the internal privacy policies, procedures, and processes of SideAway. The Data Protection Officer serves as the point of contact for company data privacy and security issues. He or she interfaces with members of management to inform, advise, and issue recommendations relating to internal data processing activities. The Data Protection Officer conducts Privacy Impact Assessments with regards to internal systems and products and provides feedback and implements processes which emphasize privacy by design.
Responsibilities
- Educate the company and employees about critical compliance requirements
- Ensure the company is compliant with all aspects of national privacy laws
- Train employees involved in data processing to ensure proper data protection policies are followed
- Conduct audits as required to ensure correct data protection compliance and address potential issues
- Maintain records and documents of all data processing activities
- Participate in meetings with management to ensure privacy by design at all levels
- Offer advice and instructions on how to conduct Data Protection Impact Assessments (DPIAs)
- Ensure the company addresses all queries from data subjects regarding their information in the company databases
- Approving, freezing, revoking & or blacklisting a member's profile
- Knowledgeable in NIST, ISO 27001, CIS or equivalent
- Knowledgeable of regulatory requirements (such as: SOX, GLBA, PCI, FERPA, HIPAA, etc.)
- Demonstrated understanding of information security in the context of data protection and governance, risk and compliance
- Demonstrated understanding of data protection, data privacy, and risk management
- Advanced knowledge of information security, governance, data protection, data privacy, risk management
Requirements
- Exceptional writing, verbal, and listening skills
- Adaptability to changes in workload, systems, and processes
- Positive attitude that is reflected in all interactions
- Recognizes opportunities for improvement and can manage issues upward
- Attention to detail
- Motivated and innovative mindset
- Proactive communicator
- Ability to work without supervision, at times
- Outstanding ability to identify & resolve problems by thinking creatively & strategically
- Ability to work in a dynamic, fast-paced environment
- Excellent analytical, organizational, project management and time management skills
- Defines, operates and implements comprehensive data protection strategies and programs to prioritize and mitigate cyber risk relevant to high value and confidential information at USC. Create and maintain an agreed upon high value asset program and controls assessment in line with the OCISO GRC Risk Framework.
- Defines and partners with the Risk Management Manager for risk assessment, remediation plans to reduce risk related to high value assets and information. Shows key milestones, metrics, KPIs, associated budget and resource impacts to continue an effective data protection program that meets USC's needs.
- Defines and manages the Application Security standards and requirements, Data Loss Prevention enterprise program requirements. Oversees the enterprise level components of the programs and partners closely to integrate with the Security Operations team on operational components of Application Security testing and monitoring and Data Loss Prevention tuning and monitoring.
- Maintains awareness and knowledge of current changes within legal, regulatory, and technology environments which may affect operations. Ensures senior management and staff are informed of any changes and updates in a timely manner. Establishes and maintains appropriate network of professional contacts. Maintains membership in appropriate professional organizations and publications. Attends meetings, seminars and conferences and maintains continuity of any required or desirable certifications, if applicable.
- Minimum Field of Expertise: Advanced knowledge of information security, data protection, data privacy, risk management. Large enterprise or complex entity related experience.
- Great sense of humor and willingness to have fun
Qualifications
- Master's degree required
- An education in law and/or certifications from data protection/privacy organizations like the International Association of Privacy Professions (IAPP) are highly preferred.
- At least 5 years of experience as a Data Protection/Information Security Officer or similar
- Strong knowledge of national data protection laws
- Familiarity with computer security systems
- Ability to handle confidential information
- Strong sense of ethics with the ability to remain impartial and report non-compliance's
- Organization skills and strong analytical and communication skills
- Experience developing policy and compliance training
- MS Office knowledge
- Must have a LinkedIn profile
- Must have a Crunchbase profile