Overview
Job summary
Come build the future of privacy with us! To get there, we need exceptionally talented, bright, and driven people. We work in a fast-paced environment across multiple industries, never losing our passion for customers.
The ‘day-to-day’ aspect of this role will be to review internal Amazon systems for compliance with global privacy obligations. As part of this you will provide proactive guidance for upcoming tech builds and roadmaps, work with senior leaders on acceptable business risk when applicable, and track remediation actions as needed. You will be responsible for knowing the ins and outs of these systems, and ensure the system owners follow the correct paths to full compliance. After reviewing each system, you will be responsible for creating a Data Protection Impact Assessment (DPIA) and Record of Processing (RoP) for regulatory need.
Key responsibilities
- Monitor known and emerging risks, measure internal control effectiveness, and develop and own action items to remediate identified risk issues.
- Socialize and secure commitment for remediation and risk management strategies.
- Create and execute project plans to achieve the defined deliverables.
- Develop deep knowledge of employee privacy obligations and data privacy processes and solutions utilized by Amazon.
- Consult on the development of business requirements for new system implementations and enhancements.
- Draft written narratives to communicate obligations, risk analyses, and recommendations.
- Inventory risk and compliance obligations in a governance, risk and compliance (GRC) system framework.
- Prepare other supporting documentation such as manager and employee communications, FAQs, and standard operating processes.
- Respond to questions and troubleshoot issues.
- Manage other risk and compliance related projects as needs arise.
- Ability to travel up to 10% including international destinations (post-COVID).
- Employees must reside within a commutable distance from the office they are assigned to but have the flexibility to regularly work from home, as well as from the office. Relocation assistance is available and flexibility may exist for full-time remote work
- Experience with GDPR, CCPA, LGPD, India’s PDP, German Works Councils and other privacy regulations
Qualifications
- 4+ years of experience in an HR, privacy, legal, compliance or risk management role
- 3+ years of program management experience, including change management, project management, stakeholder management, user training, and communications
- 5+ years of experience in an HR technology, compliance, or risk management role
- BA / BS degree or equivalent experience
- Advanced degree in a related area (MBA or JD)
- Experience working in a global, large-scale, complex, and fast-paced environment
- Experience defining technical requirements and specifications, writing policy, and adapting requirements to technical and business needs
- Excellent written and verbal communication skills