Overview
Managing the Compliance and Privacy activities at both a local and regional level, ensuring alignment with global standards, local regulations, and internal policies, strategic oversight, operational execution, risk management, and cross‑functional collaboration. The split of local and regional responsibilities is approximately equal.
Local responsibilities
- Collaborate with local stakeholders, providing strategic and operational advice and direction on compliance and privacy matters, as a member of the affiliate leadership team.
- Develop and update compliance policies and procedures to reflect local requirements, using regional templates where applicable.
- Conduct periodic local compliance risk assessments and monitoring.
- Identify, manage, and elevate potential compliance or privacy issues.
- Lead and/or support investigations into suspected violations of policies or regulations.
- Deliver trainings and monitor completions, promoting awareness of ethical standards, internal policy requirements and reporting mechanisms.
- Stay informed of changes in laws and regulations affecting the organization.
- Assist in or prepare reports for regulatory bodies and internal stakeholders.
- Perform privacy risk assessments as required.
- Implement and manage regional initiatives in the local affiliate.
Regional responsibilities
- Drive enhancements of compliance and privacy programs in the Asia region, as a member of the regional compliance and privacy team.
- Collaborate with the Executive Director, Compliance & Privacy Lead, Asia Region and, in line with the strategic regional roadmap, lead regional compliance and privacy initiatives.
- Support privacy assessments providing practical and timely advice to internal stakeholders.
- Provide dedicated compliance and privacy management or support for a specified group of affiliates.
- Contribute to regular regional stakeholder engagements.
- Receive or forward regional risk reporting from affiliates as directed.
- Deliver regional training and awareness as needed.
- Maintain a high-level understanding of regional laws and regulations affecting the organization.
- Stay informed on regional laws and regulations affecting specific initiatives managed.
Requirements
Must
- 10+ years of compliance experience in the life science industry or a relevant field.
- 5+ years of privacy experience.
- Familiarity with compliance and privacy frameworks and industry practices (e.g., Code of Conduct, ABAC, data privacy, human rights, TPRM, sustainability compliance).
- Knowledge of relevant laws, regulations, and industry standards.
- Experience in implementing compliance initiatives and conducting privacy risk assessments, including data protection impact assessments (DPIAs).
- Excellent communication and cross‑cultural/ cross‑organizational collaboration skills.
- Strong ethical judgment and attention to detail.
- Ability to work both independently and as part of a team, managing multiple priorities.
- Analytical thinking and problem‑solving ability.
- Comfortable with traveling overseas regularly.
Advantage
- Experience in regional or multi‑country (preferably in the Asia region) programs.
- International Association of Privacy Professionals (IAPP) or equivalent certifications.
- Ethics & Compliance certifications.