Executive Director, Data Protection & Privacy

9025 CVS Shared Services Resources LLC

Scottsdale (AZ)

On-site

USD 175,000 - 335,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision coverage
Paid time off
Retirement savings options
Wellness programs
Other resources

Job summary

CVS Health is seeking an Executive Director of Data Protection and Privacy to own the enterprise data protection program and mature its controls for sensitive and member data across the organization. This role requires executive presence to engage senior leaders, legal and compliance, and business stakeholders on data risk.

The position leads strategy, architecture, and operational execution for DLP, data discovery, and classification, while aligning with HIPAA, GDPR, CCPA/CPRA and state privacy

Qualifications

  • 15+ years in data protection, privacy or info security.
  • 5+ years in senior leadership/executive roles.
  • Experience with HIPAA, GDPR, CCPA/CPRA and state laws.

Responsibilities

  • Define and drive enterprise Data Protection & Privacy strategy and roadmap.
  • Own DLP design, deployment, and tuning across endpoints, network, cloud, and SaaS.
  • Lead data discovery to inventory sensitive data across stores.
  • Establish data classification standards and taxonomy.
  • Partner with engineering to embed privacy-by-design in pipelines and AI/ML workflows.
  • Ensure regulatory alignment and manage data subject requests, breaches, audits.

Skills

Data protection
DLP
Data discovery
Data classification
Privacy engineering
Executive communication
Leadership

Education

BSc in CS/IT
Master's degree preferred

Job description

We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.

Job Summary

We are seeking a highly experienced and strategic Executive Director of Data Protection and Privacy to own and mature the enterprise data protection program. This role is accountable for the strategy, design, and operational execution of data loss prevention (DLP), data discovery and classification, data privacy engineering, and the broader set of controls that safeguard sensitive, regulated, and member data across the enterprise. The successful candidate will bring deep technical fluency in data security architecture alongside the executive presence to engage senior leadership, legal, compliance, and business stakeholders on data risk. This is a highly visible leadership role responsible for reducing the organization’s data exposure risk, ensuring regulatory alignment, and building a scalable, defensible data protection program in a large, complex, highly regulated healthcare environment.

Key Responsibilities
  • Data Protection Strategy: Define and drive the enterprise Data Protection and Privacy strategy, roadmap, and multi-year investment plan, aligning with business, legal, and regulatory priorities.
  • Data Loss Prevention (DLP): Own the design, deployment, and continuous tuning of enterprise DLP controls across endpoint, network, email, cloud, and SaaS channels to prevent unauthorized exfiltration of sensitive data.
  • Data Discovery: Lead enterprise-wide data discovery efforts to identify, inventory, and map sensitive and regulated data across structured, unstructured, and cloud data stores.
  • Data Classification: Establish and operationalize data classification standards, taxonomy, and labeling schemes, ensuring consistent application across systems, applications, and third‑party platforms.
  • Data Privacy Engineering: Partner with engineering and application teams to embed privacy‑by‑design and privacy‑enhancing technologies (encryption, tokenization, masking, anonymization, differential privacy) directly into data pipelines, platforms, and AI/ML workflows.
  • Regulatory & Compliance Alignment: Ensure the data protection program aligns with HIPAA, GDPR, CCPA/CPRA, and other applicable state and federal privacy regulations; partner with Legal and Compliance on data subject requests, breach notification obligations, and audits.
  • Insider Risk & Incident Response: Partner with Detection Engineering and Incident Response to build and refine use cases for detecting data exfiltration, insider risk, and unauthorized data movement; lead data‑related incident response and forensics as needed.
  • Governance & Reporting: Establish metrics, KPIs, and executive reporting to measure the maturity and effectiveness of the data protection program; present regularly to senior leadership and risk committees (e.g., GRC SteerCo).
  • Team Leadership: Build, mentor, and scale a high‑performing team of data protection and privacy engineers and analysts; foster a culture of technical excellence and business partnership.
  • Cross‑Functional Collaboration: Serve as a trusted advisor to executive leadership, Legal, Internal Audit, and business unit stakeholders on emerging data risks, including risks introduced by generative AI and new data platforms.
  • Continuous Improvement: Stay current on emerging data protection technologies, privacy regulations, and industry threats; continuously evolve the program to address new data types, platforms, and business models.
Required Work Experience
  • Minimum of 15+ years of experience in data protection, data privacy, or information security, with at least 5 years in a senior leadership or executive‑level role.
  • Proven experience designing, building, and operationalizing enterprise DLP programs across endpoint, network, email, and cloud/SaaS environments.
  • Demonstrated experience leading enterprise data discovery initiatives, including identifying and inventorying sensitive data across structured and unstructured stores.
  • Demonstrated experience establishing data classification standards and taxonomy across systems and platforms.
  • Hands‑on experience with data privacy engineering techniques, including encryption, tokenization, data masking, and anonymization.
  • Strong working knowledge of privacy regulations, including HIPAA, GDPR, CCPA/CPRA, and applicable state privacy laws.
  • Demonstrated experience leading cross‑functional teams, managing enterprise data protection programs, and driving strategic initiatives at the executive level.
  • Experience advising boards and executive stakeholders on data protection and privacy risk.
Preferred Work Experience
  • Experience within a large, highly regulated healthcare, insurance, or financial services organization.
  • Experience integrating data protection and privacy controls into cloud‑native and AI/ML environments (AWS, Azure, GCP).
  • Experience with data security posture management (DSPM) and modern data governance platforms.
  • Experience building or maturing an insider risk management program.
Professional Certifications
  • Certified Information Privacy Professional (CIPP) – preferred.
  • Certified Information Privacy Manager (CIPM) – preferred.
  • Certified Data Privacy Solutions Engineer (CDPSE) – preferred.
Educational Credentials
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Law, or a related field; Master's degree or JD preferred.
  • Ongoing education in data privacy, data security, or related domains is a plus.
Skills and Attributes
  • In‑depth technical expertise in data protection, DLP, data classification, and privacy engineering concepts and technologies.
  • Strong executive communication skills, with the ability to translate complex data risk concepts for both technical and non‑technical stakeholders.
  • Proven ability to influence without direct authority, building consensus among stakeholders with competing priorities.
  • Excellent problem‑solving skills, with a focus on scalable, defensible, and business‑enabling data protection solutions.
  • Strong leadership capabilities, with experience building, mentoring, and scaling technical teams.
  • Sound judgment in balancing data protection rigor with business enablement and user experience.
Pay Range

The typical pay range for this role is: $175,100.00 – $334,750.00. This pay range represents the base hourly rate or base annual full‑time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short‑term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program.

Benefits
  • Medical, dental, and vision coverage
  • Paid time off
  • Retirement savings options
  • Wellness programs
  • Other resources

Additional details about available benefits are provided during the application process and on Benefits Moments.

Application Window

We anticipate the application window for this opening will close on: 10/27/2026.

Work Experience and Company Culture

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self‑disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cloud Data Security Engineer – Data Loss Prevention (DLP)
Senior Cloud Data Security Engineer – Data Loss Prevention (DLP)

9025 CVS Shared Services Resources LLC • Rhode Island

On-site
USD 102,000 - 204,000
Medical, dental and vision coverage
Paid time off
Retirement savings options
+1
Executive Director, Data Protection & Privacy
Executive Director, Data Protection & Privacy

CVS Health Corporation • Scottsdale (AZ)

Hybrid
USD 175,000 - 335,000
Comprehensive benefits package
Bonus and equity potential
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Harrisburg

On-site
USD 106,605 - 284,280
Bonus program
Equity awards
Comprehensive benefits
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Carson City (NV)

On-site
USD 106,605 - 284,280
Medical, dental, and vision coverage
Bonus eligibility and equity program
Paid time off and retirement options
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Phoenix (AZ)

On-site
USD 106,605 - 284,280
Comprehensive benefits
Bonus eligibility
Equity award program
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Tallahassee (FL)

On-site
USD 106,605 - 284,280
Medical, dental, vision coverage
Paid time off
Retirement savings options
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Hartford (CT)

On-site
USD 106,605 - 284,280
Medical, dental, vision coverage
Paid time off
Retirement savings options
+1
Lead Data Privacy Engineer
Lead Data Privacy Engineer

CVS Health • Juneau (AK)

On-site
USD 106,605 - 284,280
Data Governance, Risk & Privacy, Senior Manager
Data Governance, Risk & Privacy, Senior Manager

CVS Health Corporation • Hartford (CT)

On-site
USD 83,000 - 183,000
Bonus opportunities
Equity program
Comprehensive benefits
R1054567 Senior Analyst, IT Compliance & Risk - Data Protection
R1054567 Senior Analyst, IT Compliance & Risk - Data Protection

CVS Health Corporation • Woonsocket (RI)

Hybrid
USD 79,000 - 173,000
Medical insurance
Dental insurance
Vision coverage
+3