Citigroup - Tampa, FL
posted about 2 months ago
The Data Privacy Lead Analyst is responsible for facilitating and executing the day-to-day activities that support governance and oversight, operational risk management, and controls leadership across the respective business. This individual plays a crucial role in supporting privacy-related capabilities and requirements, ensuring compliance with the Citi Global Privacy Policy, and identifying and managing operational risks associated with privacy. The analyst will work collaboratively across the business to ensure that effective controls and monitoring are in place to mitigate risks associated with data privacy. In this role, the analyst will engage in the assessment of privacy impact processes and controls required for all initiatives, new products, and services. They will assess, evaluate, and validate controls through processes and tools such as the MCA (Management Control Assessment) and KRIs (Key Risk Indicators) as appropriate for data privacy risk. The analyst will support the business and functions during reviews and audits on data privacy, assisting in reviewing and responding to findings by reviewers. Additionally, they will manage day-to-day activities that support the implementation of global policy requirements and regional standards, as well as assess legal and regulatory requirements in collaboration with Country Legal and Compliance. The analyst will coordinate periodic reviews of the business's data privacy processes and controls, validating changes resulting from such reviews. They will track and review deviations and risk acceptances, assessing the need for deviations and ensuring that the business has implemented and documented effective compensating controls. Following the escalation policy and procedures, the analyst will ensure effective escalation and socialization of material risk events and issues across businesses for any data privacy-related items. They will assist the business in creating Issues/CAPs (Corrective Action Plans) related to data privacy as needed, tracking and escalating as necessary. Moreover, the analyst will provide input and review completed data privacy CAPs in the tracking system prior to validation by other control and assessment functions such as Internal Audit and ORM (Operational Risk Management). They will coordinate and support the business in implementing global, regional, and local data privacy, regulatory, and risk and control projects, ensuring high-quality execution for data privacy programs for any Citi-initiated programs, in coordination with Global Risk and Control and the In-Business Regulatory Engagement Head. Finally, the analyst will develop and implement training on risk and control concepts, processes, tools, and their effects.