AlixPartners - Southfield, MI

posted about 2 months ago

Full-time
Remote - Southfield, MI
Professional, Scientific, and Technical Services

About the position

At AlixPartners, we solve the most complex and critical challenges by moving quickly from analysis to action when it really matters; creating value that has a lasting impact on companies, their people, and the communities they serve. By understanding, respecting, and honoring the needs of our employees, clients, and communities, AlixPartners actively promotes an inclusive environment. We strongly believe in the value that diversity brings to our experiences and are committed to the perpetual enhancements of initiatives, policies, and practices. We hold ourselves accountable by providing the space for authenticity, growth, and equity for everyone. AlixPartners has embraced a hybrid work model to provide flexibility and support our employees' work-life integration. Our hybrid model combines a mix of in-person at an AlixPartners office on Tuesday, Wednesday, and Thursday, with remote working options for Monday and Friday. In this position on AlixPartners' Corporate Services Legal Team, you will work with other Legal, Compliance, and Risk professionals providing support in the areas of privacy and data protection. The ideal candidate will have excellent writing, organization, and communication skills, along with high attention to detail and accuracy. Known internally as Legal Compliance Professional - Privacy and Data Protection, this role has a preferred location of Southfield, Michigan, USA or London, England. This position will report to the Associate General Counsel overseeing Privacy & Data Protection. Paid relocation is not available. You will provide support in areas related to compliance with state, federal, and global data privacy statutes and regulations, including GDPR, CCPA, PIPL, HIPAA, HITECH, and ePrivacy Directive. You will also support the maintenance and enforcement of AlixPartners' data governance policies and programs and AlixPartners' privacy policies and programs. Under the supervision of the senior professionals on the Privacy and Data Protection team, you will respond to client questionnaires and due diligence requests, review data protection agreements, conduct Privacy Impact Assessments, and partner with cross-functional teams to identify and document privacy risks. Additionally, you will monitor changes in the privacy landscape and translate them into actionable measures, draft communications for internal use, and complete other administrative tasks related to the execution of a Privacy Program.

Responsibilities

  • Provide support in areas related to compliance with state, federal, and global data privacy statutes and regulations, including GDPR, CCPA, PIPL, HIPAA, HITECH, and ePrivacy Directive.
  • Support the maintenance and enforcement of AlixPartners' data governance policies and programs and AlixPartners' privacy policies and programs.
  • Respond to client questionnaires and due diligence requests.
  • Review data protection agreements, data sharing agreements, standard contractual clauses, and Business Associate Agreements for consistency of preferred terms related to data governance, privacy, and security.
  • Conduct, execute, and document Privacy Impact Assessments and Risk Assessments for programs, processes, and projects across the organization.
  • Intake, document, and respond to Data Subject Requests.
  • Partner with cross-functional teams firmwide to identify and document privacy risks within new and existing projects, and develop mitigation plans.
  • Conduct privacy assessments of third-party vendors and tools in conjunction with the procurement team and other stakeholders.
  • Monitor changes in the privacy landscape and translate to actionable measures.
  • Draft privacy, data governance, and data protection communications for internal use.
  • Complete other administrative tasks related to the execution of a Privacy Program (e.g. schedule stakeholder meetings, take meeting minutes, breach response participation, etc.).
  • Build positive relationships with stakeholders across the broader organization.

Requirements

  • Minimum two (2) years data governance, privacy, compliance, or paralegal experience.
  • Familiarity with at least one of the following data privacy regulations and one associated security frameworks: GDPR, CCPA, HIPAA, NIST frameworks, ISO frameworks, etc.
  • Track record of effectively working with data from multiple sources - willingness to dig-in and understand the data, leveraging creative thinking and problem-solving.
  • Experience with Privacy Impact Assessments and Data Subject Access Requests is a plus.
  • Contract review experience is a plus.
  • Privacy certifications (e.g. CIPM, CIPT, CDPSE) is a plus.
  • Experience using OneTrust Privacy Management Software is a plus.
  • Experience in privacy with one of the following privacy principles or technologies is preferred: privacy by design, user data protection, GDPR, CCPA, data inventory, DLP, encryption anonymization or privacy impact assessments.
  • Experience with concepts and practices such as threat modeling, data anonymization and classification, auditing access to data, and review of requests for data access is preferred.
  • Must be highly collaborative and able to work in a team-based environment offering services to a fast-paced, multi-disciplinary organization negotiating for competing priorities and resources.
  • Ability to handle and protect confidential, sensitive information.
  • Strong initiative, self-driven to learn and deliver results without daily supervision.
  • Excellent written and verbal communication skills in English.

Nice-to-haves

  • Experience with Privacy Impact Assessments and Data Subject Access Requests is a plus.
  • Contract review experience is a plus.
  • Privacy certifications (e.g. CIPM, CIPT, CDPSE) is a plus.
  • Experience using OneTrust Privacy Management Software is a plus.

Benefits

  • Dental insurance
  • Health insurance
  • Parental leave
  • Tuition reimbursement
  • Vision insurance
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service