- 4+ years of experience in a privacy, legal, compliance or risk management role
- BA/BS degree or equivalent experience
- Ability to work in an ambiguous environment and drive forward results
- Experience defining technical requirements and specifications, writing policy, and adapting requirements to technical and business needs
Come build the future of privacy with us! To get there, we need exceptionally talented, bright, and driven people. We work in a fast-paced environment across multiple industries, never losing our passion for customers.
As a member of the Workplace Trust: Privacy, AI, and Risk team, you will play a key role in operationalizing privacy across Amazon’s global employee, candidate, and contingent worker populations. This includes engaging with multiple stakeholders across the enterprise to help ensure compliant outcomes. You will be responsible for consulting with key stakeholders to drive alignment with global privacy regulatory requirements, including CPRA and GDPR.
In the execution of Amazon’s global privacy obligations, you will rely heavily on your subject matter expertise, as well as your case management, analytical, and relationship building skills to develop and deploy innovative strategies for data protection. The identified candidate will demonstrate proven experience to: support diverse stakeholders; evaluate control effectiveness; understand levels of potential risks and how to address them; provide in-depth consultation; and have the ability to synthesize diverse data to identify patterns, draw conclusions, and prioritize remediation efforts using risk management concepts. Excellent writing skills are required as the output for this role will be documentation that aligns to privacy regulations worldwide.
The ‘day-to-day’ aspect of this role will be to review internal Amazon systems for compliance with global privacy obligations. As part of this you will provide proactive guidance for upcoming tech builds and roadmaps, work with senior leaders on acceptable business risk when applicable, and track remediation actions as needed. You will be responsible for knowing the privacy risks of systems, and ensure the system owners follow the correct paths to full compliance. After reviewing each system, you will be responsible for creating a Data Protection Impact Assessment (DPIA) and Record of Processing (Ro P) for regulatory need.
The successful candidate leverages their background in compliance, data protection, records management, human resources, data governance, and/or data modelling to implement privacy controls across the internal technology ecosystem.
Key job responsibilities
- Consult with global legal, finance, benefits, IT, information security, and HR policy, process, vendor, and application owners to ensure that sound protocols are in place to mitigate privacy risks.
- Monitor known and emerging risks, measure internal control effectiveness, and develop and own action items to remediate identified risk issues.
- Socialize and secure commitment for remediation and risk management strategies.
- Develop deep knowledge of employee privacy obligations and data privacy processes and solutions utilized by Amazon.
- Assess areas for privacy program improvement and implement solutions.
- Consult on the development of business requirements for new system implementations and enhancements.
- Draft written narratives to communicate obligations, risk analyses, and recommendations.
- Inventory risk and compliance obligations in a governance, risk and compliance (GRC) system framework.
- Prepare other supporting documentation such as manager and employee communications, FAQs, and standard operating processes.
- Respond to questions and troubleshoot issues.
- Manage other risk and compliance related projects, as needed, to systematically reduce privacy risks.
- Ability to travel up to 10% including international destinations.
- Experience with GDPR, CCPA, LGPD, European Works Councils and other privacy regulations
- 5+ years of experience in an HR technology, compliance, or risk management role
- Advanced degree in a related area (MBA, MS, or JD)
- Relevant certifications such as CIPM, CIPT, CIPP/E, CIPP/US, FIP
- Experience working in a global, large-scale, complex, and fast-paced environment
- Experience standing up and developing global privacy programs and strategies
- Problem solver, able to troubleshoot issues independently or escalate when necessary; sense of accountability and sound professional judgment
- Proven analytical capabilities; experience with large amounts of data and in developing audit reports, metrics, and reporting mechanisms
- Excellent written and verbal communication skills