Privacy Analyst II
Summary
Privacy Analyst II ensures data privacy compliance by assessing risks, implementing controls, and coordinating responses to regulatory requirements across Tailored Brands' e-commerce and retail systems.
About the Job
What You’ll Do | Key Accountabilities
- Participate in developing and maintaining policies, procedures, standards, and guidelines.
- Collaborate with business and technology stakeholders to ensure that systems, processes, services, and data adhere to industry standard best practices for data security, privacy, and artificial intelligence (AI).
- Liaison with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws.
- Collaborate with business owners and technical SMEs in the identification, evaluation, treatment, and monitoring of privacy and AI risks.
- Coordinate responses to Data Subject Access Requests from Consumer and Employees in support of the company regulatory compliance program.
- Stay abreast of privacy and AI developments in the US and Canada including regulatory actions, passage of new laws, etc.
- Conduct Privacy Impact and AI Assessments with business stakeholders.
- Enhance the cookie compliance program, including the assessment of cookie usage and management within Tailored Brand’s online services. Collaborate with business owners and technical SMEs to ensure that the program aligns with the industry’s best practices and regulatory requirements.
- Participate in the security, privacy, and AI education program including developing training materials, launching assessments, and monitoring training completion in compliance with various regulatory obligations including, but not limited to, PCI-DSS.
What You’ll Bring | Skills & Experience
- Bachelor’s degree in Computer Science, Management Information Systems, Engineering, or other relevant field; or equivalent combination of education and experience required
- 5+ years of experience as a GRC Analyst, Information Security Risk and Compliance Analyst, Privacy analyst, or comparable role
- Familiarity with some or all the following types of tools: OneTrust, Atlan, Ivanti
- IAPP’s PCIP Certification preferred
- Working knowledge of industry best practices and frameworks
- Experience with CCPA/CPRA, SSAE18 SOC 2, ISO, NIST, PCI, SOX standards, and compliance assessments
- Experience with cloud computing, online services, web and enterprise applications, and data analytics
- Experience with data discovery, data mapping, authorization, and access management, and pseudonymization technologies
- Self-motivated with ability to not only work in a group/individual setting, but able to drive action and make decisions independently
- The ability to communicate effectively with people at all levels
- Must be a confident communicator and presenter
- Must possess excellent organizational and planning skills
- Strong interpersonal skills, written and verbal communication
Work Environment, Physical & Mental Demands
- Ability to sit and work at a computer keyboard for extended periods of time
- Ability to stoop, kneel, bend at the waist, and reach daily
- Able to lift and move up to 25 pounds occasionally
- Must utilize visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment
- Hours regularly 40 hours per week, as work dictates, from a remote office location.
Benefits
Work-Life Balance
- Meeting-Free Fridays (encouraged) | so you can catch up on work and self-development
- Summer Fridays | from Memorial Day to Labor Day so you can enjoy a head-start to the weekend
- Holiday Early Departure | close out early the business day before a company observed holiday