Sr. Counsel, Data Privacy
Emergent BioSolutionsAbout the role
We go where others won’t, taking on some of the biggest public health challenges to protect and enhance millions of lives, and create a better, more secure world. Here, you will join passionate professionals who advance their scientific, technical and professional skills to develop products designed-to protect and enhance life.
I. JOB SUMMARY
Based in Emergent’s Legal Department, the Sr. Counsel, Data Privacy/ Data Privacy Officer is a newly created position that will work closely with legal, business, compliance and technology teammates to ensure the company’s compliance with current/developing rules and regulations. This position is responsible for leading Emergent’s data privacy program, including driving understanding of and compliance with U.S. and international privacy laws. This role has global impact across the products and services that the company provides.
II. ESSENTIAL FUNCTIONS
Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.
- Serve as primary privacy contact for internal stakeholders regarding data privacy incidents, inquiries from governing regulatory bodies, conducting data privacy impact assessments (DPIA), data subject access requests, maintaining the Company’s privacy policy and third-party data risk assessments, among other duties;
- Maintain subject matter expertise in multiple areas of privacy, including United States and international data privacy frameworks, regulations and requirements and ability to drive compliance;
- Responsible for implementing and managing company-wide privacy program. Assess and drive further development of company’s privacy program, ensuring Emergent meets its legal, regulatory, and reputational responsibilities, including translating legal requirements into privacy program deliverables and processes;
- Manage and lead the implementation of the global training and communication programs and monitor privacy risk across the business while also providing updates to internal clients on changes in legal developments in the area of data protection, security, data governance and privacy.
- Manage cross-functional partnerships with information security colleagues, including Chief Information Security Officer;
- Lead cross-functional privacy efforts including the identification of and mapping of applicable regulatory obligations to risks, controls, controls testing and policy documents;
- Lead the DPIA review process and identify potential improvements including enhancing the workflow for the intake, monitoring and tracking of assessments, as well as developing key metrics;
- Provide oversight for the strategic review, drafting and negotiating of privacy and data security terms in contracts, including data processing agreements and data transfer agreements;
- Provide oversight and support to the team in partnering with the business and support functions to conduct analyses of the key personal data processing of their areas, including documentation of data flows, processes and procedures while providing risk and controls knowledge to the team to improve business compliance;
- Develop and implement policies and procedures for privacy compliance processes in support of our privacy strategy;
- Manage incident response for data privacy breaches, conduct root cause analyses, and oversee remediation efforts;
- Develop and leverage key performance indicators to track, manage, measure and report on metrics across the organization related to key privacy and compliance trends; and
- Implement appropriate data privacy compliance controls and tools, including working with compliance technology support and other internal functions to make improvements and address any gaps identified.
The above statements are intended to describe the nature of work performed by those in this job and are not an exhaustive list of all duties. Nothing in this job description restricts managements right to assign or reassign duties and responsibilities to this job at any time which reflects management’s assignment of essential functions.
III. MINIMUM EDUCATION, EXPERIENCE, SKILLS
- Minimum 8 years of data privacy compliance and/or legal experience in-house, at a privacy regulator, a law firm, and/or in the government;
- Law degree and/or equivalent relevant experience is preferred
- Substantial subject matter expertise in US and international data privacy laws, rules, regulations, and industry standards, including sound working knowledge of EU GDPR as well as expertise in privacy risk and compliance management;
- Ability to work independently and effectively manage and prioritize multiple projects simultaneously;
- Maintain industry certification in pri
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s