Security & Data Privacy Coordinator
H&M GroupAbout the role
Company Description
As one of the world’s largest fashion companies with more than 171,000 employees worldwide, H&M is an exciting and dynamic place to pursue a career within the fashion industry. Our business concept is to offer fashion and quality at the best price in a sustainable way and with our fast expansion we are always looking for new talents. Would you like to be part of our team?
Job Description
The Security and Data Privacy Coordinator for North America encompasses dual responsibilities of ensuring the safeguarding and security of our data, as well as overseeing our insurance processes and risk mitigation practices that protect our organization. As the Security and Data Privacy Coordinator, you will play a vital role in identifying and remediating both security and data privacy risks, providing advisory to regional management, and managing fleet operations and insurance renewals. The ideal candidate will possess a strong background in risk management, data privacy, and fleet management.
This position is based in New York, NY within our Controlling Function and reports to our Regional Data Privacy Manager, Americas."
Core Responsibilities includes but is not limited to:
Risk Management
- Identify, assess, and analyze privacy & security risks that could impact our company's operations, assets, and reputation.
- Develop and implement risk management strategies, policies, and procedures to ensure business continuity and minimize potential vulnerabilities.
- Conduct regular risk assessments and vulnerability scans to identify and prioritize risks and recommend appropriate risk mitigation measures.
- Conduct periodic security audits to ensure compliance with security policies, standards, and regulations.
- Conduct Privacy Impact Assessments (PIAs) for new systems/processes involving personal data.
- Support local POs in development of Data Processing Agreements (DPAs) for 3rd party engagements and ensure that DPAs are signed by all Data Processors
Information Privacy and Security
- Partner with privacy Process Owners (POs) to review & maintain up-to-date Record of Processing Agreements that document all regional processes involving personal data.
- Support Country privacy POs to ensure that appropriate security safeguards are mapped, maintained, and organizational measures are taken for all data processing activities (e.g., review & ensure good privacy & security practices in stores)
- Ensure that data privacy policies, guidelines, processes, and templates are communicated to relevant privacy stakeholders.
- Stay updated on local regulatory developments in the privacy space and secure local legal support in each country.
- Manage Customer and Employee Data Subject Requests (DSRs) to comply with local privacy laws.
- Support with information sharing and cause analysis following personal data breaches affecting North America.
- Act as a trusted advisor to management on both cybersecurity and privacy risks and their potential impact on the organization.
- Stay updated on the latest cybersecurity threats, vulnerabilities, and industry best practices.
- Conduct Privacy and Security awareness training for employees and promote a culture of data protection and security throughout the organization.
- Collaborate with IT teams to develop and implement robust security measures, including network security, access controls, and incident response procedures.
Fleet Management and Insurance Renewals
- Oversee the management of the company fleet, including vehicle maintenance, inspections, and repairs.
- Coordinate fleet-related activities, such as fuel management, vehicle registrations, and tracking systems.
- Manage relationships with fleet service providers and ensure compliance with safety and regulatory requirements.
- Collaborate with finance and procurement teams to ensure timely insurance renewals and manage invoicing for fleet-related expenses.
Qualifications
What You’ll Need to Succeed:
- Bachelor’s degree in a relevant field, such as Computer Science, Information Security, Risk Management, or Business Administration
- 5 years’ of store or district level management
- Background in Data Privacy and Risk Management
- Experience with Risk Assessments
- Privacy Impact Assessments (PTAs), TIAs, Record of Processing Agreements (ROPAs)
- Implementing business continuity plans based on Security risk assessments
- Working knowledge with multiple lines of Insurance
- Familiarity with fleet management processes, insurance renewals, and invoicing.
- Knowledge of relevant data privacy laws (US stat
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s