Manager, Enterprise Data Privacy-External Data Sharing
Navy Federal Credit UnionAbout the role
The Manager, Data Privacy is responsible for managing the Navy Federal's 1st line of defense Data Privacy Program and team. Assists the VP, Enterprise Data Governance and the AVP, Enterprise Data Risk & Privacy in providing strategic leadership and direction for the Data Privacy Program and provides cross-functional management and coordination of Navy Federal's privacy related functions and initiatives. Ensures the alignment of the Privacy Program mission and goals to the enterprise's strategic data objectives, consistent with Navy Federal's core values, corporate culture, market expectations, and regulatory requirements
- Assist leadership in developing strategy and capabilities for holistic management of external data sharing risks affecting data privacy
- Manage and coordinate reviews of external data shares, identifying key risk factors
- Identify and promote cross-functional usage of tooling for key data risk factors related to external data sharing, enabling the holistic evaluation of risks
- Develop compliant solutions to evolving regulations affecting external data sharing
- Manage and coordinate data purpose reviews, ensuring compliant and responsible data usage
- Create and maintain strong partnership with PVM Risk team and risk stakeholders across credit union to holistically drive external data shares risk management
- Assist senior leadership in establishing and managing the roadmap and framework for the enterprise data privacy program
- Work closely with leaders of Enterprise Data & Analytics to ensure coordination of initiatives to drive efficiency and value
- Assist senior leadership in creating, maintaining, and operationalizing policies, standards, and procedures related to privacy consistent with financial services laws and regulations as well as industry best practices, and lead the maintenance and update of these policies, standards, and procedures
- Monitor the competitive landscape to inform Navy Federal's privacy strategy, in accordance with member best interests
- Create strong partnerships with stakeholders such as Information Services, Information Security, Enterprise Risk, Internal Audit, Compliance, and the Office of General Counsel to drive cross functional program initiatives
- In partnership with OGC and Compliance, monitor evolving federal and state privacy laws and regulations, and develop comprehensive plans for operational compliance
- Partner with Enterprise Data Governance and Information Services to ensure appropriate technology tooling to drive compliance with privacy laws and regulations, such as tooling to support Data Subject Access Rights
- In collaboration with Enterprise Risk and Compliance, develop controls to manage privacy risk, and act as advisor to business areas in implementing the controls
- Oversee metrics for privacy risk reporting, and prepare reports to highlight key metrics for governing bodies such as Enterprise Risk Management Committee
- Interface with Internal Audit and external examiners in representing the Privacy Program, and prepare appropriate materials in response to examiner inquiries
- Partner with Information Security and Third Party Risk Management to ensure coverage of privacy concerns in Navy Federal's third party risk assessment and management
- Partner with second line of defense functions in creating and operationalizing Privacy Impact Assessments of products, services, and systems
- Oversee development and implementation of Privacy training for employees to raise awareness of privacy principles and protection of member and employee personal information
- Assist in identifying and engaging stakeholders and clarifying accountabilities regarding privacy risk management
- Serve as a partner to the Data Security Event Management team, providing support related to unauthorized access of personal information and privacy incidents
- Perform supervisory/managerial responsibilities
- Perform other duties as assigned
- Experience in leading and overseeing an enterprise-wide data privacy program in a large organization, preferably in a large financial services organization
- Significant experience in creating, implementing, and maintaining operational policies, standards and procedures related to data privacy programs
- Advanced knowledge and understanding of federal and state laws, rules and regulations governing data privacy and protection
- Proven success with large-scale data or project management and oversight experience in a large organization
- Advanced knowledge of industry leading technical data management and data protection management practices
- Advanced knowledge of risk data architecture and technology solutions
- Experience in interacting with audit and regulatory agencies
- Advanced kn
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s