Jobs and Careers
FI
Principal Counsel & Associate Director, Enterprise Data Privacy Office
FINRAWashington, United Statesfull_timeVerifiedPosted 20 Mar 2025
💰 $242,600/yr($111,400/yr – $242,600/yr)
About the role
The Enterprise Data Privacy Office (EDPO) Office (the Privacy Office) is responsible for ensuring that FINRA meets or exceeds its legal and ethical obligations with respect to the security and use of information it collects while executing its responsibilities, fostering the confidence of firms, regulators, staff, and the investing public. The Principal Counsel & Associate Director, EDPO, is responsible for interpreting, advising on, monitoring and managing various privacy programs and activities at FINRA, at all times acting in an independent and confidential manner. This role is responsible for privacy, legal, and programmatic privacy work. This is professional level work in which the incumbent is defining their assigned roles, increasing their skills, and independently working, relying on the Senior Director and Counsel as a point of escalation.
Essential Job Functions:
- Counsels senior leaders across the organization regarding complex privacy matters, data loss events, and privacy policy violations raised to the Enterprise Data Privacy Office (EDPO) Office.
- Proactively identifies areas for improvement in FINRA’s privacy policies and programs based on changing state, federal, and global legal requirements and best practices; develops recommendations based on desired outcomes; engages security and business stakeholders, senior leaders, and end users across the enterprise, as appropriate to identify potential impacts; briefs EDPO management on findings and recommendations; and leads activities relating to implementing necessary improvements.
- Provides subject matter legal counsel, which may include reviewing and negotiating privacy provisions in vendor contracts, as requested by the Office of General Counsel Transactions (CTG) attorneys; providing interpretive guidance to the Office of Governmental Affairs and all FINRA departments regarding proposed federal and state legislation and potential impacts on FINRA operations; identifying appropriate changes to the existing policies and program to comply with legal requirements; and reviewing, drafting, and maintaining, as appropriate, FINRA’s internally and externally facing privacy policies, including relevant application or system privacy policies.
- Leads several privacy program activities, which may include refining and implementing the privacy assessment program, identifying and establishing standard and bespoke privacy risk mitigation recommendations for projects, creating a privacy compliance/audit function, providing guidance and coaching on developing a privacy risk register, managing and enhancing the program around department level privacy leaders and department privacy policies; and conducting comprehensive investigations of potential violations of FINRA privacy policies, including interviewing relevant players, drafting summaries for case files, and working with relevant control departments to determine outcomes.
- Builds strategic relationships with FINRA privacy leads across the organization to gain familiarity with the parameters and nature of each FINRA Department’s specific restricted information programs and privacy controls; provides tailored expert advice to those department leaders and exercises independent judgment in evaluation requests to privacy policy or program changes. Responsible for updating and implementing the policy guiding the privacy leads, running routine information meetings with the privacy leads and their delegates, and working with the Departments to ensure department level policies are up to date and accurately reflect expected privacy practices.
Education/Experience Requirements:
- A law degree and appropriately licensed to practice law in all applicable jurisdictions based on the relevant licensing requirements.
- A minimum six (6) years of experience in a legal role in privacy law or operations or in policy development and implementation, preferably in a regulatory environment; corporate privacy program experience desirable; experience in a non-profit or government environment highly desirable.
- Excellent oral/written communication, critical thinking, research, and analytical skills.
- Strong legal research skills required.
- Project management experience highly desirable.
- Experience handling sensitive or confidential information.
- Must have demonstrated experience effectively managing multiple deadlines and priorities; excellent organizational skill is required.
- Ability to function effectively both independently and in a team environment is required.
- CIPP/US or CIPM or the willingness to obtain a certification is required.
- Proficiency in the use of Microsoft Word, Microsoft Excel and Microsoft Outlook required; experience with Microsoft Project, Power BI,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s