Jobs and Careers
ME
Privacy & Cybersecurity Compliance Officer
MediaoceanRemote US, United StatesRemotefull_timeVerifiedPosted 13 Sept 2024
About the role
Mediaocean is powering the future of the advertising ecosystem with technology that empowers brands and agencies to deliver impactful omnichannel marketing experiences. With over $200 billion in annualized ad spend running through its software products, Mediaocean deploys AI and automation to optimize investments and outcomes. The company's advertising infrastructure and ad tech tools are used by more than 100,000 people across the globe. Mediaocean owns and operates Prisma, the industry's trusted system of record for media management and finance, Flashtalking, the world's largest independent ad server and creative personalization platform, as well as Protected Media, the MRC-accredited ad verification solution for brand safety and fraud detection. Visit www.mediaocean.com for more information.
We are seeking an experienced and highly skilled Privacy & Cybersecurity Compliance Officer to lead and manage the company’s ad tech privacy and cybersecurity compliance efforts. As part of the legal and compliance team and reporting directly to the General Counsel, this role is critical to ensuring that our company maintains compliance with applicable data privacy laws, industry regulations, and internal cybersecurity policies. You will act as the subject matter expert on global privacy laws, data security standards, and risk management practices, while fostering a culture of compliance and security throughout the ad tech organization.
We are seeking an experienced and highly skilled Privacy & Cybersecurity Compliance Officer to lead and manage the company’s ad tech privacy and cybersecurity compliance efforts. As part of the legal and compliance team and reporting directly to the General Counsel, this role is critical to ensuring that our company maintains compliance with applicable data privacy laws, industry regulations, and internal cybersecurity policies. You will act as the subject matter expert on global privacy laws, data security standards, and risk management practices, while fostering a culture of compliance and security throughout the ad tech organization.
What You Will Do:
- Privacy & Data Protection Compliance:
- Lead and manage compliance with global data privacy regulations, including but not limited to GDPR, CCPA, CPRA, and other relevant privacy laws.
- Develop, implement, and monitor data privacy policies, procedures, and controls to ensure compliance with regulatory requirements and internal standards.
- Conduct data protection impact assessments (DPIAs), privacy audits, and assessments of data processing activities to ensure compliance with applicable laws.
- Advise on cross-border data transfer issues and implement solutions, including Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), and data localization strategies.
- Act as the primary point of contact for privacy regulators, handling inquiries, audits, and complaints from data subjects.
- Cybersecurity Compliance:
- Oversee the ad tech division’s cybersecurity compliance program, ensuring adherence to industry standards and best practices such as NIST, ISO 27001, and SOC 2.
- Collaborate with IT and security teams to design, implement, and enforce cybersecurity policies, including incident response plans, data breach protocols, and risk management strategies.
- Ensure that appropriate technical and organizational measures are in place to protect sensitive data, including encryption, access controls, and security monitoring.
- Regularly conduct risk assessments and security audits to identify vulnerabilities and implement remediation plans.
- Coordinate responses to cybersecurity incidents, including leading post-incident reviews and ensuring compliance with breach notification requirements under various regulations.
- Vendor and Third-Party Risk Management:
- Establish and maintain a robust third-party risk management program, ensuring that vendors and partners meet the company’s privacy and cybersecurity standards.
- Conduct privacy and security due diligence on new and existing vendors, especially those involved in data processing activities.
- Review and negotiate privacy and cybersecurity terms in vendor contracts, ensuring alignment with internal and regulatory requirements.
- Training & Awareness:
- Develop training programs for employees on data privacy, cybersecurity best practices, and compliance obligations.
- Promote awareness of privacy and cybersecurity risks across the organization, fostering a culture of compliance and security.
- Serve as a key advisor to ad tech senior management on emerging privacy and cybersecurity trends and their potential impact on the company.
- Regulatory & Legal Guidance:
- Provide expert advice to the legal team, business units, and senior leadership on privacy and cybersecurity-related matters.
- Keep abreast of changes in global privacy and cybersecurity laws and industry regulations,
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s