Privacy and Data Risks Lead

JPMorgan Chase JPMorgan Chase · Banking · Plano, TX +1 · Consumer & Community Banking

Lead for Data Risks within the CCB Privacy Office, focusing on identifying, assessing, and managing risks associated with data processing, ensuring compliance with data risk policies, and supporting regulatory requirements. This role involves partnering with various stakeholders to design and implement processes for strategic data risk management, including Privacy Risk Assessments for AI, applications, and third-party engagements.

What you'd actually do

  1. Use thematic analysis to identify process and control gaps, partnering with key stakeholders to drive stronger risk management.
  2. Conduct Privacy Risk Assessments for AI, applications, products and services, third party engagements and business initiatives, involving the collection, use, retention and disposal of personal information.
  3. Collaborate with Legal, Cybersecurity and other partners to develop and enhance guidance on privacy risks mitigation based on laws, Firm policies and industry standards.
  4. Oversee the implementation and governance of Data Risk Management policies and standards.
  5. Develop and implement sustainable processes to monitor and report on data risk metrics and key indicators.

Skills

Required

  • Minimum of 5 years’ experience managing complex, multi-year programs with diverse, matrixed teams.
  • Experience working with privacy laws such as GDPR, GLBA, CCPA.
  • Experience in Data Risk Management, including familiarity with legal and regulatory requirements throughout the data lifecycle.
  • Proven experience with documenting process flows and governance procedures.
  • Experience with complex operational, data and technical concepts.
  • Excellent written and verbal communication skills; able to tailor messages for different audiences.
  • Strong organizational and prioritization skills, demonstrating flexibility in a rapidly changing environment.
  • Proven ability to build partnerships and work collaboratively across teams.
  • Strategic thinking and planning skills and abilities to drive innovation.

Nice to have

  • College degree preferred; advanced education in Data Protection, Privacy, or a related field is a plus.
  • Experience in a regulated financial institution.
  • IAPP Certification (CIPP/US, CIPT), CISA or similar Certification.
  • Working knowledge of AI laws, PCI-DSS.

What the JD emphasized

  • Privacy Risk Assessments for AI
  • privacy laws such as GDPR, GLBA, CCPA
  • legal and regulatory requirements throughout the data lifecycle
  • regulated financial institution