Data Protection and Privacy Senior Associate - Data Risk Lead
Listed on 2026-02-14
-
IT/Tech
Data Security, Information Security
Location:
Anywhere in Country
At EY, we’re all in to shape your future with confidence.
We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
Ethics, Compliance, and Risk Management (ECRM) supports our people in managing the risks that arise during our daily working lives. We work closely with all parts of the organization to identify, manage and monitor risk, providing coordinated advice and assistance on independence, conflicts, compliance, regulatory, policy, security issues, as well as dealing with claims and any queries regarding ethics.
The opportunityWe are operating in an increasingly connected world that is changing how to manage risk. With fast-paced technology advancements, new innovations within emerging technologies, and an ever-challenging regulatory environment, it is business critical for our organization to identify not only the risks but the opportunities these present to us. As a Data Protection & Privacy Senior Associate, you will support processes within the Ethics, Compliance, and Risk Management (ECRM).
Our brand depends on it. It’s all part of our long-term commitment to building a better working world and in return, you can expect plenty of opportunities to take on new responsibilities and develop your career.
As part of the EY Americas Data Protection (Confidentiality, Data Privacy) function, you will maintain visibility over and perform data protection due diligence activities around business processes and processing activities (i.e., Activity Privacy Impact Assessments (APIAs)). You will help to interpret data protection and privacy laws and policies, determine required actions to standard and non-standard situations, and make recommendations based on firm guidance, professional standards, subject matter expertise, and acquired experience.
Skillsand attributes for success
Supports the Compliance function of the Data Protection program as needed, including but not limited to:
Conducting data protection due diligence reviews of business processes and data processing activities in order to enable EY compliance with legal/regulatory, EY firm, and EY client data protection and privacy requirements,
Developing procedures operationalizing data protection compliance measures, and monitoring and assessing adherence to implemented controls,
Collaborating with various functions within the organization, such as Talent, Finance, Service Line Quality, and business teams to maintain visibility over evolving and new processing activities and bake in Data Protection compliance measures as appropriate, and
Creating reports on various data protection compliance activities to be delivered to key program stakeholders, including senior leaders within the organization;
Assists the Data Risk Management function of the Data Protection program as needed, including but not limited to:
Documenting, conducting, and assisting others with investigations of data incidents (i.e., instances of loss, theft, or inappropriate disclosure of confidential/personal information); collaborating with clients, internal functions, and EY service lines to understand root cause, assess impact, and develop remediation plans, and
Developing and maintaining EY confidential and personal information inventory, in partnership with EY internal functions and service lines, to understand types of information that require protection and to fulfil data protection regulatory requirements (e.g., Records of Processing Activities (ROPA)).
Continuously maintains and expands knowledge of field of expertise and communicates new developments and resulting impact to program stakeholders and team members; and
Participates in various ad-hoc Data Protection and Privacy projects, as needs develop.
Strong verbal and written communication skills
Solid understanding of relevant firm business and area wide data protection issues and concerns
Strong problem-solving skills
Flexibility and the ability to take the initiative
Ability to right-size risk
Strong research skills
Strong…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).