Head of Compliance and Data Privacy
Listed on 2026-10-03
-
Law/Legal
Regulatory Compliance Specialist
Job Title: Head of Compliance and Data Privacy
Job Location: United States – Remote
Job Overview:
The Head of Compliance and Data Privacy leads the Company's global compliance, ethics and data privacy programs and provides practical, risk-based advice to senior leaders and business teams. The role owns the anti-bribery and corruption framework, AI governance, global ethics hotline and Whistleblowing Policy, the global data privacy program and privacy operations, audit and proposal responses related to compliance/data privacy, regulatory change advice, relevant SOPs and training.
The role also oversees Privacy Aviator, serves as NSA Security Officer, manages the Privacy Manager and DPO relationship, and manages an allocated portion of the Legal Department budget. Success requires sound judgment, risk-management skills, and the ability to translate multi-jurisdictional requirements into clear, workable controls for a global clinical research organization.
Job Duties and Responsibilities:
- Global program leadership: Set priorities and plan for the Company's compliance, ethics and data privacy programs; maintain clear governance and reporting; and advise senior leaders on material risks and recommended actions.
- Anti-bribery and corruption: Develop, implement, and maintain anti-bribery and corruption policies and training, such as advise on gifts, hospitality, sponsor ships, interactions with healthcare professionals and government officials, third-party risk and other higher-risk activities; coordinate due diligence, monitoring and remediation.
- AI governance: Lead the enterprise AI governance framework with Information Security, IT, Quality, HR and business functions. Establish policies, approval and risk-assessment processes, inventories and accountability; assess privacy, security, ethical and regulatory impacts; and provide responsible-use advice and training.
- Ethics and whistleblowing: Oversee the global Ethics hotline and Whistleblowing Policy, including intake, triage, conflict checks, non-retaliation safeguards, investigation coordination, documentation, remediation and trend reporting, consistent with confidentiality, privilege and local law.
- Own global Data Privacy program and operations: Manage and oversee policies and notices, records of processing, privacy impact and transfer assessments, data subject requests, retention and deletion, international transfers, privacy by design, third-party privacy risk and workforce training.
- Lead the privacy workstream for suspected personal-data incidents, including assessment, documentation, escalation and notification advice. Coordinate investigation, containment, remediation and lessons learned.
- DPO service/relationship oversight: Manage and oversee DPO service scope, priorities, information flow, resources and follow-through. Ensure the DPO can perform statutory duties with the independence and regulatory compliance.
- Serve as Business Owner for Privacy Aviator: Oversee configuration, access, data quality, user adoption, reporting, process improvement and coordination with the provider and internal system owners.
- Serve as NSA Security Officer: Coordinate applicable security and compliance obligations, including governance, records, reporting, training and escalation of potential issues.
- Audits and assurance: Lead responses to internal, client and regulatory audit requests concerning compliance and data privacy. Coordinate evidence, protect confidential and privileged material, ensure accurate responses, agree corrective actions and track remediation to closure.
- Proposals and client support: Own or approve compliance and data privacy content for proposals, requests for information, due diligence and assurance questionnaires. Coordinate accurate, consistent and supportable commitments and advise on related privacy and security terms when requested.
- Regulatory change: Monitor regulatory developments affecting clinical research, anti-bribery and corruption, whistleblowing, data protection and AI across Company jurisdictions. Assess business impact, recommend implementation plans and provide timely advice and training.
- SOP ownership and training: Own and review assigned global SOPs, policies, work instructions and supporting materials. Ensure approval, document control, implementation, training assignment, completion monitoring and evidence of effectiveness with Quality and functional owners.
- Budget, providers and reporting: Manage the assigned Legal budget, including forecasting, accruals,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).