Sr. Director Records Management, Transparency and Choice, and Privacy Incidents
Listed on 2026-07-13
-
Management
Regulatory Compliance Specialist
About the Job
In collaboration with the Chief Privacy Officer, the Privacy Program Lead drives the strategic vision, operating model, budget, and planning activities, and outcomes for Privacy, including the development, implementation, maintenance and adherence to the records and information management, transparency, consent, and privacy incident response policies and procedures. The role leads the privacy teams accountable for records and information management and privacy incident response and serves as a technical expert and trusted strategic advisor to the CPO, leaders, and employees within and outside the department or function.
The privacy leader is accountable for furthering the Privacy Department’s mission of ensuring regulatory compliance, fostering consumer trust, and providing foundational capabilities for unlocking the value of data by translating privacy requirements to the business and positioning privacy as a competitive advantage that drives business growth.
As a subject‑matter expert, consult on enterprise initiatives including new products and processes, proactively identifying risks and requirements to ensure compliance with data protection, privacy laws and regulations and enterprise expectations, and provide privacy‑minded solutions to the business. Lead a team of privacy professionals accountable for establishing and operationalizing the records and information management program and the privacy incident response program to ensure retention, secure deletion requirements and timely notification and reporting of privacy incidents when needed.
Provide full manager responsibilities including communication, coaching, mentoring, staff development, performance management, salary administration and staffing decisions. Participate in functional management to ensure optimum effectiveness and quality by managing adherence to strategies, goals, budgets, operating policies, and procedures. Align roles and responsibilities in decision making and translate departmental strategy into operational objectives, including systems and processes.
Key initiatives include:
- Integrating and designing measurement systems, targets, and specific initiatives in support of various strategies.
- Directing teams and individuals to ensure business outcomes are achieved.
- Identifying and cultivating relationships with key stakeholders representing a broad range of functions and levels to ensure alignment with departmental and enterprise business strategies.
Responsible for designing and maintaining an effective business unit, including organization design, workforce management, internal workflow, and information flow. Provide leadership, strategy and direction on privacy risk and technology‑related requirements for privacy controls, including privacy and RIM platforms. Maintain a comprehensive understanding of industry activities and emerging trends related to records and information management, privacy notice, consent/authorization, and incident response. Partner with Legal, IT Risk and Compliance, Data Governance, Government Relations and other stakeholders to embed records and information management and privacy incident response requirements and controls into projects, products and services.
Support privacy impact assessment processes and embed the privacy program into every business aspect of Northwestern Mutual to navigate dynamic privacy landscape. Lead enterprise projects, programs or processes with significant business impact, develop tactical plans and complete complex assignments. Collaborate with the CPO, leaders and stakeholders to develop strategic plans for collection, use, sharing and disposal of information in compliance with applicable laws and regulations, and shape a roadmap with Data Engineering to accelerate leveraging data while maintaining compliance.
Law degree preferred. Bachelor’s or Master’s degree with an emphasis in Risk Management, Insurance, Finance, Computer Science, Computer Engineering, Software Engineering, MIS or related field; or related work experience beyond the minimum required. Minimum five years of experience in a privacy‑related practice or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).