Chief Privacy Officer - EHRA
Raleigh, Wake County, North Carolina, 27609, USA
Listed on 2026-08-15
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Chief Privacy Officer
Recruitment Range: $170,000 - $230,000
The position is designated Statutory Exempt (EHRA) and is exempt from the State Human Resources Act. This position may be eligible for hybrid remote work in accordance with state policy and the agency's remote work program but does require weekly onsite work. Any telework will be under the conditions of the state Teleworking Program Policy and the employer may end any teleworking arrangement at any time in the employer's sole discretion.
Are you ready to take the next step in your career? We currently have an opening for the Chief Privacy Officer for the State of North Carolina. Step into a role where your leadership will shape the statewide future of privacy, trust, and responsible innovation. As North Carolina's Chief Privacy Officer, you will serve as the executive catalyst driving a mature, risk‑aware, and forward‑looking privacy program that underpins the integrity of statewide operations.
This is a mission‑critical position for a visionary leader who can translate complex regulatory landscapes, emerging technologies, and enterprise risk into clear strategic direction. You will partner directly with senior executives to embed privacy into organizational culture, protect the State's most sensitive data assets, and strengthen public trust through disciplined governance and proactive oversight.
Key Responsibilities:
- Provide statewide executive leadership by setting the strategic vision for the privacy program, establishing policies and standards, and guiding long‑term program maturity.
- Modernize and enhance the enterprise privacy program, ensuring consistent, statewide alignment with federal and state regulatory requirements and emerging data governance expectations.
- Develop innovative privacy strategies for new and evolving technologies, including cloud environments, IoT, AI, and advanced analytics.
- Oversee all privacy operations, including privacy impact assessments, governance activities, incident management, and continuous monitoring of controls.
- Ensure strong alignment with the Enterprise Security and Risk Management Office (ESRMO) and the Chief Data Officer to maintain unified, enterprise‑wide privacy and security compliance across programs, investigations, and policy development.
- Implement and evaluate audit controls, ensuring appropriate oversight of systems containing restricted or highly restricted information and regular review of NIST‑aligned controls.
- Lead enterprise privacy training and workforce awareness, delivering executive‑level messaging and organization‑wide education that reinforces a culture of data responsibility.
- Conduct pre‑deployment reviews of systems and initiatives, ensuring compliance with privacy laws and alignment with BAAs, MOUs/MOAs, and interconnection agreements.
- Monitor, report, and remediate privacy risks, managing violations, preventing unauthorized data use, and coordinating breach determination and notification with ESRMO and regulatory authorities.
- Serve as the State's senior privacy liaison, collaborating with internal stakeholders, regulators, legal authorities, and external partners to advance statewide privacy excellence.
About the Org:
The NC Department of Information Technology (NCDIT) is North Carolina's Technology Center, providing services to state and local agencies, schools, colleges, and universities. Reporting to the Chief Information Security/Risk Office, this role coordinates with DIT leadership and works closely with the Chief Data Office and Enterprise Security and Risk Management Office to ensure data privacy and security while using data assets to benefit North Carolina.
Knowledge
Skills and Abilities
/Management Preferences
The following Management Preferences are not required, but applicants that possess these skills are preferred:
- Regulatory & Compliance Expertise:
Deep understanding of state and federal privacy and data protection laws (e.g., HIPAA, FERPA) and evolving enforcement trends; strong knowledge of data risk management frameworks and required treatment of sensitive data types (ePHI, FTI, CJI, PII); demonstrated experience in privacy, data protection, or compliance within…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).