The Chief Privacy & Records Officer at TIAA is responsible for establishing and championing the enterprise privacy strategy, ensuring its alignment with organizational objectives, regulatory requirements (including GDPR, CCPA/CPRA, GLBA, HIPAA), and evolving industry standards. This role involves proactively monitoring the regulatory landscape, assessing organizational impact, and leading the enterprise response to new or changing requirements in partnership with Law & Policy. The officer will build and sustain a mature, risk-based privacy program, oversee privacy-related vendor oversight, and embed privacy principles across various business functions, including product development, vendor relationships, and customer-facing operations. They will serve as a trusted advisor to senior leadership and the Board of Directors on all privacy matters, coordinate responses to privacy incidents and data breaches, and drive enterprise-wide privacy literacy through training programs. Additionally, the role leads risk assessment processes for new technology investments and defines and oversees the enterprise records management strategy, developing and enforcing retention schedules and policies to ensure timely identification, preservation, and production of records for legal and regulatory needs.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Executive
Number of Employees
5,001-10,000 employees