SMD, TIAA Chief Privacy & Records Officer

TIAAFrisco, TX
Onsite

About The Position

TIAA is a market-leading retirement company with a 100+ year legacy, founded to help educators retire with dignity, and now serving millions of people. The company is committed to evolving to meet tomorrow's challenges, equipping associates with future-focused skills and AI tools to ensure a more secure financial future for all. TIAA is guided by values such as Champion Our People, Be Client Obsessed, Lead with Integrity, Own It, and Win As One. The organization fosters a collaborative in-office environment where teams work across organizational boundaries to accelerate innovation and deliver meaningful results, promoting growth through learning experiences and development pathways. The Chief Privacy & Records Officer role is pivotal in establishing and championing the enterprise privacy strategy, ensuring alignment with regulatory requirements and industry standards. This includes maintaining expertise in privacy laws, building a robust privacy program, overseeing vendor privacy, advising senior leadership, coordinating incident response, driving privacy literacy, leading technology risk assessments, engaging with regulators, and defining the enterprise records management strategy.

Requirements

  • 10+ Years Required Work Experience
  • 15+ years of progressive experience in privacy, data governance, records management, or a closely related legal or compliance field, with at least five years in a senior leadership role
  • Exceptional knowledge of domestic and international privacy law
  • Strong executive communication and influencing skills
  • Ability to lead through complexity and ambiguity in a highly regulated industry
  • The ability to engage credibly with senior regulators, institutional clients, and Board-level audiences is essential
  • Strong interpersonal skills and the ability to interact effectively with people at all levels of the organization
  • Ability to think critically and strategically, finding creative and practical solutions to achieve objectives while managing complex risks
  • Excellent oral and written communication skills, including the ability to deliver effective presentations
  • Ability to adapt to and support change in dynamic risk environments
  • Demonstrated ability to work collaboratively with cross-functional groups and provide tactical support to senior management
  • A highly collaborative team player who can effectively manage and influence relationships that are widely dispersed both functionally and geographically
  • Related Skills: Accountability
  • Related Skills: Collaboration
  • Related Skills: Consultative Communication
  • Related Skills: Critical Thinking
  • Related Skills: Executive Presence
  • Related Skills: Influence
  • Related Skills: Investigation
  • Related Skills: Relationship Management
  • Related Skills: Technology Systems

Nice To Haves

  • 15+ Years preferred Work Experience
  • A Juris Doctor or advanced degree in a relevant discipline is strongly preferred
  • Professional certifications in privacy are highly desirable, including CIPP/US, CIPP/E, CIPM, or CIPT from the International Association of Privacy Professionals (IAPP)
  • Experience in financial services, law firms or the large consultancy / accounting firms is a significant advantage
  • Demonstrated track record of building and maturing enterprise-level programs with measurable outcomes

Responsibilities

  • Establishes and champions the enterprise privacy strategy, aligning it with organizational objectives, regulatory requirements, and evolving industry standards. This includes setting the long-term vision for privacy governance and translating that vision into actionable programs, policies, and operational frameworks that are scalable, sustainable, and risk-proportionate
  • Maintains deep and current expertise in applicable domestic and international privacy laws and frameworks, including but not limited to GDPR, CCPA/CPRA, GLBA, HIPAA, and emerging state-level privacy regulations. Proactively monitors the regulatory landscape, assesses organizational impact, and leads the enterprise response to new or changing requirements in a timely and effective manner. Regulatory Change Management activities are performed in close partnership with Law & Policy (L&P)
  • Builds and sustains a mature, risk-based privacy program encompassing Privacy Risk Assessment and Management, Compliance Monitoring and Testing, Data Inventory and Mapping, consent management, and Controls Framework development
  • Owns the enterprise framework for privacy-related vendor oversight, ensuring that third-party relationships involving personal data are subject to appropriate due diligence, contractual protections, and ongoing monitoring
  • Partners closely with L&P, Cybersecurity, Technology, Human Resources, Marketing, and Business Units to embed privacy principles into product development, vendor relationships, customer-facing operations, and enterprise transformation initiatives
  • Serves as a trusted advisor to senior leadership and the Board of Directors on all privacy-related matters, providing clear, actionable guidance that balances regulatory obligation with business enablement
  • Works closely with other Corporate teams and Business Units on operational aspects of the organization's response to privacy incidents and data breaches, coordinating with teams to ensure timely and effective containment, remediation, and regulatory engagement. Formal breach notification responsibilities remain with L&P
  • Drives enterprise-wide privacy literacy by developing and delivering training programs, communications, and resources that build a culture of privacy awareness and accountability at all levels of the organization
  • Leads risk assessment processes for new technology investments, vendor relationships, and third-party/fourth-party technology dependencies, ensuring due diligence and ongoing oversight of critical technology suppliers and third-party providers
  • Works closely with the relevant team for regulatory engagement on privacy matters, supporting examinations, inquiries, and ongoing dialogue with relevant regulatory authorities. This activity is conducted in close partnership with L&P, which retains responsibility for regulatory interpretation and formal legal advice
  • Defines and oversees the enterprise records management strategy, advancing the program beyond its current focus on physical records toward a more comprehensive and integrated records governance framework
  • CPRO develops, maintains, and enforces enterprise-wide records retention schedules, records management policies, and records lifecycle standards, ensuring these frameworks remain current with evolving legal and regulatory requirements across all relevant jurisdictions, including SEC, FINRA, and ERISA mandates
  • Supports the administration of the enterprise legal hold process in coordination with L&P, which retains primary responsibility for Legal Holds and Litigation Support
  • Ensures that records management practices and systems are structured to facilitate timely identification, preservation, and production of records in response to litigation, regulatory investigations, and e-discovery requests

Benefits

  • A comprehensive Total Rewards package designed to make a positive difference in the lives of our associates and their loved ones
  • A superior retirement program
  • Highly competitive health, wellness and work life offerings that can help you achieve and maintain your best possible physical, emotional and financial well-being

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Executive

Education Level

Ph.D. or professional degree

Number of Employees

5,001-10,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service