Executive Director, Data Protection & Privacy

CVS Health•Scottsdale, AZ
•$175,100 - $334,750

About The Position

We are seeking a highly experienced and strategic Executive Director of Data Protection and Privacy to own and mature the enterprise data protection program. This role is accountable for the strategy, design, and operational execution of data loss prevention (DLP), data discovery and classification, data privacy engineering, and the broader set of controls that safeguard sensitive, regulated, and member data across the enterprise. The successful candidate will bring deep technical fluency in data security architecture alongside the executive presence to engage senior leadership, legal, compliance, and business stakeholders on data risk. This is a highly visible leadership role responsible for reducing the organization's data exposure risk, ensuring regulatory alignment, and building a scalable, defensible data protection program in a large, complex, highly regulated healthcare environment.

Requirements

  • Minimum of 15+ years of experience in data protection, data privacy, or information security, with at least 5 years in a senior leadership or executive-level role.
  • Proven experience designing, building, and operationalizing enterprise DLP programs across endpoint, network, email, and cloud/SaaS environments.
  • Demonstrated experience leading enterprise data discovery initiatives, including identifying and inventorying sensitive data across structured and unstructured stores.
  • Demonstrated experience establishing data classification standards and taxonomy across systems and platforms.
  • Hands-on experience with data privacy engineering techniques, including encryption, tokenization, data masking, and anonymization.
  • Strong working knowledge of privacy regulations, including HIPAA, GDPR, CCPA/CPRA, and applicable state privacy laws.
  • Demonstrated experience leading cross-functional teams, managing enterprise data protection programs, and driving strategic initiatives at the executive level.
  • Experience advising boards and executive stakeholders on data protection and privacy risk.

Nice To Haves

  • Experience within a large, highly regulated healthcare, insurance, or financial services organization.
  • Experience integrating data protection and privacy controls into cloud-native and AI/ML environments (AWS, Azure, GCP).
  • Experience with data security posture management (DSPM) and modern data governance platforms.
  • Experience building or maturing an insider risk management program.
  • Certified Information Privacy Professional (CIPP) – preferred.
  • Certified Information Privacy Manager (CIPM) – preferred.
  • Certified Data Privacy Solutions Engineer (CDPSE) – preferred.
  • Master's degree or JD preferred.
  • Ongoing education in data privacy, data security, or related domains is a plus.

Responsibilities

  • Define and drive the enterprise Data Protection and Privacy strategy, roadmap, and multi-year investment plan, aligning with business, legal, and regulatory priorities.
  • Own the design, deployment, and continuous tuning of enterprise DLP controls across endpoint, network, email, cloud, and SaaS channels to prevent unauthorized exfiltration of sensitive data.
  • Lead enterprise-wide data discovery efforts to identify, inventory, and map sensitive and regulated data across structured, unstructured, and cloud data stores.
  • Establish and operationalize data classification standards, taxonomy, and labeling schemes, ensuring consistent application across systems, applications, and third-party platforms.
  • Partner with engineering and application teams to embed privacy-by-design and privacy-enhancing technologies (encryption, tokenization, masking, anonymization, differential privacy) directly into data pipelines, platforms, and AI/ML workflows.
  • Ensure the data protection program aligns with HIPAA, GDPR, CCPA/CPRA, and other applicable state and federal privacy regulations; partner with Legal and Compliance on data subject requests, breach notification obligations, and audits.
  • Partner with Detection Engineering and Incident Response to build and refine use cases for detecting data exfiltration, insider risk, and unauthorized data movement; lead data-related incident response and forensics as needed.
  • Establish metrics, KPIs, and executive reporting to measure the maturity and effectiveness of the data protection program; present regularly to senior leadership and risk committees (e.g., GRC SteerCo).
  • Build, mentor, and scale a high-performing team of data protection and privacy engineers and analysts; foster a culture of technical excellence and business partnership.
  • Serve as a trusted advisor to executive leadership, Legal, Internal Audit, and business unit stakeholders on emerging data risks, including risks introduced by generative AI and new data platforms.
  • Stay current on emerging data protection technologies, privacy regulations, and industry threats; continuously evolve the program to address new data types, platforms, and business models.

Benefits

  • medical
  • dental
  • vision coverage
  • paid time off
  • retirement savings options
  • wellness programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service