Head of Data Protection

Willis ReNew York, NY
8dHybrid

About The Position

Willis Re is a technology‑led reinsurance broker built on a cloud‑native, modular and data‑driven platform. As Head of Data Protection, you will own the strategy, controls and assurance that keep client and market data secure, compliant and resilient across all regions. Sitting within the Cyber function, you will embed privacy and security by design into our products, platforms and processes, enabling rapid, compliant growth and seamless global operations. You will translate regulatory and client obligations into practical, scalable solutions that protect sensitive data end‑to-end—at rest, in transit and in use—while supporting business agility. Operating in a hybrid delivery model, you will set standards, define accountability and measure outcomes for data confidentiality, integrity and availability, partnering closely with engineering, product, legal, risk and regional leaders. You are a business‑minded data protection leader who converts regulatory and client obligations into simple, scalable guardrails that enable the business to move fast without compromising control. You balance strategic design with hands-on depth, bringing clarity to complex privacy and security topics and ensuring decisions are grounded in risk and value. You thrive in a start-up environment and are comfortable operating beyond your usual remit to get things done—rolling up your sleeves to build policies, processes and capabilities from the ground up. You communicate crisply with executives, engineers and external stakeholders, make trade-offs explicit and take clear ownership for outcomes across a global footprint.

Requirements

  • Significant experience (10+ years) leading data protection or privacy programmes in complex, cloud‑first environments; insurance/reinsurance or financial services experience strongly preferred.
  • Deep knowledge of data protection and privacy regulations and principles (e.g., GDPR, UK GDPR, CCPA/CPRA and relevant sectoral obligations), and how to operationalise them at scale.
  • Strong command of technical and organisational controls: encryption and key management, tokenisation/masking, DLP, IAM/PAM, secure configuration, data minimisation and logging/monitoring.
  • Proven track record implementing privacy/security by design, data lifecycle and retention management, subject rights processes and incident/breach response.
  • Hands‑on experience with data discovery, classification and cataloguing tools across multi-cloud and SaaS estates, and integration into engineering workflows.
  • Experience governing cross‑border data transfers, residency controls and third-party data protection, including contractual mechanisms and continuous assurance.
  • Demonstrated ability to deliver audit readiness and client assurance, with clear metrics, KPIs and board-level reporting on control effectiveness and risk reduction.
  • Strong stakeholder management and influencing skills across Cyber, Legal, Risk, product and regional teams in a multi-jurisdictional environment.

Responsibilities

  • Define and own the enterprise data protection strategy, policies and standards, aligning to global frameworks while accommodating regional regulatory requirements.
  • Implement privacy and security by design across the data lifecycle, including collection, minimisation, lawful basis, consent, retention, deletion and safe disposal.
  • Establish technical controls for sensitive data, including encryption and key management, tokenisation/masking, data loss prevention, secure data sharing and segregation of duties.
  • Set and enforce access control models (least privilege, role‑based and attribute‑based access), including joiner‑mover‑leaver processes and privileged access management.
  • Deploy data discovery and classification at scale, maintaining accurate inventories of personal, client‑confidential and regulated data across cloud and SaaS estates.
  • Lead breach readiness and response for data incidents in coordination with Cyber, Legal and Communications, including playbooks, tabletop exercises, notification and lessons learned.
  • Provide security assurance across change initiatives to ensure new platforms and data products meet data protection requirements from design through deployment.
  • Oversee cross‑border data transfer governance, residency controls and supplier data protection due diligence, including contractual clauses and ongoing assurance.
  • Drive regulatory readiness and evidence for audits and client due diligence, maintaining clear metrics and reporting on control effectiveness and risk posture.
  • Manage a hybrid delivery model for data protection capabilities and tooling, directing in‑house teams and partners with clear KPIs, cost transparency and value realisation.

Benefits

  • Health and Welfare Benefits: Medical, Dental, Vision, Health Savings Account, Commuter Benefits, Health Care and Dependent Care Flexible Spending Accounts, Accident Insurance, Critical Illness Insurance, Life Insurance, AD&D , Financial wellbeing support, Wellbeing Program and Work/Life Resources (including Employee Assistance Program)
  • Leave Benefits: Paid Holidays, Annual Paid Time Off (includes paid state/local paid leave where required), Short-Term Disability, Long-Term Disability, Other Leaves (e.g., Bereavement, FMLA, ADA, Jury Duty, Military Leave, and Parental and Adoption Leave), Paid Time Off (Washington State only)
  • Retirement Benefits: Savings Plan (401k)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service