The Senior Director, Privacy Officer serves as the enterprise leader responsible for developing, implementing, and overseeing the company’s privacy and data protection strategy. This role ensures that the organization’s handling of personal data across all regions and business functions—including clinical research, pharmacovigilance, employee data, and commercial operations—complies with applicable laws, regulations, and ethical standards. The Privacy Officer will act as a strategic advisor to executive leadership, driving a culture of privacy by design and ensuring that privacy practices align with corporate values, innovation goals, and global regulatory expectations. The Privacy Officer will also provide as a consultant to affiliates as requested. Job Description: Strategic Leadership Develop and lead the company’s privacy and data protection strategy, ensuring alignment with corporate risk management and compliance frameworks. Serve as the principal advisor to senior management and the Board on privacy risks, trends, and regulatory developments. Lead and manage a privacy team, fostering cross-functional collaboration with Legal, IT, R&D, HR, Clinical, Commercial, and Compliance teams. From time to time, the Privacy Officer will act as a consultative resource and provide strategic and operational privacy support affiliates, assisting with implementation of global policies, adaptation to local regulatory requirements, and resolution of privacy-related issues. Program Development and Oversight Design, implement, and continuously enhance the privacy compliance program, including policies, procedures, training, and governance mechanisms to Promote compliance with state, federal and international privacy laws. Align with Global Privacy Office initiatives. Oversee data privacy impact assessments (DPIAs), records of processing activities, and other regulatory documentation. Ensure integration of privacy by design and default into product development, research programs, and digital initiatives. Work with global cross-border data transfer mechanisms and contractual safeguards (e.g., SCCs, BCRs). Regulatory Compliance and Risk Management Monitor and interpret global and US federal and state privacy laws and regulations (e.g., GDPR, CCPA and other state regulations, HIPAA) and advise on implications for the company’s operations. Manage relationships with data protection authorities (as appropriate) and coordinate responses to privacy-related inquiries, audits, and investigations. Lead the response to data incidents or breaches, including investigation, containment, notification, and remediation in collaboration with cybersecurity and legal teams. Training and Culture Champion a privacy-aware culture across the organization through ongoing communication, education, and training initiatives. Develop tools and guidance to empower employees to incorporate privacy considerations into daily operations. Partner with Compliance Training team to provide privacy training to various stakeholder groups. Operational Excellence Partner with IT, Cybersecurity, and Data Governance functions to ensure alignment between privacy, security, and information management programs. Support due diligence and integration for mergers, acquisitions, and partnerships involving personal data processing. Establish and monitor KPIs and metrics to assess program maturity and continuous improvement. Partner with the Compliance team to regularly assess the effectiveness of the privacy program, overseeing periodic privacy risk assessments and implementation of corrective action plans Assist in auditing processes to monitor privacy related activities Support AI and AI Council initiatives.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director
Education Level
Ph.D. or professional degree
Number of Employees
1,001-5,000 employees