Director Risk and Compliance - US Based Remote
United States
Anywhere Real Estate Inc.
JOB SUMMARY
As a key member of the Global Information Security team, the Director of Risk & Compliance (Data Privacy and Regulatory Compliance) will spearhead the global data privacy and compliance initiatives across Product & Technology. This strategic role focuses on embedding privacy-by-design and regulatory compliance into the design, development, and operation of technology systems and products. The Director will ensure that data handling practices and information systems adhere to global and domestic regulations, including HIPAA, PCI, GDPR, and NYDFS, while also maintaining compliance with audit standards such as SOC 1 Type I and Type II through robust technical controls, risk management, and governance frameworks.
KEY RESPONSIBILITIES
- Embed Privacy and Security: Collaborate with engineering and product teams to integrate privacy-by-design and security principles into system development lifecycles.
- Translate Regulations: Convert complex regulatory requirements (e.g., HIPAA, PCI, GDPR, NYDFS) into actionable technical and operational controls.
- Ensure Audit Readiness: Oversee preparation and adherence to audit standards, including SOC 1 Type I and Type II, PCI and NYDFS, ensuring robust controls for financial reporting processes.
- Monitor Regulatory Changes: Stay abreast of evolving global regulations, assess their impact on technology systems, and provide strategic guidance to stakeholders.
- Cross-Functional Collaboration: Partner with Legal, Risk, and Compliance teams to ensure consistent interpretation and implementation of regulatory and audit requirements.
- Ensure Compliance:
- Oversee adherence to applicable laws, regulations, and industry standards through effective governance and controls.
- Oversee data protection impact assessments (DPIAs) and ensure proper handling of personal data in accordance with regulations.
- stablish metrics and key performance indicators (KPIs) to measure the effectiveness of Data Privacy and Compliance initiatives.
- Champion a Compliance Culture:
- Chair the Global Data Privacy Steering Committee
- Foster a culture of data privacy, regulatory compliance, and audit preparedness across the Product & Technology organization.
- Advise on Data Protection: Serve as a subject matter expert on data protection controls, regulatory readiness, and audit strategies.
QUALIFICATIONS
- Proven expertise in global data privacy and regulatory compliance, with deep knowledge of CCPA, HIPAA, PCI, GDPR, NYDFS, and SOC standards.
- Ability to stay current with evolving regulatory landscapes and emerging privacy trends.
- Experience leading a team and conducting audits, risk assessments, and managing data privacy programs in a complex organizational environment.
- Strong understanding of technical controls, risk management, and security governance frameworks.
- Experience collaborating with cross-functional teams to operationalize compliance within technology stacks and business processes.
- Exceptional communication skills to translate complex regulatory requirements for diverse stakeholders.
- Strategic mindset with the ability to advise senior leadership on compliance and risk management.
- Analytical mindset with the ability to assess risks and implement practical solutions.
- Bachelor’s degree in a related field; advanced degree or certifications preferred.
- Minimum of 8-10 years of experience in data privacy, regulatory compliance, or a related technology field, with at least 5 years in a leadership role.
- Certifications (Preferred):
- Certified Information Privacy Professional (CIPP/US, CIPP/E, or equivalent).
- Certified Information Systems Security Professional (CISSP).
- Certified Information Systems Auditor (CISA).
We are proud of our award-winning culture and are consistently recognized as an employer of choice by various organizations including:
- Great Place to Work
- Forbes World's Best Employers
- Newsweek World's Most Trustworthy Companies
- Ethisphere World's Most Ethical Companies
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Audits CCPA CIPP CISA CISSP Compliance GDPR Governance HIPAA KPIs Privacy Risk assessment Risk management SOC SOC 1
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.