Overview
In this role you will operationalize Thomson Reuters’ global privacy program from the General Counsel’s Office, leading a Privacy Operations team to implement policies and ensure regulatory compliance. You will bridge privacy law, technology, and strategy, embedding privacy-by-design across products and services while advancing automation and AI-driven compliance. You’ll coordinate cyber incident response, manage data flows, and report on privacy metrics to leadership. Join a cross-functional team focused on scalable privacy operations that protect stakeholders and enable innovation.
Pay / Benefits
- Hybrid work model (2-3 days in-office)
- Flexible work-life policies (Flex My Way)
- Career development and growth programs
- Comprehensive benefits and retirement plans
- Mental health support (Headspace, mental health days)
- Volunteer days and ESG initiatives
Responsibilities
- Oversee day-to-day operations of the global privacy program
- Implement privacy policies, procedures, and operating frameworks
- Conduct or facilitate privacy risk assessments (PIA, DPIA, TIA)
- Coordinate DSAR responses and ensure timely resolution
- Track and report privacy program metrics and KPIs
- Monitor changes in privacy regulations and ensure regulatory compliance
- Build data inventory and mapping initiatives
- Support privacy incident response and breach notification processes
- Maintain incident response playbooks and runbooks
- Partner with Legal, IT, Product, and Business to embed privacy-by-design
- Provide privacy training and awareness programs
- Manage vendor/privacy contractual obligations and sub-processors
- Maintain records of processing activities (ROPA) and privacy documentation
- Prepare privacy metrics and dashboards for leadership
- Support regulatory inquiries and audits
- Lead and develop Privacy Operations Specialists team
- Standardize workflows and scalable privacy processes
- Coordinate cross-functional escalation and resource alignment
Key requirements
- Bachelor’s degree in law, Information Systems, Computer Science, Cybersecurity, or related field
- 6-8 years in technical privacy, cybersecurity, or compliance, preferably in SaaS
- 3-5 years of people management
- IAPP CIPM/CIPPT or CISSP or equivalent certification
- Experience with privacy risk assessments from a technical perspective
- Proficiency with OneTrust privacy management software (3-5 years)
- Knowledge of GDPR, CCPA, PIPEDA, and other regulations
- Ability to translate regulatory requirements into system-level controls
- Experience advising product/tech teams on privacy obligations and privacy by design
- Knowledge of data classification, retention, and lifecycle management
- Experience managing privacy operations in a large organization
- Strong communication, analytical, and problem-solving skills
- Experience with privacy management tools and technologies
- Strong communication with non-technical audiences
- Cross-functional collaboration
- Attention to detail
- OneTrust privacy management software (advanced)
- DSAR workflow and consent management
- Data inventory and data mapping
…
