Overview
In this role you will strengthen Quorum’s global privacy, data protection, and AI governance posture to meet evolving regulations. You will work with cross-functional teams to embed privacy-by-design and responsible AI in products and processes, supporting compliant innovation and operational excellence. The role covers governance design, risk assessments, and vendor/customer assurance to sustain a scalable, compliant enterprise. Your work will connect regulatory insight with practical policies and training, shaping how we handle data and AI across the business.
Responsibilities
- Design, implement, and continuously improve global privacy, data protection, and AI governance programs
- Maintain privacy documentation (RoPA, data maps, DPIA/PIA materials, policies, templates, playbooks)
- Advise on privacy, data protection, vendor reviews, data subject rights, cross-border transfers, AI use cases, and privacy-by-design principles
- Conduct and support DPIAs/PIAs/TIAs, AI risk assessments, and privacy reviews for products, vendors, systems, and initiatives
- Review customer and vendor agreements (DPAs, SCCs, security schedules, AI/data use provisions)
- Support vendor management, customer audits, compliance reporting, privacy incidents, and breach response
- Maintain privacy and AI governance inventories (data processing activities, vendors, AI tools, data flows, risk assessments)
- Monitor global regulatory developments and translate requirements into practical policies and processes
- Deliver privacy, AI governance, and information security training across the organization
- Collaborate with stakeholders to integrate privacy and AI governance into products and operations
- Identify and remediate compliance gaps and risks for ongoing regulatory compliance and improvement
- Research emerging privacy, AI governance, cybersecurity, and data protection laws and best practices
- Other duties as assigned
Key requirements
- 3+ years of experience in privacy, data protection, compliance, information governance, or related fields
- Working knowledge of GDPR, UK GDPR, CCPA/CPRA, and other global privacy regulations
- Experience with DPIAs/PIAs, RoPA, data mapping, vendor privacy reviews, data subject rights, privacy-by-design, and incident response
- Familiarity with vendor management, risk management, audits, compliance reporting, and privacy/security contract reviews (DPAs, SCCs)
- Experience with GRC, privacy, or compliance platforms (e.g., OneTrust) is preferred
- Strong analytical, research, documentation, communication, and stakeholder management skills
- Excellent written and verbal communication, capable of explaining regulatory concepts to technical and non-technical audiences
- Ability to manage multiple priorities in a fast-paced, global environment
- Interest in process improvement, workflow automation, GRC tools, and scalable compliance operations
- Analytical thinking
- Strong communication
- Stakeholder management
- Knowledge of GDPR and UK GDPR
- DPIA/PIA and RoPA execution
- Data mapping and data flows
…
