Globe Life is an insurance company committed to supporting employees through a collaborative and innovative workplace. The Privacy Engineer will support the Privacy Architecture Program by managing privacy risks, monitoring compliance, conducting impact assessments and audits, and implementing Privacy Enhancing Technologies while advising internal stakeholders on privacy regulations.
Ensure privacy forms, policies, standards, and procedures are up-to-date, accurate, and within risk tolerance levels
Perform initial and periodic information privacy risk assessment/analysis, mitigation, and remediation
Conduct ongoing privacy compliance monitoring activities in coordination with the organization's other compliance and operational assessment functions
Ensure the organization maintains appropriate privacy and confidentiality consents, authorization forms, information notices, and other materials reflecting current organizational and legal practices and requirements
Work cross-functionally with other departments to provide guidance on the effectiveness of privacy controls
Support privacy outreach and awareness-building
Provide guidance to internal business partners regarding compliance with privacy regulations (SME)
Coordinate and collaborate with regulatory and compliance functions
Conduct data privacy impact assessments
Conduct Consent Management audits
Perform and provide recommendations on privacy processes around Privacy Incident Investigations and Response, Privacy Program Assurance and Audits, Privacy Impact and Risk Assessments, and Stakeholder Communication and Management under the guidance of the Privacy Architecture Manager
Research and stay current with privacy-related news and changes to policies
Stay informed on applicable privacy laws and accreditation standards
Research applicable laws, regulations, and standards that Globe Life must comply with
Communicate effectively and proactively with ideas and recommendations for optimizing business operations, resources, and capacity to meet internal and external compliance goals
Performs other duties as assigned
Some travel may be required
Reliable and predictable attendance of your assigned shift
Ability to work full time and/or part time based on the position specifications
Qualification
Required
* 1 to 2 years in Software Development, Information Security, Privacy, and/or a GRC-related role
* Familiar with relevant privacy legislation, standards, and major compliance frameworks including CCPA, PIPEDA, GDPR, HIPAA, and the New Zealand Privacy Act
* Knowledge of Privacy by Design (PbD) principles, with exposure to implementing PbD, Privacy Impact Assessments (PIAs), and/or Data Protection Impact Assessments (DPIAs)
* CIPP/US or CIPP/C certification from IAPP required
* High technical aptitude with strong knowledge of Cookie Consent Management Platforms, GRC tool Archer, IT solution architecture, and Microsoft Office Suite
* Strong problem-solving skills with the ability to use a combination of analysis, experience, and judgment to develop feasible solutions
* Excellent time management, task planning, and prioritization skills
* Excellent verbal, written, and interpersonal communication skills with both technical and non-technical audiences
* Ability to work independently and under pressure with a high level of integrity and trust
Preferred
* Bachelor's degree in Information Technology, Information Systems, or Information Assurance, or 5 years of equivalent experience preferred
* Experience in an operational risk program role, working with cross-functional teams, and conducting major compliance audits preferred