This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As part of the IMPaCT (Information Management, Privacy and Cross-border Transfer):Privacy Office, the Data Privacy Sr Analyst will support the 1st Line of Defense enterprise-level Privacy Program for businesses and functions, including risk management, metrics analysis, reporting, controls ownership, business process ownership and supporting delivery of Issue remediation and audit deliverables. Through these activities the individual will enable enterprise oversight of business/function compliance with the Citi Global Privacy Policy, related Standards/Procedures and applicable laws and regulatory requirements by ensuring effective controls and monitoring are in place to reduce and mitigate risk. This is an enterprise-level role, providing opportunities for exposure to leadership in businesses and functions, and experience across multiple controls/process areas.
Job Responsibility:
Support the Enterprise Privacy Governance Head and team in the implementation of global privacy policy requirements and regional standards, and on the assessment of the legal and regulatory requirements with Country Legal and Compliance as well as the development of local procedures as related to data privacy
Assess, evaluate, and validate controls through processes and tools such as the MCA and KRIs as appropriate for data privacy risk
Support periodic reviews of the enterprise data privacy framework components, and validate changes as a result of such reviews
Follow Escalation Policy and procedures to ensure effective escalation and socialization of material risk events and issues across businesses for any Data Privacy related items
Escalate material risk events and issues appropriately
Assist in creation of Issues/CAPs related to Data Privacy as needed (issues and CAPs owned by IMPaCT:Privacy Office). Track and escalate as necessary
Support the enterprise on reviews, audits and resulting activities on Data Privacy
Coordinate and support the enterprise in the implementation of global, regional and local Data Privacy, regulatory and risk and control projects
Requirements:
Demonstrates Data Privacy, Controls (MCA), Data Privacy Operations, Information Security or Cyber related risk management or minimum two years in an Internal Audit, Risk Management
Working knowledge of Data Privacy Compliance laws, rules, regulations, risks, and appropriate controls
familiarity with privacy related technology considerations such as cookies, mobile devices, biometrics and geolocation data is desired
Strong project management skills
Optimizes work processes by knowing the most effective and efficient processes to get things done, with a focus on continuous improvement
Ability to anticipate and balance the needs of multiple stakeholders, while monitoring tight deadlines or unexpected requirement changes
Ability to communicate effectively
Risk-based thinking and analytical mindset
Ability to build rapport and work closely with stakeholders
Up-to-date understanding of key Data Privacy risk and control concepts, tools and trends
Proficient in the use of basic Microsoft applications (Word, Excel, PowerPoint)
Bachelor's/University degree or equivalent experience