Director, Privacy and Security Policy, Risk, Compliance, Integrity

New York, New York


Employer: Google
Industry: Business Strategy
Salary: Competitive
Job type: Full-Time

Minimum qualifications:

  • Bachelor's degree in public policy, business, engineering, law, or a relevant field or equivalent practical experience.
  • 15 years of experience working in compliance, policy, risk management or a related field, with 2 years in a supervisory or managerial role.


Preferred qualifications:

  • Graduate degree in public policy, business, engineering, law, or relevant field.
  • Knowledge of the privacy and security regulatory landscape and adjacent risk areas including risk assessment methodologies and internal control frameworks.
  • Ability to collaborate and build relationships with cross-functional teams, senior management, regulators, and external stakeholders.
  • Excellent leadership and management skills, and ability to motivate, mentor, and develop a team of compliance professionals.
  • Excellent communication skills and ability to articulate complex compliance concepts to diverse audiences
  • Analytical mindset with excellent problem-solving skills, attention to detail, and ability to interpret regulatory requirements and assess their impact on business operations.


About the job

With the widespread impact of AI technologies, the growth and diversification of our products, and the proliferation of new and at times fragmented laws and reporting requirements, we face one of the most exciting and challenging moments as a company. The Risk, Compliance, and Integrity organization (RCI) brings together critical compliance, assurance, risk, and governance functions across Google to help the company meet compliance needs and enable our businesses to innovate. Our goal is to make compliance an advantage for Google by driving scaled, data-driven, and policy-based compliance programs. We manage our operations through risk-based prioritization and governance and consistent and constructive regulator engagement.

As Director, you will be responsible for building and leading a team of policy experts to shape, craft, and codify Google's privacy and security compliance policies. You will be responsible for the development and maintenance of privacy and security policies and supporting documents and work closely with other teams within Google (e.g., Regulatory Affairs and Legal teams) on legal interpretation. You and the team will engage broadly to build awareness of policies, and to solicit input in the development and refinement of policies. You will define key control sets for a given policy to ensure control coverage and consistency of controls across the business. You will advise (in a non-legal capacity) on questions pertaining to compliance policies, design of controls associated with those policies, identification of gaps in policies and whether those gaps require changes in Enterprise-level policy, creation/updates to sub-Enterprise level policies, or risk acceptance. You and the team advise and may develop training materials associated with specific policies.

The US base salary range for this full-time position is $243,000-$350,000 bonus equity benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google .

Responsibilities

  • Develop, shape, and maintain Google's compliance policies leveraging legal interpretation, stakeholder input, and research.
  • Collaborate with product areas and functions to design controls that are adequate to ensure compliance with policy requirements. Participate in risk reviews to approve exceptions to policy.
  • Develop training programs and awareness initiatives for employees to enhance their understanding of compliance requirements, standards, and regulatory obligations.
  • Review issues and incidents to assess risk and ensure remediation plans are adequate.
  • Identify risk trends through external research and monitoring of regulatory priorities and consumer sentiment.

Created: 2024-05-30
Reference: 89383862823461574
Country: United States
State: New York
City: New York
ZIP: 10036