Role Description
The Privacy professional will play a pivotal role in ensuring Servierβs compliance with privacy laws and regulations across the US. Reporting to the Sr. Director, US Head of Data Privacy, this Senior Manager level professional will be responsible for advancing Servier US data privacy programs through strategic oversight, operational execution, and cross-functional collaboration. This ensures responsible data is used to support business objectives and plays a critical role in risk identification and mitigation.
-
Support day-to-day operations of the privacy program, including policy implementation, training, and awareness initiatives.
-
Serve as the subject matter expert on privacy impact assessments (PIAs), records of processing activities, and vendor risk assessments.
-
Ensure timely completion of PIAs, including providing business guidance on when and how to complete them.
-
Review completed PIAs to identify risks, recommend mitigations, and support privacy by design.
-
Support maintenance of records of processing activities (RoPAs) and data maps.
-
Oversee privacy risk assessments for vendors and other third parties.
-
Develop training and workflows for privacy assessments and RoPAs.
-
Maintain the Privacy Intranet and related guidance documents for business teams.
-
Manage privacy technology platforms (e.g., OneTrust) and lead issue resolution, integration, and optimization.
-
Develop and track privacy program metrics to identify trends, measure effectiveness, and drive improvement.
-
Support the implementation and ongoing enhancement of processes and procedures to mitigate identified and potential privacy risks.
-
Support the development and maintenance of the internal U.S. Privacy Network.
-
Other duties as assigned by manager or department leader.
Qualifications
-
BA Degree required. JD Degree from an accredited law school is preferred.
-
BA degree with 7+ years or JD with 6+ years of privacy experience including supporting business functions on data privacy PIAs, ROPAs, and vendor risk assessments.
-
In-depth knowledge of U.S. privacy laws and requirements. Knowledge of GDPR and Canadian privacy laws and regulations is a plus.
-
AI literacy and experience using technology to enhance privacy operations.
-
Must have expert proficiency with common privacy compliance tools β e.g. One Trust, etc.
-
Ability to work independently and respond to shifting priorities.
-
Strong communication, project management, and presentation skills.
-
Proven ability to collaborate effectively with cross-functional partners.
-
Proven track record of assessing risk and developing privacy legal and compliance strategies to minimize and manage risk.
-
Experience supporting clients within the life sciences or a similar industry focused on data privacy and security is required.
-
CIPP/US privacy certification is a plus.
Requirements
-
Boston based preferred, open to remote employees.
-
Minimal travel as required.
Benefits
-
Salary range for this role is $160-$180k.
-
Eligible for Short-Term and Long-Term incentive programs.
-
Competitive and comprehensive benefits package including medical, dental, vision, and flexible time off.
-
401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements).