Deloitte Specialist, Confidentiality & Privacy - Risk & Brand Protection in Salem, Oregon
Specialist, Confidentiality & Privacy - Risk & Brand Protection
Confidentiality & Privacy is seeking an experienced Specialist to contribute to strategic priorities and mitigation of confidentiality and privacy risks across the Deloitte US Firms. This role will primarily support the operational processes in evaluating and implementing technologies for confidentiality and privacy risks, as well as participate in key strategic priorities of C&P. The successful candidate will be a technologist, with a strong understanding of technical concepts, and expected to quickly build subject matter expertise in the US Firms' privacy and confidentiality policies.
Work you'll do
Assess, design, develop and/or integrate privacy-friendly tools and technologies to create efficiency across C&P.
Recognize benefits and challenges of emerging technologies and how to use them while respecting customer/consumer/employee privacy.
Document business requirements and translate those to technical requirements.
Liaise with Deloitte and vendor Information Technology teams.
Identify vulnerabilities and inefficiencies in current technologies and recommend controls and solutions, including automating manual processes. Update and track activities methodically with relentless attention to quality, accuracy, and timeliness.
Work closely with IT professionals to monitor systems throughout the system development lifecycle for privacy and data protection compliance.
Serve as the subject matter expert who C&P relies on for timely and impactful guidance regarding C&P technologies.
Develop in-depth understanding of the US Firms' businesses and enabling areas to implement appropriate technologies.
Confidentiality & Privacy Strategic Priorities
Participate in and lead projects to implement or enhance the US Firms' confidentiality and privacy programs. Activities may include development of training and awareness materials, implementation support for technical controls, or support for other high impact C&P initiatives.
Support confidentiality and privacy program assessments and system reviews of confidentiality & privacy risks.
Review and advise on technical requirements, vendor solutions, and data protection features of applications and systems utilized and/or delivered by the Deloitte US Firms.
Provide expertise and support to data analytics efforts to identify insights, potential risks, and mitigation strategies.
Risk & Brand Protection (R&BP)
At Deloitte, we are stewards of reputation-ours and our clients. That's why we foster a culture that protects, preserves, and enhances our reputation. With your help, we will distinguish Deloitte as the clear leader in professional services, making us the first choice for clients and talent.
Confidentiality & Privacy
Confidentiality & Privacy (C&P), led by the Chief Confidentiality & Privacy Officer, is a steward for Deloitte's reputation. In that role, C&P is responsible for the development and deployment of a comprehensive program to mitigate confidentiality and privacy risks across the Deloitte US Firms. The team is highly collaborative, and individual contributions are measured relative to team contributions. C&P is organized around key service areas, which include:
ü Policy, Privacy Regulatory & Data Governance
ü Insider Threat
ü Incident Management
ü Strategy and CI Program Direction
ü Technology Assessments
Required Education & Experience
BA/BS in computer science, management information systems, cybersecurity, privacy or related field or equivalent industry experience required
5 years of related experience
Demonstrated track record of adding value through a combination of deep technical expertise, professional judgment and process/program/project ownership.
Understand privacy practices for data security and control, such as minimization, limited access and encryption
Understanding of privacy by design and other foundational privacy concepts.
Experience with privacy platform software preferred.
Familiarity with system and software design to better ensure privacy.
Knowledge of U.S. state privacy legislation and the capability to apply regulatory requirements within an operational context.
Required Professional and Technical Skills
Demonstrated track record in sound judgment, investigation, strong attention to detail, and persistence in following/driving incidents to conclusion.
Excellent organizational, communications (oral and written), problem solving, and interpersonal skills.
Remain calm while retaining your ability to influence others in high pressure situations.
Highly collaborative work ethic with demonstrated agility and strong teaming skills.
Strong project management skills while exhibiting an ability to multi-task across various initiatives and activities.
Experience and proficiency in MS Office products to include Word, PowerPoint, Excel, and SharePoint.
Required Licenses, Certifications, and Other Requirements
Certified Information Privacy Technologist (CIPT), Certified Information Security Systems Professional (CISSP), or Certified Information Systems Auditor (CISA) certification required
For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to the State of Colorado and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and delivery model. We would not anticipate that the individual hired into this role would land at or near the top end of the range, but such a decision will be dependent on the facts and circumstances of each case. A reasonable estimate of the range is $53,910 to $80,145.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.