Director, Privacy - Risk & Compliance
AmeriLife · Clearwater, FL · 1 wk ago
LegalFull-time
About the role
The Director, Privacy will lead and oversee AmeriLife’s enterprise privacy program, ensuring compliance with applicable state and federal privacy laws and regulations for the company’s insurance distribution network. This position provides strategic leadership for privacy governance, privacy risk management, data protection, consumer rights administration, incident response, and privacy-by-design initiatives. The Director serves as the primary subject matter expert on privacy regulation and partners closely with Compliance, Legal, Information Technology, Data, Operations, Marketing, Human Resources, and Vendor Management to ensure responsible collection, use, sharing, retention, and protection of personal information.
Responsibilities
- Develop, maintain, and oversee the enterprise privacy program, ensuring the home office and affiliates have appropriate controls in place to manage stakeholder privacy concerns.
- Establish privacy policies, standards, procedures, and controls to ensure compliance with applicable laws, rules, and regulations, including GLBA, HIPAA, Reg S-P, CMS privacy rules, CCPA, CPRA, and other state privacy rules.
- Lead periodic privacy risk assessments and privacy impact assessments.
- Establish key risk indicators and corresponding thresholds to monitor acceptable levels of privacy risk.
- Serve as a central resource for privacy-related issues.
- Monitor regulatory developments in the privacy space and coordinate implementation of any required new controls.
- Respond to privacy incidents and remediate any control gaps related to such incidents.
- Provide input into privacy program training to promote a risk-aware culture.
- Respond to questions about privacy that arise in connection with due diligence, carrier audits, or other third-party inquiries.
- Oversee the process for privacy requests, including data deletion requests and opt-out requests.
- Provide periodic updates on the privacy program to executive management and other governance committees.
Requirements
- Undergraduate degree or equivalent work experience.
- 5-10 years of relevant experience.
- Background in the insurance and/or securities industry with privacy, compliance, or internal audit experience preferred.
- Skilled in using computer applications, including MS Office.
- Deep understanding of privacy laws and regulations.
Skills
- Strong knowledge of data governance and information lifecycle management.
- Experience managing privacy incidents and regulatory inquiries.
- Strong communication skills, both written and oral, with the ability to communicate well to both senior management and sales professionals.
- Analytical skills to work through issues related to the privacy considerations of the retail and wholesale sale of insurance and securities products.
- Ability to build business partnerships and work collaboratively with others to meet shared objectives.
- Ability to prioritize work appropriately to focus resources on high-risk matters.
- Knowledge of data analytics and management reporting and ability to explain complex concepts through quantitative and qualitative reports.
Benefits
- Comprehensive benefits package including PTO, medical, dental, vision, retirement savings, disability insurance, and life insurance.