Director - Privacy Operations & Integration
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
Joining Amex Tech means discovering and shaping your contribution to something big. Here, you can work alongside talented tech teams and build a unique career with the Powerful Backing of American Express. With a range of opportunities to work with the latest technologies, and a commitment to back the broader engineering community through open source, our mission is to power your success. Because Amex Tech is powered by our technology, our culture, and our colleagues.
The Director, Privacy Operations & Integration will sit within the Global Privacy Center of Excellence (GPCE) and lead a team of privacy subject matter experts enabling privacy across the First Line of Defense (1LOD). This role is responsible for driving the execution and operationalization of privacy and data protection standards across business units, while overseeing the governance, processes, and operating practices necessary to effectively manage privacy risk across products, services, projects, third-party relationships, and other activities involving personal data.
- Lead, develop, and manage a team of privacy SMEs across multiple regions to embed privacy into daily operations, design, products, and processes.
- Lead stakeholders in the identification, assessment, mitigation, and escalation of privacy risks across business units and strategic initiatives.
- Partner across second and third lines of defense to align controls and audit readiness.
- Serve as a trusted advisor and thought partner to business, technology, risk, and control stakeholders, influencing decisions and driving privacy-by-design outcomes.
- Own and continuously enhance enterprise privacy processes, governance frameworks, and operating procedures to support effective privacy risk management.
- Lead enterprise privacy governance activities, including issue management, exception management, reporting, and regulatory readiness.
- Drive the implementation and operationalization of privacy requirements across business units, ensuring consistent adoption of privacy standards, controls, and risk management practices.
- Partner closely with Technology, product, data, and engineering teams to embed privacy requirements into technology delivery, platform design, data use, and operational processes.
- Work with partners in the Global Privacy Center of Excellence to facilitate enterprise-wide privacy risk management in alignment with organizational best practices.
- Provide guidance in managing privacy risk to drive enterprise continuity across different regions and business units.
- Provide support in managing privacy risk across cases including product development, AI, third-party, cross border transfers, regulatory exams, second-line effective challenge, and audits.
- Collaborate with Enterprise Data Management, Infosec, GCO, and Third-Party Lifecycle Management teams to integrate privacy by design across existing processes, tools and products.
- Facilitate the first-line subject matter expertise supporting enterprise privacy risk management in operations (e.g., purpose limitation).
- Provide advisory, guidance, and consulting services to enable business units to execute proactive identification, comprehensive assessment, effective mitigation, and timely escalation of risks and issues.
Qualifications Requirements:
- Bachelor’s degree in Business, Management, or a related field; advanced degree preferred.
- 8+ years of experience in privacy, risk management, compliance, governance, or related disciplines, including leadership responsibility for enterprise-scale programs.
- Experience designing, implementing, or managing enterprise privacy, risk, compliance, or governance programs within a complex organization.
- Demonstrated experience leading large-scale process improvements and driving adoption across a highly matrixed environment.
- Experience operating within a regulated industry and partnering effectively across first, second, and third lines of defense.
- Experience partnering with technology, product, data, or engineering teams to operationalize privacy, risk, or compliance requirements within complex technology environments.
- Strong knowledge of and experience in enhancing and uplifting privacy-related processes across an Enterprise or local level for a financial services company.
- Proven track record of driving results in a fast-paced environment often with significant ambiguity and needing to make decisions with less than perfect information.
- Track record of being able to be a subject matter expert and using enterprise-thinking to quickly identify areas of improvement.
- High degree of organization, individual initiative and personal accountability and resiliency.
- Excellent communication skills with a demonstrated ability to lead, engage, influence, and encourage partners and stakeholders to drive collaboration and alignment.
- Proven ability to manage multiple demands successfully within a matrixed organization.
- Track record of creating and leading strong cross-functional teams.
- Enjoys solving large and complicated problems.
- Ability to maintain a positive, ‘can-do’ attitude.
Preferred Qualifications
- Significant banking experience and or regulated payments experience.
- Industry credentials (e.g., IAPP).
Employment eligibility to work with American Express in the United States is required as the company will not pursue visa sponsorship for these positions.