Senior Manager - Global Privacy Compliance
Job Details
Here, your voice and ideas matter, your work makes an impact, and together, you will help us define the future of American Express.
How will you make an impact in this role?
The American Express Global Privacy Oversight are trusted advisors on the American Express Data Protection & Privacy Principles. We work to raise privacy awareness, drive compliance with both internal privacy policies and regulatory expectations across the organization and establish privacy as a strategic differentiator for the American Express brand. As a second line of defense function, Global Privacy oversee, provide expertise in, and challenge the identification, management, and mitigation of privacy risks across the company in line with the privacy framework and the company’s vision to provide the world’s best customer experience every day.This position is based in Spain and reports to the Director, Digital Privacy.
The successful candidate will be passionate about privacy, with deep subject matter expertise in privacy regulation, and have a background working in privacy risk oversight or similar control functions. They will be comfortable interacting with multiple stakeholders across a highly matrixed environment to achieve organizational goals and will be an advocate for Privacy-by-Design.Â
Key Responsibilities:
- Identify privacy risks and provide risk management and strategic risk mitigation advice.
- Assess adequacy of business controls to mitigate privacy risk, using influence and credible challenge to drive control enhancements or process change as necessary.
- Provide privacy subject matter expertise to enable delivery of privacy obligations.
- Identify, develop, and manage privacy-related documentation, policies, and procedures.
- Support the ongoing development of the American Express� global privacy program.
- Ensure adherence to the enterprise privacy risk appetite.
- Foster a culture of privacy at American Express by advocating for privacy-by-design, integration of the American Express Data Protection & Privacy Principles, accountability, and sharing of best practices.
Minimum Qualifications:
- Knowledge of the General Data Protection Regulation (GDPR) or other global Privacy related laws including the US (e.g. CCPA/CPRA, GLBA/Reg P, CAN-SPAM, TCPA, FCRA/FACTA) with 5+ years relevant experience.
- 5+ years experience supporting internal business partners or clients in a highly regulated environment.
- 5+ experience in assessing the design and efficacy of privacy or compliance risk related controls.
 Preferred Qualifications: Â
- Certified Information Privacy Professional Europe (CIPP/E, CIPP/M, CIPP/US), and other relevant Certified Information Privacy Professional (CIPP) certifications.
- Prior work experience in privacy compliance, privacy focused internal audit functions, and/or privacy risk management.
- Strong analytical capabilities.
- Strong presentation skills, particularly in the development of professional and thoughtful materials.
- Highly organized with strong written and verbal communication skills.
We back you with benefits that support your holistic well-being so you can be and deliver your best. This means caring for you and your loved ones' physical, financial, and mental health, as well as providing the flexibility you need to thrive personally and professionally:
- Competitive base salariesÂ
- Bonus incentivesÂ
- Support for financial-well-being and retirementÂ
- Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)Â
- Flexible working model with hybrid, onsite or virtual arrangements depending on role and business needÂ
- Generous paid parental leave policies (depending on your location)Â
- Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)Â
- Free and confidential counseling support through our Healthy Minds programÂ
- Career development and training opportunities
Offer of employment with American Express is conditioned upon the successful completion of a background verification check, subject to applicable laws and regulations.