Job Duties
• Design and implement privacy and compliance-related policies, controls, processes and leading practices.
• Work with the BAL Information Security and Privacy Council (ISPC) to determine whether the privacy-related policies/processes need to be modified or developed and drive any necessary policy/process changes.
• Manage, own, and coordinate all applicable privacy activities and processes associated with the ongoing maintenance and care of privacy compliance requirements such as EU-US DPF, GDPR, etc.
• Facilitate the definition of scope, goals and deliverables for defined privacy program projects.
• Responsible for communication to internal and external clients as it pertains to actions driven by the Privacy Program; including privacy breach processes.
• Advise on a variety of privacy topics, including incident response, leading privacy-related controls, and responding to data subject access requests. Identify, assess and communicate key privacy risks within the BAL operational environment.
• Monitor and report on the ongoing initiatives of the privacy program to the Senior Manager of Enterprise Security & Privacy.
• Lead the coordination of Data Privacy Impact Assessments (DPIA) to help identify and minimize the data protection risks across the organization.
• Monitor, track, and document changes to regulatory and compliance requirements.
• Provide ongoing support to the third party risk management program to include internal program development and external third party privacy assessment.
• Supports privacy audits, compliance checks and external assessment processes for our internal and external auditors.
• Participate in contract review and negotiation specific to privacy terms and data protection addendums.
• Supervise and coordinate all required internal audits required for ISO 27001 and 27701 compliance.
• Lead critical activities required to maintain ISO compliance, including, but not limited to, performance of risk assessments, mandatory clauses and control reviews.
• Own the Data Governance program including updates to data maps and monitoring of compliance with documented policies and procedures. Serve as the administrator of and subject matter expert (SME) for the OneTrust tool. May telecommute.
Job Requirements
Must have a Bachelor’s degree in Computer Science, Information Security or related field and 60 months of progressive, post-baccalaureate experience in job offered or in a Privacy and Compliance Program Manager-related occupation.
Apply at https://www.bal.com/careers Must reference job PRIVA002691

BAL is a corporate immigration law firm that powers human achievement through immigration expertise, people-centered client services and innovative technology. With 13 U.S. offices and network partners in 170-plus countries, BAL’s deep experience in employment authorization and work visas helps organizations recruit and retain the skilled talent they need to compete in today’s global economy.