
Head of Compliance and Data Privacy
- AI
- Risk Management
- triage
- Regulatory Compliance
- CIPM
- GDPR
- CCPA
Job Title: Head of Compliance and Data Privacy
Job Location: United States – Remote
Job Overview:
The Head of Compliance and Data Privacy leads the Company's global compliance, ethics and data privacy programs and provides practical, risk-based advice to senior leaders and business teams. The role owns the anti-bribery and corruption framework, AI governance, global ethics hotline and Whistleblowing Policy, the global data privacy program and privacy operations, audit and proposal responses related to compliance/data privacy, regulatory change advice, relevant SOPs and training. The role also oversees Privacy Aviator, serves as NSA Security Officer, manages the Privacy Manager and DPO relationship, and manages an allocated portion of the Legal Department budget. Success requires sound judgment, risk-management skills, and the ability to translate multi-jurisdictional requirements into clear, workable controls for a global clinical research organization.
Job Duties and Responsibilities:
- Global program leadership: Set priorities and plan for the Company's compliance, ethics and data privacy programs; maintain clear governance and reporting; and advise senior leaders on material risks and recommended actions.
- Anti-bribery and corruption: Develop, implement, and maintain anti-bribery and corruption policies and training, such as advise on gifts, hospitality, sponsorships, interactions with healthcare professionals and government officials, third-party risk and other higher-risk activities; coordinate due diligence, monitoring and remediation.
- AI governance: Lead the enterprise AI governance framework with Information Security, IT, Quality, HR and business functions. Establish policies, approval and risk-assessment processes, inventories and accountability; assess privacy, security, ethical and regulatory impacts; and provide responsible-use advice and training.
- Ethics and whistleblowing: Oversee the global Ethics hotline and Whistleblowing Policy, including intake, triage, conflict checks, non-retaliation safeguards, investigation coordination, documentation, remediation and trend reporting, consistent with confidentiality, privilege and local law.
- Own global Data Privacy program and operations: Manage and oversee policies and notices, records of processing, privacy impact and transfer assessments, data subject requests, retention and deletion, international transfers, privacy by design, third-party privacy risk and workforce training.
- Lead the privacy workstream for suspected personal-data incidents, including assessment, documentation, escalation and notification advice. Coordinate investigation, containment, remediation and lessons learned.
- DPO service/relationship oversight: Manage and oversee DPO service scope, priorities, information flow, resources and follow-through. Ensure the DPO can perform statutory duties with the independence and regulatory compliance.
- Serve as Business Owner for Privacy Aviator: Oversee configuration, access, data quality, user adoption, reporting, process improvement and coordination with the provider and internal system owners.
- Serve as NSA Security Officer: Coordinate applicable security and compliance obligations, including governance, records, reporting, training and escalation of potential issues.
- Audits and assurance: Lead responses to internal, client and regulatory audit requests concerning compliance and data privacy. Coordinate evidence, protect confidential and privileged material, ensure accurate responses, agree corrective actions and track remediation to closure.
- Proposals and client support: Own or approve compliance and data privacy content for proposals, requests for information, due diligence and assurance questionnaires. Coordinate accurate, consistent and supportable commitments and advise on related privacy and security terms when requested.
- Regulatory change: Monitor regulatory developments affecting clinical research, anti-bribery and corruption, whistleblowing, data protection and AI across Company jurisdictions. Assess business impact, recommend implementation plans and provide timely advice and training.
- SOP ownership and training: Own and review assigned global SOPs, policies, work instructions and supporting materials. Ensure approval, document control, implementation, training assignment, completion monitoring and evidence of effectiveness with Quality and functional owners.
- Budget, providers and reporting: Manage the assigned Legal budget, including forecasting, accruals, invoice review and variance management. Oversee outside counsel, the DPO and specialist providers; define service expectations, control costs and ensure timely delivery.
- Legal and cross-functional support: Conduct legal and regulatory research and collaborate across functions and geographies to resolve compliance, privacy and information-security issues. Support risk-balanced decisions and perform other responsibilities assigned by Legal or executive leadership consistent with the role.
Supervisory Responsibilities:
Directly supervises the Privacy Manager and other compliance or privacy staff as assigned. Responsibilities include recruitment, priority setting, work allocation, coaching, development, reward and performance management and workload oversight. Also manages the DPO relationship and external providers while preserving the DPO's required independence and access to senior management. All supervisory responsibilities are carried out in accordance with Company policies and applicable laws.
Job Requirements:
Education and Professional Qualification
- Juris Doctor or equivalent law degree from ABA-accredited law school; or equivalent advanced degree in compliance, privacy, information governance, or a closely related field.
- Admission and good standing as a lawyer in at least one jurisdiction, where applicable.
- Professional certification demonstrating subject-matter expertise (e.g., CIPP, CIPM, CCEP, AIGP).
Experience
- 10+ years of progressively responsible law firm and/or in-house experience in compliance, privacy, ethics, information governance or a related field, including leadership or managerial experience.
- Experience designing and improving global programs and policies including relevant control and training for compliance and privacy, anti-bribery and corruption, whistleblowing, investigations, ethics hotlines, as well as regulatory change, audits and external advisers.
- Experience with AI governance, privacy technology, data incidents and cross-functional risk management is strongly preferred.
- CRO, biopharma, or clinical research experience is preferred.
Skills/Competencies
- Strong legal, compliance and business judgment, with the ability to identify material risk, preserve appropriate independence and recommend practical solutions.
- Working knowledge of major global privacy (GDPR, CCPA, etc.), anti-bribery (FCPA, UK Birbery Act, etc.) whistleblowing and AI frameworks and able to apply requirements across jurisdictions.
- Excellent communication skills, including policy and SOP drafting, executive advice, investigation documentation, training and presentations.
- Strong program management, prioritization, follow-through and attention to detail across concurrent matters.
- Ability to assess privacy, security and compliance terms, negotiate risk-balanced positions and communicate commitments clearly.
- High integrity, discretion and fairness, with sound handling of confidentiality, privilege, conflicts and non-retaliation obligations.
- Strong analytical and problem-solving skills; uses data and trends to identify risk and improve controls.
- Collaborative, culturally aware and able to influence across functions, regions and levels
Capabilities
- Operates as a trusted, independent adviser to Legal, executive leadership and business teams.
- Translates complex requirements into clear policies, controls, workflows and training.
- Leads through influence and develops others through expectations, coaching and delegation.
- Works effectively with regulators, clients’ stakeholders, auditors, counsel, technology providers and maintain positive, professional and timely interactions
- Balances strategic leadership with hands-on resolution of compliance and privacy matters.
- Adapts quickly in fast-paced environment, prioritizes under pressure and escalates risk early.
Ability to “roll up sleeves” and keep a dynamic team operating smoothly.
#LI-BG1Â
#LI-Remote
Head of Compliance and Data Privacy · Caidya