Data risk and compliance officer
Location: New York, Palo Alto, Sacramento, San Diego, San Francisco, San Jose, Irvine, Los Angeles, Denver, Stamford, Hartford, Orlando, Miami, Jacksonville, Tallahassee, Tampa, Atlanta, Indianapolis, Des Moines, Kansas City, Wichita, Louisville, New Orleans, Baltimore, Boston, Detroit, Minneapolis, St. Louis, Hoboken, Iselin, Buffalo, Rochester, Cleveland, Columbus, Portland, Pittsburgh, Philadelphia, Providence, Greenville, Nashville, Memphis, Houston, Dallas, San Antonio, Austin, Salt Lake City, McLean, Richmond, Seattle, Milwaukee, Washington, Chicago, Charlotte
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. Data Governance, Risk, and Compliance Officer The Data Governance, Risk and Compliance Officer (“Officer”) will be responsible for developing and implementing the US Firm’s data governance strategy with regard to alignment and compliance with relevant laws and regulations. This position requires a strategic thinker with excellent communication skills to instill confidence in both internal and external audiences. The Opportunity This role involves creating and maintaining strong relationships with key stakeholders, within EYUS, including but not limited to the US Management Committee (”USMC”), the Ethics, Compliance, and Risk Management Sub-Committee (“ECRM SC”), US General Counsel’s Office (“GCO”), US Chief Information Officer (“CIO”), US Chief Technology Officer (“CTO”), US Chief Data Officer (“CDO”), Global Data Stewardship Office (“DSO”), Global Data Privacy Counsel, and various other Global, Area, and Region leaders. Position is expected to interface with executive leaders and must be able to demonstrate an expanded knowledge of data governance, risk, and compliance, as well as privacy and data protection policies, communicate processes/activities, identify and provide solutions for addressing issues and mitigate risk factors associated with these initiatives. Oversee the Data Protection Leader and teams, including assigning work and reviewing performance which may require leadership of virtual teams engaged in carrying out aspects of data governance, risk, and compliance initiatives. Your Key Responsibilities Strategy Development: Develop and implement the US Firm’s overall data governance strategy, risk and compliance programs, and related policies, processes, and procedures. Stakeholder Relationships: Create and maintain strong and effective relationships with key stakeholders, including EYUS, USMC/ECRM, US General Counsel’s Office, US CIO, US CTO, US CDO, Global CDO, Global DSO, Records and Information Management Leader, Enterprise Risk Management (ERM) Leader, Global Data Enablement Leader, Global Data Privacy Counsel, Global Chief InfoSec Officer, and Data Privacy/Protection Leaders in each applicable Region/Member Firm. Compliance Leadership: Working with the Data Protection Leader, oversee the EYUS activities for compliance with applicable data-related laws, including cyber/InfoSec, in accordance with EYUS’s overall Compliance Program Framework. Data Governance and Process Improvement: Continuously manage and monitor adherence to data governance policies and regulatory requirements. Identify opportunities to improve manual processes and implement automation where possible to enhance data management efficiency. Support the office of the CIO to enhance data governance and streamline data management processes in alignment with data-related laws and needs. Advisory Role: Advise management and business on best practices for data governance, data risk, and compliance with relevant laws and regulations. Policy Development: Support and oversee development and implementation of policies and procedures for managing data within EYUS, including any required additional US supplements to Global policies. Regulatory Updates: Keep up to date with changes to data-related laws. Point of Contact: In conjunction with the General Counsel’s Office and Data Protection Leader, serve as the main point of contact between the Firm and the relevant data protection authorities. Risk Assessment: Identify and assess the Firm’s existing and emerging data governance and compliance related risks as part of the Compliance Program Framework and Firm’s Enterprise Risk Management strategy and programs. Risk Management program: Work closely with relevant stakeholders to develop and implement strategies to mitigate these risks, ensuring compliance with legal and regulatory requirements. This includes understanding the root cause of data incidents and trends to better manage risk and inform prevention actions. Operational Oversight: Work with General Counsel’s Office and Data Protection Leader, oversee US Firm’s activities related to data governance, risk, and compliance including but not limited to:- Incident Response: Respond to data incident and manage business, regulator, and client interactions.
- Root Cause Analysis: Conduct root cause analysis of data incidents and identification of trends to better manage risk and inform prevention actions.
- Awareness and Education: Raise awareness and educate personnel on obligations under data privacy legislation and EY policies, and how best to handle confidential information and manage associated risk.
- Monitoring and Review: Monitor and review the handling of personal and confidential data within EYUS based on risk assessment.
- Privacy Impact Assessments (PIAs): Manage Privacy Impact Assessments and look for ways to enable the business while adequately protecting the firm.
- Data Lifecycle Tracking: Supporting CIO, CTO, CDO in the tracking of the lifecycle of data within the organization and the governance and compliance risks associated with it.
- Data Processing Monitoring: Monitor data processing activities and align with EYUS Records of Processing Activities (ROPA) process.
- Artificial Intelligence: Work closely with relevant stakeholders to enable the Firm to leverage data to support AI strategies and tools, including agentic AI, and move at the speed of the market while identifying and managing data governance and compliance risks to protect the firm.
- 15+ years directly related experience in data governance, risk, and compliance functions
- 10+ years of experience leading high performing teams in the data governance, risk, and compliance space
- Demonstrated abiity to successsfuly build trust and influence with the most senior leaders of an organization (e.g., equivalent to Boards or C-Suite)
- Experience in a similar capacity for a professional services firm, Big 4, or large consulting practice
- Keen ability to work at the highest strategic level while operating at the tactical level
- Bachelor’s degree or equivalent work experience
- Ability to work overtime as required throughout the year and will vary based on volume of work.
- Ability to travel when necessary
- Relevant certifications preferrred but not required (e.g., Certified Data Management Professional; Information Governance Professional; Certified Information Privacy Manager; Certified Information Privacy Professional; Artificial Intelligence Governance Professional; MSFT and/or Databrikcs related certificates)
- Advanced degree or equivalent work experience; juris doctor (JD) preferred
- We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $250,000 to $495,000. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $300,000 to $562,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
- Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
- Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
Recommended Jobs
Sous Chef
Position Summary: The Sous Chef is responsible for supporting the Executive Chef in overseeing daily kitchen operations, ensuring high-quality food production, and maintaining culinary excellence in l…
Volunteer Experience Specialist - Central (Dayton, OH)
Volunteer Experience Specialist Central - Region (Dayton) At Girl Scouts of Western Ohio, we believe every girl deserves a place to grow, lead and thrive. As a Volunteer Experience Specialist, …
Production Process Supervisor
Job Description Job Description Rumpke is a family-owned and operated company that ranks as one of the largest firms in the waste and recycling industry. Our mission is simple: to deliver excepti…
Teacher (PreK-3rd Grade)
Hello K-3rd Grade Teachers, Come join a therapist founded and led school team! Sage Connections is seeking a K-3rd Grade Teacher to join our team and provide services within the school setting for…
Supply Chain Supervisor
Overview: The Supply Chain Returns Supervisor will support and assist the Operations Manager with day-to-day activities in their assigned functional area. Responsible for safety, service, cost, qua…
IV Pharmacist - LTC
Licensed IV Pharmacist – Long-Term Care Pharmacy Location: Columbus, OH | Schedule: Monday–Friday, 8:00 AM – 4:30 PM | Full-Time About Us: SpecialtyRx is a rapidly growing Long-Term Care …
Experience Columbus: Where Care Meets Heartfelt Community
Registered Nurse - Progressive Care - Travel - (PCU RN) Are you ready for an exciting change in your nursing career? Join us as a Progressive Care Registered Nurse in Columbus, renowned for its vibra…
Controls Technician
Job Description Job Description Controls Technician Controls Technician Position Overview CyberCoders is partnering with a leading manufacturer and marketer of home appliances. We are seek…
Sales furniture
Job Description Job Description We are currently seeking to hire a Sales to join our team! You will be responsible for overseeing and developing a sales team to drive company revenue. Responsi…
Director associate / professor of clinical
Current UC employees must apply internally via SuccessFactors Next Lives at the University of Cincinnati Founded in 1819, the University of Cincinnati ranks among the nation’s best urban pu…