Search

Senior Data Privacy & Governance Analyst

remoteFully Remote
PublishedPublished: 8/1/2026
IT / Technology


SUMMARY

Responsible for supporting the development, implementation, and administration of Alliant's enterprise data privacy and governance strategies, regulatory compliance efforts, and operational privacy framework, including obligations related to GDPR, CCPA/CPRA, U.S. state privacy laws, and other applicable privacy and data protection requirements. This role will help enable the responsible use of data to support innovation, business growth, strategic objectives, and the organization's ability to operate effectively across jurisdictions. This role will also be responsible for managing privacy operations independently, advising stakeholders on privacy and data governance risks, supporting AI and regulatory governance, coordinating privacy impact assessments, assisting with privacy and security incidents, maintaining policies, procedures, playbooks, and program documentation, and serve as the privacy representative on cross-functional business and technology initiatives.


ESSENTIAL DUTIES AND RESPONSIBILITIES

Support the development, implementation, and administration of the enterprise data privacy and governance program, including privacy operations, regulatory compliance, risk assessments, data governance, policy management, and stakeholder advisory support.

Perform compliance activities related to GDPR, CCPA/CPRA, U.S. state privacy laws, and other applicable privacy and data protection requirements, including operationalizing regulatory obligations into policies, procedures, assessments, documentation, training, and business guidance.

Serve as the privacy representative for new and existing business, technology, data, vendor, and AI initiatives, providing practical guidance on privacy-by-design, data minimization, appropriate data use, retention, access, sharing, and risk mitigation.

Conduct and support Privacy Impact Assessments, Data Protection Impact Assessments, and related privacy risk reviews

Work with the organization's AI Center of Excellence and related AI governance forums, including AI intake reviews, AI risk assessments, privacy reviews, documentation, approval workflows, and inventory of AI tools, use cases, models, vendors, data inputs, and decision-impacting use cases.

Maintain governance of cookie banners, consent management platforms, tracking technologies, pixels, analytics tools, website privacy notices, and digital data collection practices.

Handle the review, maintenance, publication, and periodic updates of privacy notices, disclosures, and transparency materials, and monitor for inconsistencies between notices, data inventories, PIAs, vendor reviews, consent tools, and actual business practices.

Handle the development, maintenance, and application of data classification standards, and provide guidance on data minimization, least privilege, purpose limitation, appropriate data use, secure handling, retention, and remediation of sensitive data exposure risks.

Manage and support DSR and privacy rights requests, including intake, validation, routing, response tracking, exception handling, fulfillment coordination, reporting, escalation, and continuous process improvement.

Work on privacy review of security incidents involving personal information or sensitive data, including assessment of data elements, affected populations, impacted systems, jurisdictions, contractual notice requirements, escalation needs, remediation activities, and lessons learned.

Maintain incident documentation, timelines, decision logs, evidence, remediation tracking, lessons learned, and updates to privacy incident response playbooks.

Respond to client, partner, vendor, and due diligence questionnaires related to privacy, data protection, AI, data governance, and security controls.

Support governance of enterprise platforms and business systems such as Box, Dropbox, ChatGPT, Google Drive, OneDrive, SharePoint, Salesforce, Snowflake, Zoom, and similar systems

Own or coordinate annual review of privacy and governance policies, procedures, standards, SOPs, playbooks, templates, and guidance documents.

Work on the creation, update, delivery, and tracking of privacy, data governance, and security awareness training, including targeted guidance for teams handling personal, sensitive, client, employee, or regulated data.

Track training completion, effectiveness, improvement opportunities, and related evidence, and support employee communications and privacy awareness campaigns.

Participate in committees, working groups, and governance forums involving privacy, AI, data governance, security, risk, compliance, technology, vendor management, and business operations.

Participate in planning, preparation, content development, speaker coordination, stakeholder engagement, logistics, and follow-up for the Annual Privacy Summit.


QUALIFICATIONS
EDUCATION / EXPERIENCE

Bachelor's Degree in computer science, law, information technology, business administration or related field, or equivalent combination of education and experience

Five (5) or more years of relevant experience in privacy, data governance, or a related field.

Experience supporting GDPR, U.S. state privacy laws, AI governance, cookie and consent management, security incident response, enterprise technology platforms, data inventories, records of processing activities, data classification, sensitive data handling, retention, and data governance operating models.

Experience with privacy management, GRC, consent management, data discovery, data catalog, or workflow tools such as OneTrust, Osano, TrustArc, BigID, Securiti, or similar platforms.

Experience supporting governance committees, councils, outside legal counsel coordination, audits, and executive-level reporting.

IAPP Certifications: CIPP/US, CIPP/E, CIPM, CIPT, AIGP, or similar


SKILLS

Strong working knowledge of domestic and international privacy and data protection laws and frameworks, including GDPR, CCPA/CPRA, HIPAA, PIPEDA, CAN-SPAM, NYDFS, U.S. state privacy laws, and emerging cybersecurity and AI governance requirements.

Strong cross-functional collaboration and relationship-building skills, with the ability to partner effectively with Legal, Information Security, IT, Risk, Compliance, Vendor Management, Software Development, Learning & Development stakeholders.

Strong understanding of privacy operations, including data subject rights, privacy impact assessments, privacy incidents, cookie and consent governance, privacy notices, vendor reviews, third-party data sharing, and privacy documentation.

Excellent written and verbal communication skills, including the ability to explain complex privacy, governance, legal, technical, and regulatory concepts clearly to all levels of the organization.

Ability to assess privacy and governance risks across business, technology, vendor, data, marketing, and AI initiatives and translate requirements into practical, risk-based recommendations.

Ability to develop, maintain, and adjust policies, procedures, SOPs, playbooks, templates, and controls based on regulatory requirements, risk, business needs, and operational realities.

Ability to communicate the importance of data privacy and governance as a business differentiator, core value, and compliance requirement.

Ability to create high-quality presentations, dashboards, leadership updates, training materials, evidence records, and executive-ready summaries.

Ability to remain impartial and report all issues of non-compliance.

Proficient in Microsoft Office products and comfort working with privacy, governance, GRC, consent management, data discovery, data catalog, and enterprise collaboration tools.



#LI-MH1
#LI-REMOTE