At a Glance
- Tasks: Lead privacy operations and implement global privacy policies at Thomson Reuters.
- Company: Join a leading global information provider with a commitment to privacy and compliance.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Dynamic role with opportunities to collaborate across various departments.
- Why this job: Make a real impact on privacy practices while working with cutting-edge technology.
- Qualifications: Experience in privacy law, data protection, and team leadership required.
The predicted salary is between 66150 - 80850 £ per year.
Thomson Reuters is seeking an experienced Privacy Operations Manager to join our General Counsel's Office. Reporting to the Chief Privacy Officer, this role presents an exciting opportunity to operationalize our global privacy program across Thomson Reuters.
This role will lead a team of privacy operations specialists and be responsible for implementing privacy policies, managing day-to-day privacy operations, and ensuring compliance with global data protection and cybersecurity regulations including regional (GDPR, NIS2, Digital Services/Markets Act), federal (PIPEDA, UK GDPR), U.S. State (CCPA), provincial (Quebec's Law 25) and sectoral (HIPAA, GLBA, FedRamp, CJIS, etc.) privacy regulation, and other applicable data protection laws.
This role will also manage the operational aspects of cyber incident management, coordinate incident response activities and ensure effective execution of the organization's cyber incident response processes. The ideal candidate will bridge the gap between privacy law, technology and strategy, working cross-functionally to embed privacy practices throughout the organization and drive automation, leveraging the use of AI and other tools to operationalize privacy compliance across products, services and functions.
About the Role
In this opportunity as a Privacy Operations Manager, you will lead:
- Privacy Program Management
- Oversee the day-to-day operations of Thomson Reuters' global privacy program
- Implement privacy policies, procedures, and operational frameworks
- Conduct or facilitate the conduct of risk assessments, including privacy impact assessments (PIAs), data protection impact assessments (DPIAs), transfer impact assessments (TIAs)
- Coordinate responses to data subject access requests (DSARs) and ensure timely resolution
- Track and report on privacy program metrics and KPIs
- Privacy Compliance & Risk Management
- Track and report changes in new/existing privacy regulations and monitor compliance with key regulations including GDPR, CCPA, PIPEDA, among others
- Build out and maintain data inventory, and data mapping initiatives
- Identify privacy risks and work with stakeholders to implement mitigation strategies
- Support privacy incident response and breach notification processes
- Conduct privacy audits and assessments of internal processes and third-party vendors
- Cyber Incident Management
- Support the day-to-day operational execution of the cyber incident response program, including intake, triage, and escalation of security incidents with privacy implications
- Support cross-functional coordination with Information Security, IT, Legal, and Business teams during active incidents to ensure timely containment, remediation, and communication
- Support legal assessment of incidents to determine breach notification obligations under applicable privacy and data protection regulations, and drive timely notification to affected individuals and regulators
- Maintain and continuously improve incident response playbooks, runbooks, and operational procedures for cyber incidents
- Privacy-by-Design and Cross-Functional Collaboration
- Partner with Legal, Information Security, IT, Product, and Business teams to integrate and operationalize privacy-by-design principles and guidance into the product development cycle
- Serve as a privacy subject matter expert and advisor to business units
- Facilitate privacy training and awareness programs for employees
- Work with vendors and partners to ensure contractual privacy obligations are met
- Identify current sub-processors and update contractual documentation to reflect current state
- Documentation & Reporting
- Maintain records of processing activities (ROPA) and privacy documentation
Privacy Operations Manager employer: PowerToFly
At PowerToFly, we pride ourselves on being an exceptional employer, offering a dynamic work culture that fosters collaboration and innovation in the surgical equipment sector. Our Camberley location provides a vibrant environment with ample opportunities for professional growth, supported by comprehensive training and development programmes. We value our employees' contributions and offer competitive benefits, making us a rewarding place to build a meaningful career.
StudySmarter Expert Advice🤫
We think this is how you could land Privacy Operations Manager
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like PowerToFly looking for candidates who are engaged and informed.
We think you need these skills to ace Privacy Operations Manager
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at PowerToFly. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at PowerToFly
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with PowerToFly’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!