About this role
Essential Job Duties and Responsibilities: At International SOS, we are in the business of protecting and saving lives. For 40 years, we have delivered customised security risk management, health, and wellbeing solutions to organisations worldwide. With a presence in 90 countries and a team of nearly 13,000 experts, we provide 24/7 support to help organisations fulfil their Duty of Care responsibilities. Now, we’re looking for talented individuals to join our team and make a difference. The Privacy Director, Government Services, US plays a key role in ensuring consistently high standards of data protection and regulatory compliance across the organisation, supporting business development and change through robust and pragmatic privacy governance. This role is suited to an individual that is hands-on, solutions-focused, and pragmatic, with a preference for technical knowledge. Key Responsibilities: Strategically Oversee and Advise on Privacy Risk Mitigation: Lead the identification and mitigation of privacy risks across new and existing products, services, and processes. Develop pragmatic compliance measures and remedial action plans that balance business objectives with regulatory requirements. Manage and Optimise Privacy Processes: Oversee the use of the centralised privacy management platform (e.g. OneTrust) to manage privacy processes efficiently. Provide expert guidance to stakeholders to ensure the platform is used effectively and compliance is maintained across the organisation. Act as a Privacy Lead in Incident Response: Coordinate with Legal, Information Security, Contracts, and Government Program leadership to ensure compliance with contractual breach notification timelines, regulatory reporting (e.g., HHS, state AGs), and federal agency reporting obligations. Serve as the primary point of contact for data incidents, guiding the organisation’s response efforts and ensuring that regularly and client notification are made promptly. Conduct thorough risk assessments and support the development of incident response strategies that minimise harm and ensure regulatory compliance. Lead Cross-Functional Privacy Projects: Coordinate and drive privacy-related projects across multiple business units and functions, ensuring timely completion of Records of Processing Activities (RoPA), Data Protection Impact Assessments (DPIAs), and other critical assessments. Support and Enhance Third-Party Risk Management: Collaborate with Information Risk Management to evaluate and manage third-party vendors, ensuring their compliance with data protection regulations. Provide strategic input into third-party risk assessments and remediation plans. Provide Regular Status Reports on the Privacy Programme: Regularly update senior leadership on the status of the privacy programme, including identified risks, remediation strategies, and ongoing compliance efforts. Ensure transparency and accountability in privacy management. Guide and Support Data Management Practices: Support managers in maintaining accurate and up-to-date Personal Data Processing Inventory records. Ensure that records meet regulatory requirements and support organisational compliance. Monitor and Enhance Data Subject Rights Request (DSRR) Processes: Monitor Data Subject Rights Requests and handle inquiries from data subjects, clients, and other stakeholders. Ensure that all requests are managed efficiently and in compliance with applicable laws. Stay Informed on Regulatory Changes and Best Practices: Continuously monitor changes in privacy regulations and industry best practices. Communicate relevant updates to stakeholders and ensure the organisation’s policies and practices remain up-to-date and compliant. Advise on Vendor Compliance and Contract Negotiations: Provide advice on vendors’ compliance with data protection regulations. Support contract negotiations to ensure that data privacy requirements are appropriately addressed and enforced. Review and Develop Privacy Training Programmes: Collaborate with the learning and development teams to regularly review and enhance privacy training programmes. Ensure that all employees understand their privacy responsibilities and are equipped to handle them effectively. AI Governance: Support implementation of AI governance and responsible data use frameworks in coordination with Group Head of Privacy & AI Governance, including risk assessments for AI-enabled solutions used in government healthcare delivery. Required Experience and Knowledge Extensive Privacy and Data Protection Experience: A minimum of 3 years of experience in data privacy roles. Experience should cover areas such as data protection impact assessments (DPIAs), cross-border data transfers, privacy by design in digital products, and managing data breaches. Regulatory Compliance Expertise: Proven track record of ensuring compliance with global privacy regulations such as GDPR and US specific federal and state regulations including HIPAA, the Texas Data Privacy and Security Act, US Federal Acquisition Regulations and other relevant laws. Experience and managing internal and external audits is essential. Pragmatic Risk Management: Proven ability to assess privacy risks pragmatically, balancing legal requirements with business needs. Experience in conciliatory risk management, where appropriate, to achieve outcomes that consider the interests of all stakeholders, including clients, data subjects, and regulators. Technical Knowledge in Privacy Engineering: Experience working closely with technical teams, such as IT, Information Security, and Product Development, to embed privacy by design principles into digital applications. Familiarity with privacy technologies and platforms, such as OneTrust, is preferred. Project Management in Complex Environments: Experience in managing large-scale privacy projects across multiple regions or business units, often in a matrixed organisation. Proven ability to manage cross-functional teams and drive projects to successful completion. Vendor and Third-Party Risk Management: Experience in evaluating and managing third-party vendors for compliance with data protection regulations, including conducting due diligence, risk assessments, and supporting contract negotiations. Crisis Management and Incident Response: Hands-on experience in managing data breaches and privacy incidents, including conducting risk assessments, coordinating responses, and ensuring timely notifications to affected parties and regulators. Oversee Tricare Privacy Officer who manages incidents and compliance specific to the Tricare Overseas Program platform. Training and Development: Experience in developing and delivering privacy training programmes to various stakeholders within an organisation, ensuring that all relevant parties understand and can apply privacy principles in their roles. Required Qualifications Data Protection Practitioner Certification or equivalent (eg. CIPP/US, CIPM, CIPT) Required Languages Full professional command of English Travel Requirements International travel, based on business requirements