Head of Compliance and Data Privacy

Unlock Employer

Posted Oct 1, 2026

Remote · US Full Time
Est. $180K – $250K/yr

Overview

This role leads global compliance, ethics, and data privacy programs and provides practical, risk-based guidance to senior leaders and business teams. Responsibilities include ownership of anti-bribery and corruption, AI governance, a global ethics hotline and whistleblowing program, the global data privacy program and privacy operations, and audit/proposal responses related to compliance and data privacy.

The position also oversees privacy operations, manages a data protection officer (DPO) relationship, serves as NSA Security Officer, and manages an allocated portion of the Legal Department budget. Success requires strong judgment, risk-management skills, and the ability to translate multi-jurisdictional requirements into clear, workable controls for a global clinical research organization.

Responsibilities

Global program leadership

  • Set priorities and plan for compliance, ethics, and data privacy programs
  • Maintain governance and reporting
  • Advise senior leaders on material risks and recommended actions

Anti-bribery and corruption

  • Develop, implement, and maintain anti-bribery and corruption policies and training
  • Advise on gifts, hospitality, sponsorships, interactions with healthcare professionals and government officials, third-party risk, and other higher-risk activities
  • Coordinate due diligence, monitoring, and remediation

AI governance

  • Lead the enterprise AI governance framework with Information Security, IT, Quality, HR, and business functions
  • Establish policies, approval and risk-assessment processes, inventories, and accountability
  • Assess privacy, security, ethical, and regulatory impacts
  • Provide responsible-use advice and training

Ethics and whistleblowing

  • Oversee the global Ethics hotline and Whistleblowing Policy, including:
    • Intake and triage
    • Conflict checks
    • Non-retaliation safeguards
    • Coordination of investigations
    • Documentation, remediation, and trend reporting
  • Ensure processes align with confidentiality, privilege, and local law

Data privacy program and privacy operations

  • Manage and oversee privacy policies and notices
  • Oversee records of processing, privacy impact and transfer assessments, data subject requests, and retention/deletion
  • Support international transfers and privacy by design
  • Manage third-party privacy risk and workforce training

Personal-data incident workstream

  • Lead the privacy workstream for suspected personal-data incidents, including assessment, documentation, escalation, and notification advice
  • Coordinate investigation, containment, remediation, and lessons learned

DPO service/relationship oversight

  • Manage and oversee DPO service scope, priorities, information flow, resources, and follow-through
  • Ensure the DPO can perform statutory duties with independence and regulatory compliance

Privacy Aviator ownership

  • Serve as Business Owner for Privacy Aviator, including:
    • Configuration
    • Access
    • Data quality
    • User adoption
    • Reporting
    • Process improvement
    • Coordination with the provider and internal system owners

NSA Security Officer responsibilities

  • Coordinate applicable security and compliance obligations, including governance, records, reporting, training, and escalation of potential issues

Audits and assurance

  • Lead responses to internal, client, and regulatory audit requests related to compliance and data privacy
  • Coordinate evidence, protect confidential and privileged material, ensure accurate responses
  • Agree corrective actions and track remediation to closure

Proposals and client support

  • Own or approve compliance and data privacy content for proposals, requests for information, due diligence, and assurance questionnaires
  • Coordinate accurate, consistent, supportable commitments
  • Advise on related privacy and security terms when requested

Regulatory change

  • Monitor regulatory developments affecting clinical research, anti-bribery and corruption, whistleblowing, data protection, and AI across company jurisdictions
  • Assess business impact, recommend implementation plans, and provide timely advice and training

SOP ownership and training

  • Own and review assigned global SOPs, policies, work instructions, and supporting materials
  • Ensure approval, document control, implementation, training assignment, completion monitoring, and evidence of effectiveness with Quality and functional owners

Budget, providers, and reporting

  • Manage the assigned Legal budget, including forecasting, accruals, invoice review, and variance management
  • Oversee outside counsel, the DPO, and specialist providers
  • Define service expectations, control costs, and ensure timely delivery

Legal and cross-functional support

  • Conduct legal and regulatory research and collaborate across functions and geographies
  • Resolve compliance, privacy, and information-security issues
  • Support risk-balanced decisions
  • Perform other responsibilities assigned by Legal or executive leadership consistent with the role

Supervisory responsibilities

  • Directly supervises the Privacy Manager and other compliance or privacy staff as assigned
  • Includes recruitment, priority setting, work allocation, coaching, development, reward and performance management, and workload oversight
  • Manages the DPO relationship and external providers while preserving the DPO’s required independence and access to senior management

Requirements

Education and professional qualification

  • Juris Doctor or equivalent law degree from ABA-accredited law school; or equivalent advanced degree in compliance, privacy, information governance, or a closely related field
  • Admission and good standing as a lawyer in at least one jurisdiction, where applicable
  • Professional certification demonstrating subject-matter expertise (e.g., CIPP, CIPM, CCEP, AIGP)

Experience

  • 10+ years of progressively responsible law firm and/or in-house experience in compliance, privacy, ethics, information governance, or a related field, including leadership or managerial experience
  • Experience designing and improving global programs and policies, including relevant control and training for compliance and privacy, anti-bribery and corruption, whistleblowing, investigations, ethics hotlines, as well as regulatory change, audits, and external advisers
  • Experience with AI governance, privacy technology, data incidents, and cross-functional risk management is strongly preferred
  • CRO, biopharma, or clinical research experience is preferred

Skills and competencies

  • Strong legal, compliance, and business judgment; able to identify material risk and recommend practical solutions while preserving appropriate independence
  • Working knowledge of major global privacy (GDPR, CCPA, etc.), anti-bribery (FCPA, UK Bribery Act, etc.), whistleblowing, and AI frameworks, with the ability to apply requirements across jurisdictions
  • Excellent communication skills, including policy and SOP drafting, executive advice, investigation documentation, training, and presentations
  • Strong program management, prioritization, follow-through, and attention to detail across concurrent matters
  • Ability to assess privacy, security, and compliance terms; negotiate risk-balanced positions; and communicate commitments clearly
  • High integrity, discretion, and fairness, with sound handling of confidentiality, privilege, conflicts, and non-retaliation obligations
  • Strong analytical and problem-solving skills; uses data and trends to identify risk and improve controls
  • Collaborative, culturally aware, and able to influence across functions, regions, and levels

Capabilities

  • Acts as a trusted, independent adviser to Legal, executive leadership, and business teams
  • Translates complex requirements into clear policies, controls, workflows, and training
  • Leads through influence and develops others through expectations, coaching, and delegation
  • Works effectively with regulators, client stakeholders, auditors, counsel, and technology providers
  • Balances strategic leadership with hands-on resolution of compliance and privacy matters
  • Adapts quickly in a fast-paced environment, prioritizes under pressure, and escalates risk early
  • Ability to “roll up sleeves” and keep a dynamic team operating smoothly

Preferred Qualifications

  • Experience with AI governance, privacy technology, data incidents, and cross-functional risk management
  • CRO, biopharma, or clinical research experience

Compensation & Benefits

  • Budget management includes forecasting, accruals, invoice review, and variance management for an allocated portion of the Legal Department budget. (Additional compensation and benefits details were not provided.)

Location

  • United States — Remote

Don't miss out on remote legal roles