Overview
This role leads global compliance, ethics, and data privacy programs and provides practical, risk-based guidance to senior leaders and business teams. Responsibilities include ownership of anti-bribery and corruption, AI governance, a global ethics hotline and whistleblowing program, the global data privacy program and privacy operations, and audit/proposal responses related to compliance and data privacy.
The position also oversees privacy operations, manages a data protection officer (DPO) relationship, serves as NSA Security Officer, and manages an allocated portion of the Legal Department budget. Success requires strong judgment, risk-management skills, and the ability to translate multi-jurisdictional requirements into clear, workable controls for a global clinical research organization.
Responsibilities
Global program leadership
- Set priorities and plan for compliance, ethics, and data privacy programs
- Maintain governance and reporting
- Advise senior leaders on material risks and recommended actions
Anti-bribery and corruption
- Develop, implement, and maintain anti-bribery and corruption policies and training
- Advise on gifts, hospitality, sponsorships, interactions with healthcare professionals and government officials, third-party risk, and other higher-risk activities
- Coordinate due diligence, monitoring, and remediation
AI governance
- Lead the enterprise AI governance framework with Information Security, IT, Quality, HR, and business functions
- Establish policies, approval and risk-assessment processes, inventories, and accountability
- Assess privacy, security, ethical, and regulatory impacts
- Provide responsible-use advice and training
Ethics and whistleblowing
- Oversee the global Ethics hotline and Whistleblowing Policy, including:
- Intake and triage
- Conflict checks
- Non-retaliation safeguards
- Coordination of investigations
- Documentation, remediation, and trend reporting
- Ensure processes align with confidentiality, privilege, and local law
Data privacy program and privacy operations
- Manage and oversee privacy policies and notices
- Oversee records of processing, privacy impact and transfer assessments, data subject requests, and retention/deletion
- Support international transfers and privacy by design
- Manage third-party privacy risk and workforce training
Personal-data incident workstream
- Lead the privacy workstream for suspected personal-data incidents, including assessment, documentation, escalation, and notification advice
- Coordinate investigation, containment, remediation, and lessons learned
DPO service/relationship oversight
- Manage and oversee DPO service scope, priorities, information flow, resources, and follow-through
- Ensure the DPO can perform statutory duties with independence and regulatory compliance
Privacy Aviator ownership
- Serve as Business Owner for Privacy Aviator, including:
- Configuration
- Access
- Data quality
- User adoption
- Reporting
- Process improvement
- Coordination with the provider and internal system owners
NSA Security Officer responsibilities
- Coordinate applicable security and compliance obligations, including governance, records, reporting, training, and escalation of potential issues
Audits and assurance
- Lead responses to internal, client, and regulatory audit requests related to compliance and data privacy
- Coordinate evidence, protect confidential and privileged material, ensure accurate responses
- Agree corrective actions and track remediation to closure
Proposals and client support
- Own or approve compliance and data privacy content for proposals, requests for information, due diligence, and assurance questionnaires
- Coordinate accurate, consistent, supportable commitments
- Advise on related privacy and security terms when requested
Regulatory change
- Monitor regulatory developments affecting clinical research, anti-bribery and corruption, whistleblowing, data protection, and AI across company jurisdictions
- Assess business impact, recommend implementation plans, and provide timely advice and training
SOP ownership and training
- Own and review assigned global SOPs, policies, work instructions, and supporting materials
- Ensure approval, document control, implementation, training assignment, completion monitoring, and evidence of effectiveness with Quality and functional owners
Budget, providers, and reporting
- Manage the assigned Legal budget, including forecasting, accruals, invoice review, and variance management
- Oversee outside counsel, the DPO, and specialist providers
- Define service expectations, control costs, and ensure timely delivery
Legal and cross-functional support
- Conduct legal and regulatory research and collaborate across functions and geographies
- Resolve compliance, privacy, and information-security issues
- Support risk-balanced decisions
- Perform other responsibilities assigned by Legal or executive leadership consistent with the role
Supervisory responsibilities
- Directly supervises the Privacy Manager and other compliance or privacy staff as assigned
- Includes recruitment, priority setting, work allocation, coaching, development, reward and performance management, and workload oversight
- Manages the DPO relationship and external providers while preserving the DPO’s required independence and access to senior management
Requirements
Education and professional qualification
- Juris Doctor or equivalent law degree from ABA-accredited law school; or equivalent advanced degree in compliance, privacy, information governance, or a closely related field
- Admission and good standing as a lawyer in at least one jurisdiction, where applicable
- Professional certification demonstrating subject-matter expertise (e.g., CIPP, CIPM, CCEP, AIGP)
Experience
- 10+ years of progressively responsible law firm and/or in-house experience in compliance, privacy, ethics, information governance, or a related field, including leadership or managerial experience
- Experience designing and improving global programs and policies, including relevant control and training for compliance and privacy, anti-bribery and corruption, whistleblowing, investigations, ethics hotlines, as well as regulatory change, audits, and external advisers
- Experience with AI governance, privacy technology, data incidents, and cross-functional risk management is strongly preferred
- CRO, biopharma, or clinical research experience is preferred
Skills and competencies
- Strong legal, compliance, and business judgment; able to identify material risk and recommend practical solutions while preserving appropriate independence
- Working knowledge of major global privacy (GDPR, CCPA, etc.), anti-bribery (FCPA, UK Bribery Act, etc.), whistleblowing, and AI frameworks, with the ability to apply requirements across jurisdictions
- Excellent communication skills, including policy and SOP drafting, executive advice, investigation documentation, training, and presentations
- Strong program management, prioritization, follow-through, and attention to detail across concurrent matters
- Ability to assess privacy, security, and compliance terms; negotiate risk-balanced positions; and communicate commitments clearly
- High integrity, discretion, and fairness, with sound handling of confidentiality, privilege, conflicts, and non-retaliation obligations
- Strong analytical and problem-solving skills; uses data and trends to identify risk and improve controls
- Collaborative, culturally aware, and able to influence across functions, regions, and levels
Capabilities
- Acts as a trusted, independent adviser to Legal, executive leadership, and business teams
- Translates complex requirements into clear policies, controls, workflows, and training
- Leads through influence and develops others through expectations, coaching, and delegation
- Works effectively with regulators, client stakeholders, auditors, counsel, and technology providers
- Balances strategic leadership with hands-on resolution of compliance and privacy matters
- Adapts quickly in a fast-paced environment, prioritizes under pressure, and escalates risk early
- Ability to “roll up sleeves” and keep a dynamic team operating smoothly
Preferred Qualifications
- Experience with AI governance, privacy technology, data incidents, and cross-functional risk management
- CRO, biopharma, or clinical research experience
Compensation & Benefits
- Budget management includes forecasting, accruals, invoice review, and variance management for an allocated portion of the Legal Department budget. (Additional compensation and benefits details were not provided.)
Location