Data Governance, Risk, and Compliance Officer
Listed on 2026-03-02
-
IT/Tech
Data Security, Information Security
Data Governance, Risk, and Compliance Officer
Location:
New York (Other locations: Anywhere in Region)
At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
OverviewThe Data Governance, Risk and Compliance Officer (“Officer”) will be responsible for developing and implementing the US Firm’s data governance strategy with regard to alignment and compliance with relevant laws and regulations. This position requires a strategic thinker with excellent communication skills to instill confidence in both internal and external audiences.
The OpportunityThis role involves creating and maintaining strong relationships with key stakeholders, within EYUS, including but not limited to the US Management Committee ("USMC"), the Ethics, Compliance, and Risk Management Sub-Committee ("ECRM SC"), US General Counsel’s Office ("GCO"), US Chief Information Officer ("CIO"), US Chief Technology Officer ("CTO"), US Chief Data Officer ("CDO"), Global Data Stewardship Office ("DSO"), Global Data Privacy Counsel, and various other Global, Area, and Region leaders.
Position is expected to interface with executive leaders and must be able to demonstrate an expanded knowledge of data governance, risk, and compliance, as well as privacy and data protection policies, communicate processes/activities, identify and provide solutions for addressing issues and mitigate risk factors associated with these initiatives.
Oversee the Data Protection Leader and teams, including assigning work and reviewing performance which may require leadership of virtual teams engaged in carrying out aspects of data governance, risk, and compliance initiatives.
Your key responsibilities- Strategy Development
:
Develop and implement the US Firm’s overall data governance strategy, risk and compliance programs, and related policies, processes, and procedures. - Stakeholder Relationships: Create and maintain strong and effective relationships with key stakeholders, including EYUS, USMC/ECRM, US General Counsel’s Office, US CIO, US CTO, US CDO, Global CDO, Global DSO, Records and Information Management Leader, Enterprise Risk Management (ERM) Leader, Global Data Enablement Leader, Global Data Privacy Counsel, Global Chief Info Sec Officer, and Data Privacy/Protection Leaders in each applicable Region/Member Firm.
- Compliance Leadership: Working with the Data Protection Leader, oversee the EYUS activities for compliance with applicable data-related laws, including cyber/Info Sec, in accordance with EYUS’s overall Compliance Program Framework.
- Data Governance and Process Improvement: Continuously manage and monitor adherence to data governance policies and regulatory requirements. Identify opportunities to improve manual processes and implement automation where possible to enhance data management efficiency. Support the office of the CIO to enhance data governance and streamline data management processes in alignment with data-related laws and needs.
- Advisory Role
:
Advise management and business on best practices for data governance, data risk, and compliance with relevant laws and regulations. - Policy Development: Support and oversee development and implementation of policies and procedures for managing data within EYUS, including any required additional US supplements to Global policies.
- Regulatory Updates
:
Keep up to date with changes to data-related laws. - Point of Contact: In conjunction with the General Counsel’s Office and Data Protection Leader, serve as the main point of contact between the Firm and the relevant data protection authorities.
- Risk Assessment: Identify and assess the Firm’s existing and emerging data governance and compliance related risks as part of the Compliance Program Framework and Firm’s Enterprise Risk Management strategy and programs.
- Risk Management program
:
Work closely with relevant stakeholders to develop and implement strategies to mitigate these risks, ensuring compliance with legal and regulatory requirements. This includes understanding the root cause of data…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).