Privacy & Data Protection Analyst

• Posted 1 day ago • Updated 10 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Innovation
  • Information Security
  • Information Governance
  • Procurement
  • Negotiations
  • Risk Management
  • Management
  • Risk Assessment
  • Auditing
  • Artificial Intelligence
  • Collaboration
  • Data Governance
  • Data Security
  • Data Processing
  • Data Flow
  • Documentation
  • HIPAA
  • ISO/IEC 27001:2005
  • NIST SP 800 Series
  • Writing
  • Stakeholder Management
  • Legal
  • Attention To Detail
  • Privacy
  • CISSP
  • CISA
  • CISM
  • ISACA
  • Professional Services
  • Customer Service
  • Insurance
  • Regulatory Compliance
  • SAP BASIS
  • Law

Summary

King & Spalding is a leading global law firm with a commitment to excellence, innovation, and the seamless delivery of legal services. We harness innovative technology and exceptional talent to meet the complex needs of our clients in a fast-paced and dynamic legal landscape.

We are seeking a Privacy & Data Protection Analyst to support and mature the firm's privacy program. This role will work closely with Information Security, Legal, Information Governance, Procurement, HR, the Privacy Committee, and other business stakeholders to help the firm govern, protect, and responsibly use personal information, including client information, employee HR data, PHI, Controlled Unclassified Information (CUI), and other regulated or sensitive data types.

KEY RESPONSIBILITIES:


  • Support the firm's privacy program, including Privacy Committee meeting coordination, agenda and materials preparation, follow-up tracking, privacy program updates, and governance documentation.

  • Support the review and negotiation of vendor and client privacy requirements, including Data Processing Agreements (DPAs), data transfer terms, privacy provisions within client agreements and Outside Counsel Guidelines, AI-related requirements, and other contractual data protection obligations.

  • Assess how vendors and software tools collect, use, store, share, and protect sensitive privacy-related information as part of the firm's third-party risk management program

  • Complete client privacy and AI assessments and questionnaires, working with internal stakeholders to demonstrate the firm's controls and help ensure clients remain confident that their sensitive information is appropriately protected.

  • Manage and improve operational privacy processes, including data subject access request intake, tracking, and coordination; cookie and consent management; privacy notice updates; and privacy-related policy maintenance.

  • Lead governance activities for regulated and controlled information types, such as HIPAA-regulated PHI and Controlled Unclassified Information (CUI), including advising teams on the handling of especially sensitive matters, by coordinating compliance assessments, supporting initiatives such as HIPAA Security Risk Assessments and CMMC audits, and driving remediation and program maturity efforts.

  • Analyze highly sensitive or high-risk matters (e.g., significant PII, PHI, or sensitive government/regulatory matters) and advise engagement teams on appropriate data handling, access, and protection measures.

  • Maintain awareness of relevant privacy, data protection, AI, and regulated data requirements in jurisdictions where the firm operates, and translate changes into practical guidance for internal stakeholders.

  • Own core privacy governance activities in OneTrust, including ROPAs, PIAs/DPIAs, TIAs, vendor and application privacy assessments, data flow documentation, privacy risk tracking, remediation coordination, and stakeholder guidance.



QUALIFICATIONS:


  • Bachelor's degree in a related field or equivalent professional experience.

  • 3+ years of experience supporting privacy, data protection, or regulated data governance programs.

  • Working knowledge of privacy and data protection concepts, including personal information, protected health information, data processing agreements, data transfers, data subject rights, privacy notices, and records of processing or data flow documentation.

  • Experience reviewing privacy or security terms in vendor agreements, client contracts, or similar contractual documents.

  • Familiarity with privacy and security frameworks or requirements such as HIPAA, GDPR/UK GDPR, U.S. state privacy laws, NIST, ISO 27001, NIST 800-171, or CMMC.

  • Strong writing, organization, and stakeholder management skills, with the ability to keep work moving across legal, technical, and business teams.

  • Sound judgment, attention to detail, and the ability to apply privacy and security requirements in a practical, business-aware manner.

  • Privacy, security, or risk certifications such as CIPP/US, CIPP/E, CIPM, CIPT, CISSP, CISA, CISM, CRISC, or related credentials preferred.

  • Experience in a law firm, professional services, regulated industry, or client-service environment preferred.



The firm offers a generous total compensation package with bonuses and raises awarded in recognition of individual merit-based performance. All full-time Business Services employees may participate in King & Spalding's comprehensive benefit program including health and wellness plan, life and disability insurance, flexible spending accounts and a health savings account, a 401(k) plan, profit sharing plan, and a substantial Paid Time Off (PTO) program.

King & Spalding LLP (K&S) is committed to providing equal employment opportunity to all applicants and employees in full compliance with all state, federal, and local laws prohibiting discrimination on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, age, disability or any other status protected by applicable law.

We are proud of our remarkably cohesive culture, which now encompasses more than 2,500 lawyers and business professionals worldwide. We seek to attract and develop the very best talent to work with us.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90922487
  • Position Id: 24739443
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Atlanta, Georgia

Today

Full-time

Atlanta, Georgia

Today

Full-time

Compensation information provided in the description

Atlanta, Georgia

Yesterday

Easy Apply

Contract, Third Party

Depends on Experience

Remote

Today

Full-time

Search all similar jobs