Manager, Confidentiality & Privacy - Strategic Risk

Risk Management | Strategic Risk
Same job available in 60 locations

Position Summary

Confidentiality & Privacy is seeking an experienced Manager to contribute to strategic priorities and mitigation of confidentiality and privacy risks across the Deloitte US FirmsThe successful candidate will be expected to quickly build subject matter expertise in the US Firms’ confidentiality and privacy policies while providing impactful contributions to risk identification, risk mitigation, and cross-functional response to confidentiality and privacy incidents. The successful candidate will be expected to participate and manage confidentiality and privacy initiatives designed to safeguard confidential information (CI) and protect Deloitte’s brand and reputation.

Work you’ll do

  • Participate in and lead projects to implement or enhance the US Firms’ confidentiality and privacy programs. Activities may include development of training and awareness materials, completion of Privacy Impact Assessments, management of Data Subject Access Requests, or support for other high impact C&P initiatives.
  • Contribute to the design, development, and deployment of technology solutions to enhance confidentiality and privacy processes and mitigate risk.
  • Support confidentiality and privacy program assessments and system reviews of confidentiality & privacy risks.
  • Review and advise on technical requirements, vendor solutions, and data protection features of applications and systems utilized and/or delivered by the Deloitte US Firms.
  • Provide expertise and support to data analytics efforts to identify insights, potential risks, and mitigation strategies.
  • Serve as the subject matter expert and coordinate cross-functional CI incident response teams; be an incident response leader who business teams can turn to and rely on for timely and impactful advice and resolution of issues.
  • Conduct investigation and analysis of incidents involving business technologies and provide guidance on required course of action by technology teams (e.g., ITS/ Cyber).
  • Develop in-depth understanding of the US Firms’ businesses and enabling areas to provide quick response and guidance based on the nature of the incident and potential risks to Deloitte.
  • Ensure prompt and thorough investigation and response based on incident criticality, nature, and severity. Draw out details that may not be obvious, identify proactive measures to address identified issues, and escalate matters to leadership as needed.
  • Establish and maintain open lines of communication with leadership and key stakeholders to drive follow-up through incident closure.
  • Ensure incident records are properly documented with supporting evidence that is thorough, accurate, and complete.
  • Assist with projects/strategies to enhance the US Firms’ incident management and preparedness based on emerging trends and risks.

The Team

Risk & Brand Protection (R&BP)

At Deloitte, we are stewards of reputation—ours and our clients. That’s why we foster a culture that protects, preserves, and enhances our reputation. With your help, we will distinguish Deloitte as the clear leader in professional services, making us the first choice for clients and talent.

Confidentiality & Privacy

Confidentiality & Privacy (C&P), led by the Chief Confidentiality & Privacy Officer and Managing Director, Confidentiality & Privacy, is a steward for Deloitte’s reputation. In that role, C&P is responsible for the development and deployment of a comprehensive program to mitigate confidentiality and privacy risks across the Deloitte US Firms. The team is highly collaborative, and individual contributions are measured relative to team contributions. C&P is organized around key service areas, which include:

  • Policy, Regulatory/Privacy & Data Governance
  • Insider Threat
  • Incident Management
  • Strategy and CI Program Direction
  • Technology Assessments


Required Education & Experience

  • Bachelor’s Degree; Master’s or other Advanced degree
  • 15+ years of experience, including 10+ years of related experience (quality and risk management, investigations, incident handling and response, confidentiality and privacy).
  • Direct experience in confidentiality and privacy, risk management, crisis/incident response required.
  • Prior experience in professional services, risk management, client service, consulting services, preferably with Deloitte (established knowledge/experience with infrastructure and culture).
  • Demonstrated track record of adding value through a combination of deep technical expertise, professional judgment and process/program/project ownership
  • Direct experience investigating and managing compliance and/or privacy incident response activities.
  • Knowledge of technologies used to collect, share, access and use personal data such as cookies, web beacons, data warehouse, and web analytic and decision support software.
  • Familiarity with cyber threats and potential impact on business
  • Knowledge of U.S. privacy legislation such as HIPAA, CAN-SPAM, COPPA, FCRA, GLBA, stated privacy laws, state data breach laws and the capability to apply regulatory requirements within an operational context.

Required Professional and Technical Skills

  • Highly responsive and operate with a sense of urgency when managing reported incidents, including outside normal business hours as required.
  • Demonstrated track record in sound judgment, investigation, strong attention to detail, and persistence in following/driving incidents to conclusion.
  • Excellent organizational, communications (oral and written), problem solving, and interpersonal skills.
  • Strong client service orientation - our clients expect and deserve high quality work products and effective resolution of identified issues.
  • Executive presence, strong facilitation skills
  • Remain calm while retaining your ability to influence others in high pressure situations.
  • Highly collaborative work ethic with demonstrated agility and strong teaming skills.
  • Strong project management skills while exhibiting an ability to multi-task across various initiatives and activities.
  • Quick and eager learner to apply new skills and technologies in a results-oriented manner.
  • Experience and proficiency in MS Office products to include Word, PowerPoint, Excel, and SharePoint.
  • Limited immigration sponsorship may be available

Required Licenses, Certifications, and Other Requirements

  • Certified International Privacy Professional (CIPP) or Certified Information Privacy Technologist (CIPT) certification preferred
  • Proficiency in Analytics Tools (e.g., Tableau) and Collaboration Tools (e.g., SharePoint) a plus
  • Work Location: Any Deloitte US office location

Our people and culture

Our diverse, equitable, and inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work. Learn more about our inclusive culture.

Professional development

From entry-level employees to senior leaders, we believe there’s always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career. Learn more about our commitment to developing our people.

As used in this posting, “Deloitte” means Deloitte LLP. Please see for a detailed description of the legal structure of Deloitte LLP and its subsidiaries.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.

Requisition code: 48863


Caution against fraudulent job offers!

We have been informed of instances where jobseekers are led to believe of fictitious job opportunities with Deloitte US (“Deloitte”). In one or more such cases, false promises of actual or potential selection, or initiation or completion of the recruitment formalities appear to have been or are being made. Some jobseekers appear to have been asked to pay money to specified bank accounts of individuals or entities as a condition of their selection for a ‘job’ with Deloitte. These individuals or entities are in no way connected with Deloitte and do not represent or otherwise act on behalf of Deloitte.

We would like to clarify that:

  • At Deloitte, ethics and integrity are fundamental and not negotiable.
  • We are against corruption and neither offer bribes nor accept them, nor induce or permit any other party to make or receive bribes on our behalf.
  • We have not authorized any party or person to collect any money from jobseekers in any form whatsoever for promises of getting jobs in Deloitte.
  • We consider candidates on merit and that we provide an equal opportunity to eligible applicants.
  • No one other than designated Deloitte personnel (e.g., a Deloitte recruiter or Deloitte hiring partner) is permitted to extend any job offer from Deloitte.

Anyone who at any time has made or makes any payment to any party in exchange for promises of job or selection for a job with Deloitte or any matter related to this (including those for ‘registration’, ‘verification’ or ‘security deposit’) or otherwise engages with any such person who has made or makes fraudulent promises or offers, does so (or has done so) entirely at their own risk. Deloitte takes no responsibility or liability for any such unauthorized or fraudulent actions or engagements. We encourage jobseekers to exercise caution.