EY Data Privacy and Protection Senior Associate in New York, New York

Data Privacy and Protection Senior Associate

Core Business Services

Requisition # NEW00KZ1

Post Date 3 days ago

Join our Core Business Services (CBS) team and you will help support the important business enablement functions that keep our organization running strong. As a CBS professional, you will work across teams to provide the knowledge, resources and tools that help EY deliver exceptional quality service to our clients, win in the marketplace and support EY’s growth and profitability. Major teams within CBS include Finance, Information Technology, Human Resources, Enterprise Support Services, Brand Marketing and Communications, Business Development, Knowledge and Risk Management.

Join our Risk Management team and help protect EY from risks that arise from its professional practice. Risk Management teams provide coordinated advice and assistance on independence, conflicts, regulatory and risk management issues, as well as dealing with claims, and any queries regarding the organization’s ethics. You’ll help us meet our compliance responsibilities while supporting our client-facing teams as they deliver quality service to their clients.

With so many offerings, you have the opportunity to develop your career through a broad scope of engagements, mentoring and formal learning. That’s how we develop outstanding leaders who team to deliver on our promises to all of our stakeholders, and in so doing, play a critical role in building a better working world for our people, for our clients and for our communities. Sound interesting? Well this is just the beginning. Because whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.

Ernst & Young LLP, an equal employment opportunity employer (Females/Minorities/Protected Veterans/Disabled), values the diversity of our workforce and the knowledge of our people. To learn more about career opportunities at Ernst & Young, please visit us at www.ey.com/careers .

The global Ernst & Young organization is a leader in assurance, tax, transaction and advisory services. The insights and quality services we deliver help build trust and confidence in the capital markets and in economies the world over. We develop outstanding leaders who team to deliver on our promises to all of our stakeholders. In so doing, we play a critical role in building a better working world for our people, for our clients and for our communities.

Job Summary:

Position Summary:

This position supports the EY Data Protection (Confidentiality, Data Privacy) function by supporting the development, implementation and monitoring of various activities within the EY data protection program. The position will participate in various stakeholder discussions regarding laws, regulations and broad data industry practices and consider the resulting changes to firm policies, procedures, training, awareness and monitoring activities.

The position will recommend various creative solutions participating in discussions regarding these recommendations to various stakeholders. The position will also respond to, investigate and document data loss, theft or other related matters. In that capacity this individual will assess risk with these cases, engaging with the related stakeholders and inputting cases into the case management system and maintaining the accuracy of the data in a timely manner.

The position will assist in the coordination and reporting of various Data Privacy and Data Protection activities to stakeholders. The position interacts with executive level personnel.

Essential Functions of the Job:

  • Supports in the evaluation of data protection processes for certain service offerings and functions.

· Promotes data protection awareness efforts that address law/policy and provide guidance on the development of local policy.

  • Develops various awareness communications and assists with maintaining the data protection communication plan

  • Assists with conducting Data Protection/Privacy Impact Assessments (PIAs)

  • Conducts data protection and data privacy research anddrafts policies and/or awareness materials

  • Identify and extract key issues and risks related to the risk management function or process by comparing facts and circumstances to current firm policies

  • Understand complex, non-routine questions from client teams regarding data protection and coordinates appropriate responses through consultation

  • Propose suggestions and solutions for improvement and/or develop new approaches and/or policies/guidance by leveraging their knowledge of existing risk management processes and business experience

· Conducts data protection vendor assessments collaborating with EY’s IT Risk, Information Security, Service Lines, functional teams as well as other stakeholders

  • Interacts with various service line quality teams in all of the above processes so as to understand and recommend enhancements to various policy or awareness efforts

  • Maintain and expand current knowledge of field of expertise and communicates new developments and resulting impact to clients and team members.

  • Develop relationships and builds a network of people within the team and across the firm

  • Other ad hoc related projects, as assigned

Analytical/Decision Making Responsibilities :

· Position applies judgment to initial or escalated consultations and/or submission reviews and has an enhanced understanding of key requirements of firm and data protection programs, procedures and policies.

  • Leadership of local or virtual teams, demonstrating natural authority

  • Understanding of key requirements of firm and regulator’s data privacy and data protection

  • Ability to drive and adapt to change

  • Strong communication skills, as well as listening and interpretation skills

  • Develop a broad knowledge of the firm and its practices

  • Ability to successfully handle multiple projects and initiatives simultaneously

  • Will reference existing policies and their knowledge and experience to review unique and complex situations and, through specific consultation and inquiries of the client team, propose solutions to issues.

  • May receive escalated matters or sensitive transactions to respond to or process.

Knowledge and Skills Requirements:

· Ability to learn and understand the firm and data protection polices as well as familiarity with other risk management initiatives outside of area of expertise

  • Ability to manage tasks and activities in a timely manner and be responsible for specific outcomes

  • Strong knowledge of firm and regulators’ data privacy and protection rules and policies as well as familiarity with other RM initiatives outside of their specific RM area.

  • Requires a solid understanding of relevant firm business and area wide privacy issues and concerns.

  • Requires an understanding the high level technology issues surrounding information security as well as the firm’s application architecture for those applications which process personal or client confidential data.

  • Basic knowledge of project management tools and methodologies

  • Problem solving, flexibility and initiative

  • Ability to keep confidential sensitive information

  • Strong research and communications skills

  • Good working knowledge of computers and common software packages including analytical tools

Supervision Responsibilities:

· Position works independently with minimal feedback to conduct necessary research or client outreach.

  • Expected to interface with executive leaders and must be able to demonstrate expanded knowledge of one or more risk management Functional areas while communicating processes, identifying and providing solutions for mitigating risk factors associated with quality & risk management initiatives.

  • May take responsibility for a discreet component(s) of a project and work independently with periodic feedback.

  • Risk Management Senior Associate may assist in the training of Associates and/or Intern to familiarize these individuals with firm processes and policies and enable these members to handle more complex issues.

Other Requirements:

Overtime will be required throughout the year and will vary based on volume

Job Requirements:


  • Bachelor’s degree or equivalent work experience


  • Approximately 3-5 years related experience

Certification Requirements:

  • Privacy certification and compliance certification preferred

EY, an equal employment opportunity employer (Females/Minorities/Protected Veterans/Disabled), values the diversity of our workforce and the knowledge of our people.