* Privacy Strategy & Governance: Define and execute a comprehensive privacy strategy aligned with business goals, regulatory requirements, and industry best practices. * Regulatory Compliance: Responsible for compliance with global privacy laws (e.g., SEC Regulation S‑P, GLBA, CCPA/CPRA, GDPR, PIPEDA, state-level privacy laws), including AI tools, models, and workflows. Monitor regulatory changes and lead organizational readiness. * Policy Development: Create, maintain, and enforce privacy policies, standards, and data-handling procedures across the enterprise, and develop and report on compliance metrics. * Risk Management: Lead privacy risk assessments, DPIAs, vendor risk reviews, and audits. Identify gaps and drive remediation. * AI Policies and controls: Develop and implement AI‑specific data‑handling policies and controls, including rules for input restrictions, redaction, anonymization, retention, and secure storage of AI‑generated or AI‑processed data, as well as controls for access management, monitoring, and employee training on safe and compliant AI usage. * Data Protection Operations: Oversee processes for data subject rights, consent management, data retention and deletion, breach response, privacy-by-design, and use of data in AI. * Incident Response Leadership: Assist in managing response to privacy incidents, coordinating with security and communications teams. * Cross-Functional Collaboration: Partner with Compliance, Technology, the People Team, and Marketing to embed privacy into systems, products, and workflows.