Job Description
We are looking for a Data Compliance Manager (Privacy & Security) to support the Group in implementing and maintaining effective data privacy and information security compliance practices across its global operations.
The role will work closely with Legal, R&D, Operations, Product, and other business functions to translate regulatory and internal policy requirements into practical processes, controls and day-to-day practices. The role will have a balanced focus on data privacy implementation and assurance, as well as cybersecurity governance and compliance oversight.
What You'll Do:
Data Privacy (50%)
- Translate data privacy policies, legal requirements and regulatory expectations into practical operational processes and controls, working closely with legal and relevant business and technology teams.
- Partner with Product, Operations, and other business teams to embed privacy requirements into the product and business lifecycle, including data collection, use, sharing, retention, international transfers, analytics, advertising and third-party SDKs and services.
- Conduct and coordinate privacy compliance assessments and DPIAs for new products, features, technologies, vendors and business initiatives, identifying gaps and recommending appropriate remediation measures.
- Monitor and assess the effectiveness of data privacy controls and practices, including through periodic reviews, internal assessments and compliance checks, and track remediation of identified gaps.
- Review vendor arrangements and operational practices to identify data privacy risks and verify that contractual and policy requirements are appropriately implemented in practice.
- Monitor global data protection laws, regulations and industry developments to understand their practical implications and support implementation by relevant teams.
- Maintain privacy compliance documentation and records, including data inventories, assessments, processing records, procedures and other governance materials.
- Support the management of privacy incidents and personal data breaches, including investigation, impact assessment, remediation and coordination with Legal and relevant stakeholders.
- Develop and deliver practical data privacy training and awareness programs for employees and relevant operational teams.
Cybersecurity (40%)
- Provide governance, oversight and strategic guidance on the Group's cybersecurity and information security compliance program, working closely with the operations teams responsible for day-to-day security activities.
- Coordinate internal and external information security audits and assessments, including ISO 27001 and other relevant security certifications or frameworks.
- Monitor the implementation and effectiveness of information security policies, controls and compliance requirements, identifying gaps and coordinating remediation with responsible teams.
- Track key cybersecurity and information security risks, audit findings and compliance gaps, and provide regular updates to relevant stakeholders and management.
- Support business and technology teams in assessing security compliance requirements for new products, systems, vendors and technology initiatives.
- Monitor relevant cybersecurity regulations, standards and industry developments, and work with legal and technical teams to assess and implement applicable requirements.
Other Responsibilities (10%)
- Serve as a key point of contact for data privacy, information security and technology compliance matters, and support ad hoc compliance projects as required.
- Collaborate with Legal, Product, Operations, HR and other functions to strengthen the Group's compliance culture and the practical implementation of compliance requirements.
- Prepare compliance reports, management updates, audit materials and other documentation required for effective governance and oversight.
What an ideal candidate means to us:
- Bachelor's degree or above, with 8 years or more of relevant experience in data privacy, information security, IT compliance, cybersecurity governance, risk management, or related fields.
- Strong practical understanding of data privacy and information security requirements, with experience implementing and monitoring compliance measures in a multinational organization.
- Demonstrated ability to translate legal, regulatory and internal policy requirements into practical processes, controls and operational practices, and to assess whether such measures are effectively implemented.
- Experience working with cross-functional stakeholders, including Legal, Product, Operations and other business functions, to identify compliance risks and drive remediation.
- Working proficiency in English and Chinese to communicate effectively with global teams and stakeholders.
- Strong understanding of cybersecurity concepts, frameworks and terminology, with the ability to work effectively with technical and security operations teams.
- Experience with privacy assessments, DPIAs, vendor assessments, audits, ISO 27001 and/or other relevant compliance frameworks would be an advantage.
- Ability to develop and deliver practical training and awareness programs that promote a strong compliance culture across the organization.
- Strong communication, coordination, analytical, project management and document writing skills.
- Proactive, pragmatic and comfortable working independently, with the ability to manage both strategic initiatives and day-to-day compliance matters in a fast-paced environment.
