Enterprise Compliance Lead - Privacy
Enterprise Compliance Lead – Privacy
An exciting opportunity is available for an experienced privacy and compliance professional to join a large, purpose-led organisation operating in a highly regulated environment.
Working within the Enterprise Risk and Compliance function, you will provide specialist privacy advice across the organisation while supporting the delivery of its broader compliance framework. This role combines hands-on privacy expertise with second-line monitoring, assurance, control testing and senior stakeholder engagement.
Key responsibilities
-
Act as the organisation’s subject-matter expert for privacy compliance.
-
Conduct and manage end-to-end Privacy Impact Assessments, including stakeholder consultation, risk analysis and formal reporting.
-
Maintain privacy obligations, frameworks, policies and supporting guidance.
-
Interpret relevant legislation and regulatory requirements and translate them into practical business controls.
-
Provide constructive advice and challenge to first-line risk and control owners.
-
Support second-line monitoring, assurance and testing of the control environment.
-
Review ineffective or partially effective controls and recommend remediation actions.
-
Advise on privacy incidents, potential breaches, investigations and regulatory reporting.
-
Develop privacy compliance metrics and prepare reports for senior management and risk committees.
-
Support annual reviews of regulatory obligations and controls.
-
Partner with Risk, Legal, Technology, Incident Management and business teams to strengthen privacy compliance.
-
Contribute to compliance training and help embed a strong organisation-wide compliance culture.
About you
You will bring:
-
Approximately 5-7+ years of operational compliance, risk or assurance experience.
-
Strong subject-matter expertise in privacy compliance.
-
Demonstrated experience conducting Privacy Impact Assessments end to end.
-
Strong knowledge of the Australian Privacy Act, Australian Privacy Principles and relevant privacy obligations.
-
Experience with privacy frameworks, policies, obligations registers and control environments.
-
Practical experience in second-line monitoring, assurance or control testing.
-
Experience investigating privacy incidents or potential regulatory breaches.
-
Strong written communication, report-writing and stakeholder-influencing skills.
-
The ability to translate complex regulatory requirements into practical business advice and controls.
Experience within NSW Government, insurance, workers’ compensation, banking, healthcare or another highly regulated environment will be highly regarded. Knowledge of NSW privacy legislation, including the PPIP Act and HRIP Act, would also be advantageous.
Candidates must be based in Sydney and hold unrestricted working rights in Australia.
This is an excellent opportunity to take ownership of enterprise privacy compliance while contributing to broader risk, assurance and governance outcomes across a complex organisation.