Privacy Program Analyst
Seattle, OR - USA
Job Summary
ABOUT KALLES GROUP:
Everyone deserves to be secure. Our mission at Kalles Group is to help secure the future for companies of all shapes and sizes.
While our expertise spans multiple disciplines our method remains consistent: building trust and relationship with people -- whether you are a client a consultant or--in this case--a candidate.
No matter what role you come from--whether youre an executive or just starting your career-you can expect our highest level of attention and respect. We want to find the right fit for each role but we also want you to find the right fit for your career.
We believe the best way to show you what our team is like is to treat you like youre already a part of it. We hope youll consider joining our team of experienced professionals who are building their careers at Kalles Groupand having fun while doing it.
WHAT YOU WILL DO:
The Privacy Program Analyst will be part of our team of skilled collaborative practitioners supporting privacy programs across a range of enterprise clients. Youll lead privacy assessments strengthen data governance practices and help clients build durable well-documented privacy programs as a key component of our growing Privacy & Compliance practice.
If you are passionate about protecting peoples data grounded in privacy fundamentals and experienced in leading privacy impact assessments and cross-functional risk work we want to speak with you!
You will:
- Lead end-to-end privacy impact assessments (and related assessments such as DPAs) including evaluation of first- and third-party applications systems and business processes identifying privacy and technological gaps against applicable laws and business requirements.
- Evaluate privacy risks and document clear actionable mitigation recommendations for partner teams to execute.
- Collaborate closely with Legal IT and Security teams to ensure privacy controls stay aligned with an evolving risk and compliance posture.
- Identify opportunities to improve privacy assessment processes data mapping practices and documentation escalating recommendations to leadership as appropriate.
- Support audits maturity assessments and other program-level compliance initiatives.
- Respond to and help fulfill data subject access requests (DSARs).
- Maintain and build out data mapping and governance documentation.
- Support the rollout of privacy-enhancing technologies and tools.
- Identify and escalate privacy risks and help lead incident response for privacy-related events.
- Flex across multiple privacy workstreams as program needs evolve bringing the same grounded principles-based approach to each.
ABOUT YOU:
Your values:
- Integrity: You believe in doing the right thing even when its uncomfortable seemingly inefficient or costly.
- Purposefulness: You have a desire to serve others with your skillset and an openness to continuous learning and growth.
- Ownership: You stick to your commitments follow up with action and seek clarity in communication & expectations.
Your experience:
- 3 years of experience in privacy risk or compliance-related work with hands-on experience conducting privacy impact assessments.
- Bachelors degree in information technology computer science cybersecurity or related experience required.
- IAPP certification (CIPP/US CIPM or CIPT) strongly preferred.
- Strong foundational understanding of privacy principles (e.g. Fair Information Practice Principles) and core privacy controls such as retention schedules and least-privilege access well-rounded fundamentals matter more to us than mastery of any single tool.
- Working knowledge of relevant privacy regulations (e.g. CCPA PIPEDA and other U.S. state or sectoral privacy laws) and comfort navigating evolving regulatory landscapes.
- Experience with privacy management platforms (e.g. OneTrust TrustArc) a plus.
- Strong attention to detail and consistency in both written and verbal communication.
- Comfortable working across multiple concurrent workstreams and adapting as program priorities shift.
Wed be especially excited to talk to you if you have:
- Past experience conducting privacy assessments in complex matrixed enterprise environments.
- Relevant experience within e-commerce retail or large-scale consumer-facing organizations.
- Experience supporting global or multi-jurisdictional privacy programs.
- A broad view of privacy that connects naturally to adjacent disciplines like security data governance and IT risk.
WHAT WE OFFER:
- Salary range of $95000$135000 depending on experience and location.
- Medical dental vision and pharmaceutical coverage.
- An education stipend of $2000 annually to put towards your own growth and development.
- 401(k) and life insurance benefits.
- 3 weeks of Paid Time Off. PLUS 8 paid company holidays and 2 flexible holidays for anything you want to celebrate!
- Work/life balance we know theres more to life than work! We encourage our team to pursue other passions get outside and spend time with family. We work with clients and consultants to set expectations for a manageable workload.
- Opportunities to connect in person and remotely with a passionate supportive team.
LOCATION:
This role requires on-site work in the Seattle WA area. Please apply only if you are located in Washington. If you would like to request more information please reach out to .
HOW TO APPLY:
Please fill out the form below (including uploading your most recent resume) and well be in touch! We know imposter syndrome can be a barrier to many great applicants. We hope youll still consider applying. Thats why weve made the application process as short and simple as possible.
Even if youre not a fit for the role you can expect to hear back from us! We want you to have the best experience as a candidate so please feel free to share feedback at any stage of the process to .
Kalles Group is an equal-opportunity employer and does not discriminate on the basis of creed nationality race ethnicity disability gender or other protected class.
Required Experience:
IC
About Company
“I sleep much better knowing I have a trusted resource to call in the event of a security incident or question.” “HIPAA alignment report contained targeted…