Summary
Seminole Hard Rock Support Services is seeking a detail-oriented Data Protection Analyst to join its Global Data Protection Office in Davie, Florida. The role focuses on third-party privacy risk management, DSAR processing, privacy engineering support, data protection assessments, enterprise data mapping, regulatory research, and privacy program management.
Responsibilities
- Lead end-to-end processing of DSARs, ensuring timely fulfillment and compliance with applicable data protection regulations and internal Company policies and procedures
- Work closely with Company marketing, technology, security, data governance, and business teams to support privacy-by-design and the implementation of privacy-enhancing technologies, including data minimization, pseudonymization, anonymization, consent management, and preference management solutions
- Support privacy engineering initiatives by translating privacy requirements into operational and technical controls, including data minimization, purpose limitation, consent management, data mapping, retention, access controls, monitoring, and privacy-by-design requirements
- Conduct third-party privacy risk assessments, review vendor documentation, document findings, and track remediation in coordination with business owner, Security and Legal
- Assist with enterprise data mapping to help maintain clear visibility into personal information processed by the Company, including data flows, systems, processing purposes, vendors, and applicable controls
- Conduct DPIAs and related privacy risk assessments in accordance with GDPR requirements and other global regulatory requirements applicable to the Company
- Research global and local privacy and data protection laws, standards, and regulatory developments and translate requirements into actionable business, vendor, and technical steps
- Review and assist in developing privacy-related policies, standards, procedures, templates, and guidance materials
- Monitor changes in third-party and privacy regulatory requirements and coordinate with GDPO stakeholders to support impact analysis and remediation planning
- Support privacy program management activities by maintaining trackers, documenting decisions, monitoring control implementation, preparing status updates, and escalating issues requiring GDPO leadership attention
Skills
- Minimum of three (3) years of experience in data protection, privacy, compliance, risk management, or related role
- Strong understanding of privacy, data protection, and information security requirements within the United States and globally
- Ability to identify opportunities to streamline or automate repetitive tasks with a high degree of accuracy and consistency
- Excellent organizational skills with a strong focus on accuracy, attention to detail, and documentation quality
- Bachelor's degree or equivalent combination of education and experience
- Experience processing DSARs and coordinating with stakeholders to complete privacy requests accurately and in a timely manner
- Ability to operate effectively both independently and as part of a team
- Strong written and verbal communication skills, including the ability to explain privacy requirements clearly to business and technical stakeholders
- Ability to manage multiple priorities, shift focus as needed and maintain accuracy under competing deadlines
- High level of personal integrity, discretion, and confidentiality
- Positive, collaborative attitude with a practical approach to getting things done
- Preferably in MIS, CIS, Computer Science, Cybersecurity, Law, or related field
- CIPP/US, CIPP/E, CIPM, CIPT, or other relevant privacy, data protection, security, or risk certification
- Experience with the design, implementation, and maintenance of privacy compliance policies, procedures, controls, and programs
- Experience working with technical, security, data governance, marketing, or product teams to operationalize privacy requirements through systems, workflows, and controls
- Proficiency in Microsoft Office Suite, including PowerPoint, Excel, Word, and OneDrive
- Experience with GRC tools, data posture management solutions, consent or preference management tools, and international legal research toolsets
- Ability to cross-train and collaborate with the GDPO and compliance teams on day-to-day privacy operations
- Experience performing privacy risk assessments and ongoing privacy compliance monitoring activities
- Ability to translate regulatory requirements into practical, actionable controls while supporting business strategy
Qualifications
Must Haves
- Minimum of three (3) years of experience in data protection, privacy, compliance, risk management, or related role
- Strong understanding of privacy, data protection, and information security requirements within the United States and globally
- Ability to identify opportunities to streamline or automate repetitive tasks with a high degree of accuracy and consistency
- Excellent organizational skills with a strong focus on accuracy, attention to detail, and documentation quality
- Bachelor's degree or equivalent combination of education and experience
- Experience processing DSARs and coordinating with stakeholders to complete privacy requests accurately and in a timely manner
- Ability to operate effectively both independently and as part of a team
- Strong written and verbal communication skills, including the ability to explain privacy requirements clearly to business and technical stakeholders
- Ability to manage multiple priorities, shift focus as needed and maintain accuracy under competing deadlines
- High level of personal integrity, discretion, and confidentiality
- Positive, collaborative attitude with a practical approach to getting things done
Nice to Haves
- preferably in MIS, CIS, Computer Science, Cybersecurity, Law, or related field
- CIPP/US, CIPP/E, CIPM, CIPT, or other relevant privacy, data protection, security, or risk certification
- Experience with the design, implementation, and maintenance of privacy compliance policies, procedures, controls, and programs
- Experience working with technical, security, data governance, marketing, or product teams to operationalize privacy requirements through systems, workflows, and controls
- Proficiency in Microsoft Office Suite, including PowerPoint, Excel, Word, and OneDrive
- Experience with GRC tools, data posture management solutions, consent or preference management tools, and international legal research toolsets
- Ability to cross-train and collaborate with the GDPO and compliance teams on day-to-day privacy operations
- Experience performing privacy risk assessments and ongoing privacy compliance monitoring activities
- Ability to translate regulatory requirements into practical, actionable controls while supporting business strategy
Benefits