Privacy and Security Engineer

Kubota Tractor Corporation
Grapevine, United States of America
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Grapevine, United States of America

Tech stack

Microsoft Access
Control Objectives for Information and Related Technology (COBIT)
Data Mapping
Disaster Recovery
Data Classification

Job description

This position will support the Privacy and Security Manager in developing and maintaining a comprehensive enterprise-wide privacy program. The Privacy Engineer will lead several efforts pertaining to privacy governance, data collection practices, and administrative security. The Privacy Engineer will also be responsible for supporting privacy-related procurement and overseeing vendor management activities.

What You'll Do:

  • Led enterprise privacy and compliance programs, serving as the primary point of contact for regulatory, audit, and governance initiatives.
  • Managed and coordinated internal and external audits, partnering with third-party assessors to ensure successful compliance outcomes.
  • Acted as a subject matter expert on NIST 800-53/66/171, HIPAA, FERPA, GDPR, FedRAMP, and FISMA requirements.
  • Developed and maintained privacy, security, and compliance documentation, policies, standards, and control repositories.
  • Conducted privacy impact assessments, data mapping, data classification, and access/privilege reviews to strengthen data protection and risk management.
  • Collaborated across business and technology teams to implement privacy technologies, drive regulatory readiness, deliver training, and ensure ongoing compliance with evolving legal requirements.

Requirements

  • Bachelor's degree or equivalent work experience required.
  • Minimum of 5 years of relevant experience in consumer finance environment required.
  • At least 7 years of privacy or security experience required.
  • Certifications such as CIPP, CIPM, CIPT, CISA, CRISC preferred.
  • Strong understanding of U.S. privacy and security regulations.
  • Experience with privacy and security frameworks such as GAPP, ISO 27000, NIST-SP, COBIT and SSAE18, etc.
  • Understanding of "role-based access" and "segregation of duties" protocols.
  • Experience supporting/interpreting 3rd party risk assessments and privacy compliance activities.
  • Strong experience with privacy-related contract review and vendor management processes.
  • Experience with Incident Response and Business Continuity Planning / Disaster Recovery Planning.

Apply for this position