About this role
Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits
Job Description:
Seminole Hard Rock Support Services is seeking a highly motivated, detail-oriented Data Protection Analyst with a focus on third-party risk management, Data Subject Access Request (“DSAR”) operations, privacy engineering support, and privacy program management. This role will join the Company’s exciting and fast-paced Global Data Protection Office (“GDPO”) team in Davie, Florida. The Analyst will work closely with Company business units, third-party vendors, and service providers to assess privacy, data protection, and information security operational and contractual risks. The Analyst will communicate requirements and recommend practical controls to support risk reduction and Company compliance.
In addition to third-party risk management, the Analyst will provide privacy subject matter support to Company business units by supporting DSAR processing, privacy documentation, privacy and data protection research, Data Protection Impact Assessments (“DPIAs”), enterprise data mapping, privacy engineering initiatives, and privacy program management activities. The Analyst will help translate privacy requirements into practical business, vendor, and technical controls and monitor implementation to support compliance, accountability, and risk reduction.
Our team is growing and if you are equally passionate about privacy, data management, and career growth, an opportunity at Seminole Hard Rock may be a great match!
Job Responsibilities:
- Lead end-to-end processing of DSARs, ensuring timely fulfillment and compliance with applicable data protection regulations and internal Company policies and procedures.
- Work closely with Company marketing, technology, security, data governance, and business teams to support privacy-by-design and the implementation of privacy-enhancing technologies, including data minimization, pseudonymization, anonymization, consent management, and preference management solutions.
- Support privacy engineering initiatives by translating privacy requirements into operational and technical controls, including data minimization, purpose limitation, consent management, data mapping, retention, access controls, monitoring, and privacy-by-design requirements.
- Conduct third-party privacy risk assessments, review vendor documentation, document findings, and track remediation in coordination with business owner, Security and Legal.
- Assist with enterprise data mapping to help maintain clear visibility into personal information processed by the Company, including data flows, systems, processing purposes, vendors, and applicable controls.
- Conduct DPIAs and related privacy risk assessments in accordance with GDPR requirements and other global regulatory requirements applicable to the Company.
- Research global and local privacy and data protection laws, standards, and regulatory developments and translate requirements into actionable business, vendor, and technical steps.
- Review and assist in developing privacy-related policies, standards, procedures, templates, and guidance materials.
- Monitor changes in third-party and privacy regulatory requirements and coordinate with GDPO stakeholders to support impact analysis and remediation planning.
- Support privacy program management activities by maintaining trackers, documenting decisions, monitoring control implementation, preparing status updates, and escalating issues requiring GDPO leadership attention.
Minimum Required Qualifications:
- Minimum of three (3) years of experience in data protection, privacy, compliance, risk management, or related role.
- Strong understanding of privacy, data protection, and information security requirements within the United States and globally.
- Ability to identify opportunities to streamline or automate repetitive tasks with a high degree of accuracy and consistency.
- Excellent organizational skills with a strong focus on accuracy, attention to detail, and documentation quality.
- Bachelor’s degree or equivalent combination of education and experience, preferably in MIS, CIS, Computer Science, Cybersecurity, Law, or related field.
- Experience processing DSARs and coordinating with stakeholders to complete privacy requests accurately and in a timely manner.
- Ability to operate effectively both independently and as part of a team.
- Strong written and verbal communication skills, including the ability to explain privacy requirements clearly to business and technical stakeholders.
- Ability to manage multiple priorities, shift focus as needed and maintain accuracy under competing deadlines.
- High level of personal integrity, discretion, and confidentiality.
- Positive, collaborative attitude with a practical approach to getting things done.
Additional Preferred Qualifications:
- CIPP/US, CIPP/E, CIPM, CIPT, or other relevant privacy, data protection, security, or risk certification.
- Experience with the design, implementation, and maintenance of privacy compliance policies, procedures, controls, and programs.
- Experience working with technical, security, data governance, marketing, or product teams to operationalize privacy requirements through systems, workflows, and controls.
- Proficiency in Microsoft Office Suite, including PowerPoint, Excel, Word, and OneDrive.
- Experience with GRC tools, data posture management solutions, consent or preference management tools, and international legal research toolsets.
- Ability to cross-train and collaborate with the GDPO and compliance teams on day-to-day privacy operations.
- Experience performing privacy risk assessments and ongoing privacy compliance monitoring activities.
- Ability to translate regulatory requirements into practical, actionable controls while supporting business strategy.