About this role
At Apple, we believe privacy is a fundamental human right. IS&T builds and operates the systems that run Apple's business — and we hold them to that standard. Here, your ideas can quickly become the processes, controls, and tooling that protect our customers, employees, and partners at global scale.
Business Operations, Employee Engagement, and Strategy is part of IS&T and shapes the strategy, operations, and culture of IS&T. The team oversees business planning, IS&T's partnership strategy across Apple, and the technology tools that support the organization's day-to-day operations. This team also leads IS&T's enterprise generative AI strategy and manages compliance across systems. Through its communications and employee programs, it champions the growth, inclusion, and development of everyone in IS&T and drives the standard for IS&T brand and product communications across Apple.
Apple's IS&T Security, Privacy, and Compliance organization is seeking a Privacy Compliance Analyst to help establish and operate enterprise privacy and regulatory compliance programs across a complex, global technology landscape. In this role you will translate regulatory and policy requirements into scalable compliance processes, assess and govern privacy and data protection risk, and drive accountability for remediation across the organization.
You will partner with Legal, Privacy, Information Security, Engineering, Product, Data, and business teams — as well as regional in-country compliance teams — to establish a coordinated, risk-based approach for identifying, assessing, governing, and monitoring high-risk personal information processing activities. You'll bring the rigor of an auditor, the discipline of a program manager, and the technical depth to propose and reason about data platforms, pipelines, and data at scale.
Minimum Qualifications
Bachelor's degree or equivalent practical experience
3+ years of experience in privacy, compliance, risk management, information security, technology audit, or data governance
Experience performing risk assessments, control assessments, privacy assessments, audits, or compliance reviews
Hands-on experience with global privacy and data protection regulations such as GDPR, CCPA/CPRA, PIPL, or other emerging global data protection regimes
Experience with data classification, data governance, data inventories, or data-flow mapping
Preferred Qualifications
Familiarity with cloud environments, enterprise applications, APIs, data platforms, and software development life cycle methodologies
Ability to evaluate technical designs and architectures against control objectives and articulate gaps to both engineering and non-technical audiences
Demonstrated ability to translate regulatory, policy, or control requirements into practical and scalable processes
Strong analytical skills and the ability to assess complex business and technical processes
Experience working with cross-functional stakeholders across technology, security, engineering, product, legal, and business teams
Experience managing multiple priorities and driving complex cross-functional initiatives to completion
Strong written and verbal communication skills, including the ability to frame complex concepts for senior audiences
Ability to work independently and operate effectively in an ambiguous, evolving regulatory environment
Audit or advisory experience at a Big 4 or comparable professional services firm
Experience with Privacy Impact Assessments, Data Protection Impact Assessments, or similar risk assessment methodologies
Experience with cross-border data transfer governance