This position is an onsite position and available to be filled at any Huntington Corporate office location (see location options on posting)
Summary:
The Senior Manager, Data Protection is responsible for leading the strategy, governance, and operational execution of enterprise Data Protection and Privacy incident response operations. This role will report to the Director of Insider Risk and Data Protection and provide leadership across data security, privacy compliance, and data governance capabilities to ensure the organization's sensitive information remains protected.
A successful candidate will partner closely with Cybersecurity, Legal, Privacy, Risk, Human Resources, Technology, Compliance, and business stakeholders to develop and mature enterprise-wide capabilities that protect customer, employee, and corporate data across on-premises, cloud, SaaS, collaboration, and endpoint environments. This leader will drive risk reduction through technical controls, operational governance, and continuous innovation leveraging analytics, automation, and AI.
Duties and Responsibilities:
Execute the enterprise Data Protection strategy, roadmap, and governance model.
Lead and engage in programs focused on protecting sensitive information across the full data lifecycle, including collection, storage, processing, transmission, sharing, retention, and disposal.
Establish policies, standards, and operating procedures supporting secure data handling and regulatory compliance.
Drive enterprise adoption of data protection technologies, controls, and best practices.
Provide strategic direction and leadership for Data Protection, Privacy Operations.
Lead and support enterprise-wide initiatives related to:
Data classification and labeling
Data discovery and inventory management
Data Loss Prevention (DLP)
Insider Risk Management
Encryption and tokenization
Ensure protection of sensitive data across:
Endpoints
Cloud platforms
SaaS applications
Collaboration platforms
Email systems
Enterprise repositories
Develop risk-based controls to prevent unauthorized access, misuse, or exfiltration of sensitive data.
Define and oversee enterprise data protection metrics, reporting, and governance processes.
Lead the operational execution of enterprise privacy incident response playbook.
Collaborate with Legal, Compliance, and Privacy teams to ensure alignment with privacy regulations, including:
GDPR
CCPA
HIPAA
Other applicable regulatory requirements
Provide subject matter expertise on:
Personal Information (PII)
Data minimization
Data sharing
Maintain enterprise Data protection strategy, governance, and operational processes.
Partner with Insider Risk and Security Operations teams to develop monitoring, detection, investigation, and response capabilities.
Lead data protection assessment activities.
Conduct or oversee:
Data Protection Impact Assessments
Regulatory compliance assessments
Data flow analysis
Security control evaluations
Identify data protection risks and develop scalable remediation strategies.
Maintain risk registers, governance reporting, and remediation tracking processes.
Provide executive-level reporting on:
Data protection program maturity
Key performance indicators
Support and drive large-scale cybersecurity and data protection transformation initiatives.
Evaluate emerging technologies, automation opportunities, and AI-enabled capabilities that enhance data protection and privacy operations.
Required Qualifications
Deep experience implementing and managing enterprise Data Protection solutions and controls.
Experience with:
DLP platforms
Exceptional communication and stakeholder management skills.
Basic Qualifications:
Bachelor's Degree or 4+ additional years of equivalent experience.
7+ years' experience leading Data Protection and/or Data Privacy, programs.
2+ years' experience leading privacy event response and notification activities.
Preferred Qualifications:
Experience supporting cloud-first security and data protection programs.
Experience with Microsoft Purview, Insider Risk Management, Defender Suite, or similar technologies.
Professional certifications such as:
CISSP
CISM
CIPP/US
CIPP/E
CRISC
Direct hands-on AND leadership experience within Cyber Security organizations designing, implementing, administering and supporting related technologies or services with Subject Matter Expertise in Data Protection technologies
3 years+ Cyber Security/Data Protection technologies/programs
Master's degree or related combination of work, training and educational experience (6 years +)
Computer Science, Cyber Security, Information Assurance, MIS, IT Communication Systems/Networking or STEM discipline focus or equivalent
Expert and hands-on working knowledge of three or more of the following:
Data Privacy Fundamentals and Advanced Concepts (Working knowledge with Data Privacy Laws and Regulations specific to Financial Industries, Personal Information (PI) protection, Privacy Breach incident management, reporting/impact, investigation & analysis)
Leadership Competencies
Strategic vision and executive presence
Data-driven decision making
Cybersecurity leadership and talent development
Regulatory and risk management expertise
Influence and stakeholder engagement
Program and portfolio management
Organizational transformation leadership
Innovation and continuous improvement mindset
Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay)
Workplace Type:
OfficeOur Approach to Office Workplace Type
Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team.
Huntington is an Equal Opportunity Employer.
Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details.
Note to Agency Recruiters: Huntington Bank will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington Bank colleagues, directly or indirectly, will be considered Huntington Bank property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.