|
Senior Information Governance Compliance Analyst - Boston Massachusetts
Company: Ropes & Gray LLP Location: Boston, Massachusetts
Posted On: 01/18/2025
About Ropes & GrayRopes & Gray is a preeminent, global law firm. The firm has been ranked in the top-three on The American Lawyer's prestigious "A-List" for seven years and is ranked #1 on Law.com International's "A-List" in the U.K.-rankings that honor the "Best of the Best" firms.The firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, New York, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C.The firm has consistently been recognized for its leading practices in many areas, including asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring.Ropes & Gray is an equal opportunity employer.OverviewThe Senior Information Governance Compliance Analyst has a specialized focus and expertise in IG risk and compliance issues. The Senior IG Compliance Analyst has an understanding of global regulatory laws with which the firm must comply. The Senior IG Compliance Analyst develops procedures, policies, and programs to promote, monitor, maintain, and train on compliance with laws, local guidance, and firm policies. The Senior IG Compliance Analyst will provide guidance on how evolving technologies are used, including AI tools, and how data is stored or used. The Senior IG Compliance Analyst combines technical skills with strong analytical, customer service, and communication skills.Responsibilities Analyze current IG risk and compliance processes, procedures, and technologies and identify gaps or areas of improvement. Recommend and execute plans to close gaps. Recommend enhancements/improvements to existing policies. Conduct routine audits to ensure compliance with processes and procedures. Stay informed of new regulatory guidance and laws in all countries in which the firm has offices. Consult with colleagues in other offices to understand the privacy and regulatory landscapes. Draft communications to inform stakeholders at the firm. Respond to client audits, in collaboration with the Information Security Risk & Compliance team. Respond to Outside Counsel Guideline requests with Information Security and the IG Disposition Specialist. Review and provide guidance on new software and services, in collaboration with Information Security. Provide guidance as a member of the IT Architectural Review Board on the implementation of new tools. Provide guidance on the classification of data, especially relating to network shares. Identify where Know Your Client (KYC) data is stored at the firm. Develop and maintain a process to audit for KYC data on a recurring basis, determining when retention has been met based on regulations, and the process for purging the data. Advise on best practices and requirements for storing files containing Protected Health Information and Personally Identifiable Information. Improve processes for monitoring compliance with PHI and PII document storage in the DMS and other approved firm repositories. Develop and maintain user-facing documentation and materials regarding storage procedures. Participate in presentation development and facilitation for PHI and PII best practices training. Perform routine audits to ensure sensitive data is not retained longer than needed. Coordinate with paralegals and attorneys to obtain and execute Business Associate Agreements and Sub-Business Associate Agreements. Maintain the firm's BAA and sub-BAA libraries. Coordinate with IG team members when a PHI document storage request requires a BAA on file. Perform routine audits to ensure BAAs are in place where needed. Assist with matter mobility, file transfer reviews, attorney departures, and personal document reviews as needed. Review requests from users and clients to use removable media and cloud-based storage or collaboration services, such as Box.com. Respond to other tickets as needed.Qualifications |
|