Agency
Department of Information TechnologyDivision
DIT Secretary , CIOJob Classification Title
IT Executive I (NS)Position Number
60087459Grade
DT14About Us
The N.C. Department of Information Technology (NCDIT) serves as the Technology Center for the State of NC. Services that NCDIT provides reach a client base of state and local government agencies, as well as schools, colleges and universities. NCDIT’s mission is to enable trusted business-driven solutions that meet the needs of North Carolinians. NCDIT provides technology services to state agencies and is charged with closing the digital divide by expanding availability of broadband services and promoting the adoption of affordable, high-speed internet.
Description of Work
Recruitment Range: $170,000 - $230,000The position is designated Statutory Exempt (EHRA) and is exempt from the State Human Resources Act.
This position may be eligible for hybrid remote work in accordance with state policy and the agency’s remote work program but does require weekly onsite work. Any telework will be under the conditions of the state Teleworking Program Policy and the employer may end any teleworking arrangement at any time in the employer's sole discretion.
Are you ready to take the next step in your career? We currently have an opening for the Chief Privacy Officer for the State of North Carolina.
Step into a role where your leadership will shape the statewide future of privacy, trust, and responsible innovation. As North Carolina’s Chief Privacy Officer, you will serve as the executive catalyst driving a mature, risk‑aware, and forward‑looking privacy program that underpins the integrity of statewide operations. This is a mission‑critical position for a visionary leader who can translate complex regulatory landscapes, emerging technologies, and enterprise risk into clear strategic direction. You will partner directly with senior executives to embed privacy into organizational culture, protect the State’s most sensitive data assets, and strengthen public trust through disciplined governance and proactive oversight.
Key Responsibilities:
• Provide statewide executive leadership by setting the strategic vision for the privacy program, establishing policies and standards, and guiding long‑term program maturity.
• Modernize and enhance the enterprise privacy program, ensuring consistent, statewide alignment with federal and state regulatory requirements and emerging data governance expectations.
• Develop innovative privacy strategies for new and evolving technologies, including cloud environments, IoT, AI, and advanced analytics.
• Oversee all privacy operations, including privacy impact assessments, governance activities, incident management, and continuous monitoring of controls.
• Ensure strong alignment with the Enterprise Security and Risk Management Office (ESRMO) and the Chief Data Officer to maintain unified, enterprise‑wide privacy and security compliance across programs, investigations, and policy development.
• Implement and evaluate audit controls, ensuring appropriate oversight of systems containing restricted or highly restricted information and regular review of NIST‑aligned controls.
• Lead enterprise privacy training and workforce awareness, delivering executive‑level messaging and organization‑wide education that reinforces a culture of data responsibility.
• Conduct pre‑deployment reviews of systems and initiatives, ensuring compliance with privacy laws and alignment with BAAs, MOUs/MOAs, and interconnection agreements.
• Monitor, report, and remediate privacy risks, managing violations, preventing unauthorized data use, and coordinating breach determination and notification with ESRMO and regulatory authorities.
• Serve as the State’s senior privacy liaison, collaborating with internal stakeholders, regulators, legal authorities, and external partners to advance statewide privacy excellence.
About the Org:
The NC Department of Information Technology (NCDIT) is North Carolina's Technology Center, providing services to state and local agencies, schools, colleges, and universities. Reporting to the Chief Information Security/Risk Office, this role coordinates with DIT leadership and works closely with the Chief Data Office and Enterprise Security and Risk Management Office to ensure data privacy and security while using data assets to benefit North Carolina.
Knowledge Skills and Abilities/Management Preferences
The following Management Preferences are not required, but applicants that possess these skills are preferred:
Regulatory & Compliance Expertise: Deep understanding of state and federal privacy and data protection laws (e.g., HIPAA, FERPA) and evolving enforcement trends; strong knowledge of data risk management frameworks and required treatment of sensitive data types (ePHI, FTI, CJI, PII); demonstrated experience in privacy, data protection, or compliance within complex organizations; professional certifications such as Certified Information Privacy Professional (CIPP) and/or Certified Information Privacy Manager (CIPM).
Governance, Strategy & Risk Leadership: Proven ability to design, lead, and mature enterprise privacy programs and frameworks; strong strategic insight and business judgment, with the capacity to balance risk management with organizational objectives; experience overseeing privacy governance related to artificial intelligence, machine learning, and advanced analytics.
Technology & Operational Privacy Management: Awareness of current and emerging privacy technologies that support compliance and organizational adaptation; practical experience implementing privacy controls, conducting assessments, and ensuring appropriate handling of sensitive data; demonstrated ability to integrate privacy-by-design principles into systems, processes, and enterprise initiatives.
Discover why NCDIT is the ideal destination for your professional growth - Why Work for NCDIT
Minimum Education and Experience
Some state job postings say you can qualify by an “equivalent combination of education and experience.” If that language appears below, then you may qualify through EITHER years of education OR years of directly related experience, OR a combination of both. See the Education and Experience Equivalency Guide for details.
Bachelor’s degree in computer science or a related IT field, business administration, project management, or closely related degree from an appropriately accredited institution and seven years of progressive information technology experience including three years managerial experience
or
Associate degree in computer science or a related IT field, business administration, project management, or closely related degree from an appropriately accredited institution and eight years of progressive information technology experience with three years of managerial experience; or an equivalent combination of education and experience.
This position requires a fingerprint-based background search. Hires must agree to a fingerprint-based background search prior to being hired.
EEO Statement
The State of North Carolina is an Equal Employment Opportunity Employer and dedicated to providing employees with a work environment free from all forms of unlawful employment discrimination, harassment, or retaliation. The state provides reasonable accommodation to employees and applicants with disabilities; known limitations related to pregnancy, childbirth, or related medical conditions; and for religious beliefs, observances, and practices.
Recruiter:
Shaun OsborneRecruiter Email:
Skills Required
- Bachelor's degree in computer science or a related IT field, business administration, project management, or closely related degree and seven years of progressive information technology experience including three years managerial experience; OR Associate degree and eight years of progressive IT experience with three years managerial experience; or equivalent combination of education and experience.
- Fingerprint-based background search required and must agree to undergo the search prior to hire.
- Ability to perform weekly onsite work (hybrid remote eligibility but weekly onsite attendance required).
- Professional privacy certifications such as CIPP or CIPM.
- Deep understanding of state and federal privacy and data protection laws (e.g., HIPAA, FERPA) and handling of sensitive data types (ePHI, FTI, CJI, PII).
- Proven experience designing, leading, and maturing enterprise privacy programs, privacy impact assessments, and governance for AI/ML, cloud, and IoT.
What We Do
The North Carolina Department of Public Instruction (NCDPI) is charged with implementing the state's public school laws for pre-kindergarten through 12th grade.






