Description:

Job Description:
Company Overview:
CB&I delivers integrated storage and asset‑management solutions that help customers operate safely, reliably, and efficiently across the lifecycle of their facilities. Through our two global business units - Storage Solutions, the world leader in tanks, terminals, and storage systems, and Asset Solutions, a leading provider of operations, management, wells and decommissioning services - we combine technical excellence with execution capability to extend asset life, optimize performance, and maximize value.

Overview:
The Principal Regulatory Compliance Attorney is responsible for designing and implementing a comprehensive risk-based compliance framework; managing regulatory strategy and examinations; protecting data and privacy; and mitigating regulatory and compliance risk across our global organization. This position is an Individual Contributor role and is required to be in the office. The role directly reports to the Director, Legal – Litigation, Ethics, and Compliance.

Responsibilities:
Enterprise Compliance
  • Help design, implement, and improve CB&I's enterprise compliance program across multiple jurisdictions. This includes various responsibilities, such as:
  • Create policies, procedures, and controls to confirm alignment with applicable laws, regulations, and industry standards;
  • Provide oversight and collaboration on compliance matters intersecting with export controls, trade compliance, cross-border regulatory requirements, and third-party due diligence; and
  • Conduct risk assessments, identify root causes, develop mitigation strategies, implement and manage correction actions; and track compliance and remediation efforts
  • Support and help lead supply chain and trade and export compliance

Internal Investigations

Support and conduct confidential internal investigations. Draft investigation reports. Help manage the employee whistleblower hotline and metric reporting.

Regulatory
  • Serve as a primary contact for regulator, inspector, or supervisory communications. Help coordinate or lead productions, submissions, and responses to regulatory exams, audits, inquiries, remediation plans, incidents, or breaches.
  • Take responsibility for statutory updates and submissions.
  • Ensure alignment between regulatory requirements and internal policies and programs. Provide guidance on aligning operational controls and initiatives with regulatory requirements.

Data Privacy

  • Help design, implement, and improve the company's privacy framework and data protection program, ensuring alignment with GDPR principles, accountability requirements, and supervisory authority expectations.
  • Help draft and maintain GDPR-compliant privacy notices, polices, and procedures and conduct or assist with conducting periodic privacy monitoring and audits.
  • Advise on and potentially lead data protection impact assessments, privacy risk assessments, and privacy-related incident response, including breach assessments, notification obligations, and coordination with regulators and external counsel, as needed.

Qualifications:
Requried:
  • Education: J.D., LL.M., or LL.B.
  • License: Licensed attorney in good standing in Texas or who qualifies to work as in-house counsel under Texas rules

Experience:
  • 8-10 years of building and overseeing compliance programs and frameworks (preferably multi-jurisdictional experience)
  • 3-5 years of EU and UK regulatory compliance experience, including GDPR and EU data governance, data protection, and privacy
  • 3-5 years defending against regulatory inquiries, investigations, and enforcement and interacting with regulators and supervisory authorities (EU or UK experience preferred)

Preferred:
Certifications: Certified Information Privacy Professional (CIPP), Certified Compliance and Ethics Professional (CCEP), or Certified Regulatory Compliance Manager (CRCM)

Experience:
  • Demonstrated experience supporting global companies with EU and GDPR compliance needs and handling complex regulatory compliance matters across multiple jurisdictions
  • Familiarity with ISO 27001, 27701, and NIST Privacy Framework
  • Experience with litigation and employment law

Skills and Behaviors
  • Strong functional knowledge and proven experience building and maintaining compliance frameworks and handling regulatory matters for a global or multijurisdictional organization or across multiple jurisdictions and borders
  • Functional knowledge and proven experience designing and maintaining EU/UK and GDPR compliance
  • Subject matter expertise on U.S., EU, and GDPR regulatory, compliance, privacy, and data protection regulations
  • Practical approach to regulatory compliance in operational environments
  • Ability to work autonomously and proactively without frequent supervision
  • Strategic thinker with strong analytical and problem-solving skills
  • Business presence, polish, and credibility with regulators, leadership, and colleagues
  • High emotional intelligence and interpersonal skills
  • Strong written and verbal communication and presentation skills
  • Fluent in English (speaking and writing). Spanish is a plus but not required.
  • Proactively embraces and promotes the company's values and culture, including a healthy and safe work environment.