
Manager, Privacy & Regulatory Compliance
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in Canada.
• Oversee and enhance Plooto’s privacy initiatives while acting as a key subject-matter expert in privacy.
• Ensure compliance with PIPEDA, Quebec Law 25, Alberta PIPA, BC PIPA, and other relevant privacy regulations.
• Offer practical, risk-based privacy advice to the organization.
• Conduct privacy evaluations for new products, features, vendors, and data usage, including Privacy Impact Assessments.
• Contribute to Plooto’s responsible AI strategy and scalable evaluation techniques.
• Integrate privacy by design principles across all products, AI tools, models, vendors, and automated processes.
• Manage data rights requests, privacy incidents, breach evaluations, third-party privacy assessments, cross-border data issues, and data retention/deletion practices.
• Track emerging privacy, data, and AI trends in Canada and the United States, providing actionable recommendations.
• Aid in the implementation of the Enterprise Risk Management framework, covering risk assessments, the enterprise risk register, mitigation monitoring, and risk reporting.
• Collaborate with leadership to pinpoint significant risks, clarify ownership, monitor actions, and maintain effective reporting.
• Assist with regulatory changes, third-party risk management, audits, effectiveness assessments, compliance with the Retail Payment Activities Act, and AML/ATF requirements.
• Foster organizational awareness through guidance, tools, and training on privacy, responsible AI, and risk management.
• Work in partnership with Product, Engineering, Security, Legal, People, Operations, and other departments.
• Report to the Senior Manager of Compliance within the Payments Strategy & Compliance division.
• 3–6+ years of practical privacy experience, preferably in fintech, payments, technology, banking, financial services, or another regulated sector.
• In-depth knowledge of Canadian privacy laws, especially PIPEDA and Quebec Law 25, along with an understanding of Alberta and British Columbia privacy regulations.
• Hands-on experience with Privacy Impact Assessments, privacy reviews, data rights requests, and privacy incident or breach evaluations.
• Ability to apply privacy regulations appropriately and establish defensible, practical, risk-appropriate controls.
• A genuine interest in AI and emerging technologies.
• Capacity to distill complex requirements into clear guidance, decision-making frameworks, and processes.
• A pragmatic, action-oriented approach.
• Excellent written and verbal communication skills, with the ability to collaborate effectively across Product, Engineering, Security, People, Operations, Legal, and leadership teams.
• Capability to independently handle competing priorities, demonstrate sound judgment, and identify when escalation is necessary.
• Familiarity with U.S. privacy regulations, including CCPA/CPRA and emerging state privacy laws, is advantageous.
• Experience in enterprise risk management, third-party risk, fintech regulation, payments compliance, or AML/ATF is beneficial but not essential.
• CIPP/C certification is preferred; CIPP/US, CIPM, or other relevant privacy certifications are beneficial.
• Bilingualism in English and French is a plus.
• Compensation will be based on the successful candidate’s knowledge, skills, experience, and overall fit for the role.
• An inclusive workplace environment.
• Accommodations during the recruitment process in accordance with applicable accessibility legislation.
Elfonze Technologies
Eli Lilly and Company
Cisco
Get handpicked remote jobs straight to your inbox weekly.