
Senior Privacy & Compliance Program Manager
Posted Jul 23

Posted Jul 23
This is a fully remote position, open to applicants in United States.
• Oversee MZLA’s privacy and compliance initiatives, encompassing program planning, regular assessments, risk management, documentation, and reporting to leadership.
• Convert privacy, security, and compliance obligations into actionable processes tailored to MZLA’s products, infrastructure, support workflows, vendor ecosystem, and operational model.
• Facilitate vendor and tool evaluations by collaborating with legal, engineering, product, support, finance, operations, and other stakeholders to identify and record data flows, subprocessors, privacy, security, contractual, and operational considerations.
• Assist in privacy operations and data governance for a global audience, including Data Subject Access Requests (DSARs) and privacy-rights workflows, records of processing, data retention practices, privacy policy maintenance, international privacy considerations, and associated documentation.
• Aid in the development and upkeep of practical data inventories and data maps that outline the data MZLA collects, its storage locations, usage, involved vendors or systems, and relevant retention practices.
• Collaborate with technical teams to promote privacy-by-design principles and ensure that new products, services, tools, and data-processing activities undergo early and appropriate review.
• Support compliance and audit readiness initiatives, including those related to ISO, policy implementation, evidence tracking, control execution, access evaluations, training, and remediation follow-up.
• Assist in establishing ongoing review processes for vendors, tools, systems, policies, and data-processing activities to ensure documentation remains up-to-date as products and operations evolve.
• Enhance incident response preparedness by clarifying roles, escalation pathways, documentation expectations, and coordination across Legal, Infrastructure, leadership, and other relevant teams.
• Create concise guidance, checklists, templates, and training materials that empower teams to meet privacy and compliance standards without causing unnecessary bureaucratic hurdles.
• A minimum of 8 years of relevant professional experience, ideally in a software, SaaS, technology, or technical product setting.
• At least 5 years of direct or closely related hands-on experience in privacy operations, compliance program management, governance, risk management and compliance (GRC), legal operations, security compliance, vendor governance, data governance, or a similar role.
• Proven experience in coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams, including collaboration with external counsel, advisors, auditors, consultants, or vendors to advance complex projects.
• Familiarity with vendor, tool, or subprocessor evaluations, addressing privacy, security, legal, and operational risk considerations.
• Experience in supporting privacy operations, data governance, or user-rights workflows for products or services with international users, including compliance with GDPR or EU privacy directives, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy upkeep.
• Technical proficiency with the ability to collaborate with technical teams to comprehend data movement through systems, such as cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage.
• Acquaintance with incident response, breach preparedness, or security/privacy escalation protocols.
• Strong project and program management capabilities, exceptional written communication, sound judgment, and a knack for developing pragmatic, appropriately scaled processes for a small but expanding organization.
• Capacity to learn, assess, and responsibly utilize emerging technologies, including AI-enabled tools, to enhance work processes.
• Proactive in navigating areas where processes are still in development, including stakeholder identification, next steps proposal, ownership clarification, and escalation awareness.
• Fully remote work & schedule flexibility
• Company-provided laptop
• Annual bonus program
• Monthly remote work stipend
• Annual professional development stipend
• Access to Coursera learning platform
• Industry conferences
• Company all-hands and team gatherings
• 24 days PTO per year (prorated)
• Your birthday
• Year-end company shutdown
• 9 wellbeing days
• Public holidays
• Other paid leave
• Quarterly wellbeing stipend for personal/family activities
• 401(k) / RRSP contributions
• Health, dental, & vision insurance
• Disability insurance
• Life insurance
• Employee assistance program
• Paid parental leave
• Paid sick days
Wadhwani Foundation
Day Wireless Systems
Constellation Inc
Flywire
Get handpicked remote jobs straight to your inbox weekly.