Director, Privacy (Remote)
$138,200–$179,650 year
RemoteUnited States
Job Summary
Lead the enterprise privacy program roadmap, priorities, and maturity strategy by coordinating scalable governance processes that enable privacy-by-design across the organization. Drive execution of the company's privacy strategy while partnering with Legal, Technology, Cybersecurity, Product, Sales, and Government Affairs teams to embed privacy into business processes and technology solutions. Assess and lead privacy risks through a risk-based framework, implementing appropriate mitigation measures and controls to reduce regulatory exposure. Provide practical privacy mentorship to business teams, translating regulatory requirements into scalable business processes and coordinating legal advice as needed. Support the assessment, investigation, and response to cybersecurity, data privacy, and information security events, serving as the primary Privacy and Legal point of contact to resolve and fulfill applicable legal, regulatory, contractual, and notification obligations. Lead privacy impact assessments and data protection impact assessments, maintain Records of Processing Activities, and support related privacy-by-design, risk assessment, and compliance activities. Partner with Cengage's Counsel and AI teams to provide privacy leadership relating to AI governance, responsible data use, and emerging technology initiatives.
Required Qualifications
- Bachelor's degree or equivalent experience
- 10+ years leading privacy, compliance, governance, or related enterprise programs
- Practical understanding of GDPR, CCPA/CPRA, U.S. state privacy laws, and other applicable privacy regulations
- Familiarity student privacy requirements (FERPA, etc.)
- Experience building and operating enterprise privacy programs
- Strong cross-functional leadership, program management, and communication skills
- Ability to translate regulatory requirements into practical business processes and assess technical solutions
Desired Qualifications
- Experience in education, publishing, SaaS, or technology organizations
- Familiarity with international privacy regulations, particularly in Canada, Mexico, Brazil, the EU, China, India, and Australia
- CIPP/US, CIPP/E, CIPM, or similar certification
- Experience implementing or leading a privacy management platform (e.g., Transcend.io, MineOS, etc.)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.