Senior Privacy & Compliance Program Manager
$115,000–$145,000 year
RemoteUnited Kingdom or United States
Job Summary
Coordinate MZLA's privacy and compliance program work, including planning, recurring reviews, risk tracking, documentation, and leadership reporting. Translate privacy, security, and compliance requirements into practical processes that fit how MZLA works. Coordinate vendor and tool reviews with legal, engineering, product, support, finance, operations, and other stakeholders. Help document data flows, subprocessors, and privacy, security, contractual, and operational considerations. Support privacy operations and data governance for a global user base, including DSAR and privacy-rights workflows. Help develop and maintain practical data inventories, records of processing, retention practices, and privacy-related documentation. Partner with technical teams to support privacy-by-design practices for new products, services, tools, and data-processing activities. Support compliance and audit-readiness efforts, including ISO-related readiness, evidence tracking, access reviews, and remediation follow-up. Help strengthen incident response readiness by clarifying roles, escalation paths, documentation expectations, and coordination needs. Build lightweight guidance, checklists, templates, and training materials that help teams meet privacy and compliance expectations without creating unnecessary bureaucracy. This role requires regular overlap with Eastern Time working hours.
Required Qualifications
- 8+ years of relevant professional experience
- preferably within a software, SaaS, technology, or technical product environment
- 5+ years of direct or closely related hands-on experience in privacy operations, compliance program management, GRC, legal operations, security compliance, vendor governance, data governance, or a similar function
- Experience coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams
- including work with external counsel, advisors, auditors, consultants, or vendors to move complex work forward
- Experience supporting vendor, tool, or subprocessor reviews, including privacy, security, legal, and operational risk considerations
- Experience supporting privacy operations, data governance, or user-rights workflows for products or services with international users
- including areas such as GDPR or EU privacy requirements, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy maintenance
- Technical fluency and the ability to work with technical teams to understand how data moves through systems
- including cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage
- Familiarity with incident response, breach readiness, or security/privacy escalation processes
- Strong project and program management skills
- excellent written communication
- sound judgment
- the ability to build pragmatic, right-sized processes for a small but growing organization
- Ability to learn, evaluate, and responsibly use emerging technologies, including AI-enabled tools, to improve work processes
- Ability to operate with initiative in areas where processes are still evolving
- including identifying stakeholders, proposing next steps, clarifying ownership, and knowing when to escalate
- regular overlap with Eastern Time working hours for meetings, collaboration, and time-sensitive coordination
- We welcome candidates in other time zones who can consistently maintain meaningful overlap with ET
- Applicants must reside in and have permanent work authorization for the country location(s) specified in the posting
- we are unable to consider applicants outside of these markets at this time
- And, we do not provide visa sponsorship
Desired Qualifications
- Bonus points for Experience supporting ISO 27001 readiness, SOC 2 readiness, audits, certifications, or similar compliance efforts
- Experience working in an open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organization
- Experience developing training or enablement materials for privacy, security, compliance, vendor review, or data handling
- Experience with GRC platforms, policy management tools, ticketing systems, vendor management tools, or other systems used to track compliance workflows
- Privacy certification such as CIPP/E, CIPP/US, CIPM, or similar
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.