USA - Remote
Remote
Senior
Full Time
💰$ 165,000 - $ 223,300
complianceprivacysecuritydocumentationauditAI regulation
Requirements
- •Substantial experience in privacy operations, GRC, security compliance, or technical compliance documentation
- •Exceptional writing skills for technical and compliance documentation
- •Demonstrated ownership of compliance operational systems at scale
- •Hands-on involvement in at least one formal audit (SOC 2, ISO 27001, or PCI DSS) producing and defending evidence
- •Practical experience with GDPR and CCPA/CPRA and knowledge of AI regulation trends
- •Technically fluent with ability to understand architecture diagrams, data flows, logs, and retention settings
- •Able to engage with Fortune 500 privacy teams, security reviewers, or DPOs independently
- •Startup-friendly judgment on compliance trade-offs and policies
- •Bias toward building systems and templates for compliance processes
- •Comfortable with ambiguity and making defensible calls when laws or standards are unsettled
What You'll Do
- •Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end
- •Build and maintain accurate data flow maps and records of processing across deployments
- •Own the operating model for privacy controls including retention, deletion, DSAR workflows, consent handling
- •Own subprocessor and vendor privacy review process and DPAs
- •Translate GDPR, UK GDPR, CCPA/CPRA and emerging AI regulation into actionable requirements
- •Partner with Legal on DPAs, SCCs, transfer mechanisms, and residency commitments
- •Own audit evidence for SOC 2, ISO 27001, and PCI DSS and be primary auditor contact
- •Own control mapping across compliance frameworks
- •Own security questionnaires and RFP security sections
- •Partner with Security Engineering to automate evidence generation
- •Author and own lifecycle of internal policies and standards
- •Own public-facing posture documents and deployment documentation
- •Manage documentation system and ensure traceability of claims
- •Design and run operational auditing and remediation workflows
- •Run compliance and privacy training and enablement
Nice to Have
- •Certification such as CIPM, CIPT, CIPP/E, CISA, or ISO 27001 Lead Implementer/Auditor
- •Experience with compliance automation platforms like Vanta or Drata and trust center tooling
- •Familiarity with AI governance frameworks such as NIST AI RMF, ISO/IEC 42001, EU AI Act
- •Experience with ML/AI data pipelines and training-data governance
- •Compliance work in hybrid deployment models (multi-tenant SaaS and self-hosted)
- •Comfort with SQL, light scripting, or AI tooling for evidence assembly
- •Exposure to HIPAA or FedRAMP
