Senior Privacy & Compliance Program Manager
Job description
About the role
In this pivotal role, you will play a key part in shaping and refining the privacy, compliance, data governance, and vendor assessment strategies for Mozilla's products and operations. Your expertise will be essential in converting privacy and compliance requirements into actionable processes that foster user trust and ensure responsible data management.
Key facts
What you'll do
- Lead the privacy and compliance initiatives at MZLA, which includes planning, conducting reviews, tracking risks, and preparing documentation and reports for leadership.
- Develop and implement effective processes that harmonize privacy, security, and compliance requirements with MZLA's operational practices.
- Collaborate with legal, engineering, product, support, finance, and operations teams to oversee vendor assessments and tool evaluations.
- Create comprehensive documentation of data flows, subprocessors, and pertinent privacy, security, contractual, and operational information.
- Support privacy operations and data governance for a diverse global user base, including managing data subject access requests (DSARs).
- Assist in the creation and upkeep of data inventories, records of processing activities, retention schedules, and privacy-related documentation.
- Work alongside technical teams to incorporate privacy-by-design principles into new products, services, and data-related activities.
- Contribute to compliance and audit readiness initiatives, including tracking necessary evidence and managing remediation efforts.
- Enhance incident response preparedness by defining roles, establishing escalation paths, and identifying documentation requirements.
- Develop clear guidance, checklists, and training resources to assist teams in meeting privacy and compliance standards without introducing unnecessary complexity.
Requirements
- A minimum of 8 years of professional experience, preferably in software, SaaS, technology, or technical product sectors.
- At least 5 years of hands-on experience in privacy operations, compliance program management, governance, risk management, legal operations, security compliance, or data governance.
- Proven ability to coordinate cross-functional programs that involve legal, engineering, product, support, finance, and operations teams, including collaboration with external advisors and vendors.
- Experience in conducting vendor, tool, or subprocessor reviews, assessing privacy, security, legal, and operational risks.
- Familiarity with privacy operations, data governance, or user rights workflows for international users, including knowledge of GDPR or similar regulations, DSARs, data deletion/export requests, data inventories, records of processing, retention, access controls, or privacy policy updates.
- Technical knowledge to collaborate effectively with engineering teams on data movement within systems, including cloud services, vendor tools, support systems, and data storage solutions.
- Understanding of incident response, breach readiness, or security/privacy escalation protocols.
- Strong project and program management skills, excellent written communication abilities, sound judgment, and the capability to develop practical processes for a growing organization.
- Willingness to learn and apply emerging technologies, including AI tools, to improve work processes.
- Ability to proactively identify stakeholders, suggest next steps, clarify ownership, and escalate issues in dynamic environments.
Nice to have
- Experience in supporting ISO 27001 or SOC 2 readiness, audits, or certifications.
- Background in open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organizations.
- Experience in creating training or enablement materials related to privacy, security, compliance, vendor review, or data handling.
- Familiarity with governance, risk, and compliance (GRC) platforms, policy management tools, ticketing systems, or vendor management solutions.
- Possession of a privacy certification such as CIPP/E, CIPP/US, CIPM, or an equivalent credential.
Skills & tools
- Program Management
- Privacy Operations
- Compliance Management
- Data Governance
- Vendor Risk Management
- Governance, Risk, and Compliance (GRC)
- Cross-functional Collaboration
- Technical Fluency
- Incident Response
- Documentation
Practical notes
This position is fully remote and offered on a full-time basis. The salary for this role in Canada ranges from CAD 100,000 to CAD 125,000 annually, with the final compensation determined based on qualifications and experience. Benefits include a company-issued laptop and participation in an annual bonus program. The role requires significant overlap with Eastern Time working hours for effective meetings and collaboration.