Privacy Manager
Job description
Privacy Manager at Sezzle
About the role
Sezzle is establishing a comprehensive privacy program based on the NIST Privacy Framework. This role offers a unique chance to build and lead this initiative from its foundational stages within a rapidly expanding team. You will be instrumental in shaping how Sezzle handles data, ensuring user protection while enabling product innovation.
Key facts
What you'll do
Drive the implementation of the NIST Privacy Framework, including developing profiles, conducting gap analyses, and creating action plans aligned with US (CCPA/CPRA, GLBA, TCPA) and Canadian (PIPEDA, Law 25) privacy regulations.
Manage privacy risk assessments and Privacy Impact Assessments for new products, features, and third parties, establishing a process for timely review and approval.
Develop and maintain an enterprise data inventory and map, and oversee the fulfillment of consumer data rights requests.
Administer the de-identification and aggregation standards and their associated approval workflows to support data-driven products.
Collaborate with Engineering, Product, and Marketing teams to integrate privacy considerations into the early stages of development.
Facilitate the privacy working group, track program metrics, and support executive reporting, working with Information Security on incident response and data transfer risks.
Requirements
Over 4 years of experience managing data privacy programs, including building at least one significant program component from inception.
Demonstrated experience implementing a privacy or security framework such as NIST Privacy Framework, NIST CSF, or ISO 27701.
Solid understanding of North American privacy laws including CCPA/CPRA, US state privacy laws, TCPA, GLBA, PIPEDA, and Quebec's Law 25.
Experience with privacy-enhancing techniques like de-identification and aggregation.
Strong communication and influencing skills, with the ability to work effectively with technical and non-technical stakeholders.
A proactive and self-starting approach to managing multiple projects in a fast-paced environment.
Nice to have
CIPM certification, along with CIPP/US or CIPP/C. CIPT is also beneficial.
Familiarity with privacy technology platforms such as OneTrust, Securiti.ai, or WireWheel, and data analytics infrastructure.
Experience with financial regulations and compliance frameworks like GLBA and PCI-DSS.
Previous experience supporting public company reporting, including to audit committees or boards.
Skills & tools
NIST Privacy Framework
CCPA/CPRA
GLBA
TCPA
PIPEDA
Quebec Law 25
De-identification
Data mapping
Privacy Impact Assessments
Practical notes
Compensation range: $4,500 - $6,500 USD GROSS per month.
This role is fully remote.