Jobs › CCPA / CPRA
CCPA and CPRA (California Privacy) Jobs
The CCPA, as amended by the CPRA, is California's privacy law and the leading US state privacy regime.
The California Consumer Privacy Act (CCPA), in effect since 2020 and significantly expanded by the California Privacy Rights Act (CPRA) from January 2023, is the most influential state privacy law in the United States. It gives California residents rights to know, delete, correct, and opt out of the sale or sharing of their personal information, and it created a dedicated regulator, the California Privacy Protection Agency, to enforce and make rules. The CPRA added protections for sensitive personal information and obligations around data minimization, retention, and risk assessments.
California set the pattern that Virginia, Colorado, Connecticut, Texas, and a growing list of states have adapted, so a CCPA/CPRA program is usually the foundation of a US multistate privacy operation. For privacy and governance professionals, it is the most commonly required US framework after the GDPR, and the two together cover most of the global privacy map.
CCPA / CPRA: Frequently Asked Questions
What is the difference between the CCPA and the CPRA?
The CPRA is a 2020 ballot measure that amended and expanded the CCPA. It took effect in January 2023, added rights and protections for sensitive personal information, and created the California Privacy Protection Agency.
Who has to comply with the CCPA/CPRA?
For-profit businesses that handle California residents' personal information and meet thresholds on revenue, data volume, or data-sale activity.
Does the CCPA apply to businesses outside California?
Yes. A business anywhere must comply if it meets the thresholds and handles the personal information of California residents.
Open CCPA / CPRA GRC jobs (32)
Cybersecurity Requirements and Data Protection Lead
Credit Risk Officer, Energy Trading Credit Risk Management - Vice President
Latin America Credit Risk Officer - Vice President
Leveraged Finance Risk - Vice President
Data Privacy and Security Counsel (US Federal)
Governance, Risk, and Compliance Manager - FedRAMP
Governance, Risk, and Compliance Manager - Privacy
Manager, Legal Programs (Privacy & AI)
Technology Auditor – Compliance & Anti-Financial Crime - Assistant Vice President
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Security, Risk and Compliance Consultant
Interim General Counsel
Global Risk and Compliance Manager
Staff+ Software Engineer, Privacy
Privacy Operations Program Manager
Sr. Counsel, Privacy Compliance
Product & Privacy Counsel
Field CISO
Director, Privacy Counsel
Governance, Risk & Compliance Analyst
Senior AI Governance Counsel
Virtual CISO & Cybersecurity Practice Lead
Security, Risk and Compliance Consultant
Staff Software Engineer - Data Governance
Security Compliance Analyst, Privacy
IT Enterprise Risk Analyst
CCPA / CPRA jobs: what the market looks like right now
A snapshot built from the 32 CCPA / CPRA roles currently on this page.
What these roles pay by level
| Level | Median midpoint | Postings |
|---|---|---|
| Mid-level | $209k | 5 |
| Executive / C-suite | $174k | 6 |
How these figures were calculated, and sources
Primary source: our own board. Every figure above is the median midpoint of the salary ranges published in the live postings on this page. Nothing is estimated, modelled, or carried over from a previous month. It is recalculated each time the board refreshes.
What is included. Only postings that publish a salary range. Hourly, weekly and monthly rates are annualised (2,080 hours, 52 weeks, 12 months). Ranges below $20,000 a year are excluded as data-entry placeholders. A seniority band is shown only when at least five postings support it; senior / lead / manager is present on this page but below that threshold, so no median is published for that band.
What this is not. These are advertised ranges, not accepted offers. Advertised ranges tend to run wider than what is actually paid, and roles that do not publish a range are missing from the calculation entirely, which can bias the result upward.
For an independent benchmark, compare against the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC 13-1041 — Compliance Officers, published annually at bls.gov/oes. BLS reports actual wages across all employers rather than advertised ranges, so its medians normally sit below job-board figures.
Where the work is
- Work mode: 4 remote, 1 hybrid, 27 on-site or unstated.
- Seniority mix: mid (17), senior (8), executive (6), director (1)
- Employers hiring more than one: SEI (9), Deutsche Bank (4), Decagon (2)
Skills these postings ask for
- data mapping and records of processing
- DSAR and rights request handling
- privacy impact assessments (DPIA/PIA)
- GDPR and CCPA/CPRA application
- vendor and transfer assessments
How to get a privacy job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in CCPA / CPRA postings to be worth knowing: CIPP/US, CIPP/E, CIPM, CIPT, AIGP. The certification academy covers what each one actually tests and who it is for.
Hiring for CCPA / CPRA?
We have 32 open CCPA / CPRA roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
All GRC jobs · Job alerts