GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsRemoteManager, Privacy Compliance

Manager, Privacy Compliance

Affirm
PrivacyRemoteFull-timeRemote$165,000 - $225,000

Affirm is hiring for the role of Manager, Privacy Compliance, Remote. This is a Privacy role in the governance, risk, and compliance field, with a posted range of $165,000 - $225,000. Review the full details below and apply directly with Affirm.

Organization: AffirmLocation: RemoteWorkplace: RemoteFocus: PrivacySalary: $165,000 - $225,000Posted: Aug 11, 2026
This is a remote Privacy role. Remote governance, risk, and compliance hiring has grown as organizations extend compliance, risk, and AI oversight across distributed teams, which widens the candidate pool beyond any single metro. Browse all remote GRC roles →

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

About the Team:

Affirm s Compliance organization supports the company s risk management framework across all three lines of defense, partnering with teams throughout the business to promote a strong culture of compliance and effective risk management. The Privacy Compliance team sits within the second line of defense and is responsible for the independent oversight and governance of Affirm s privacy compliance program. The team partners closely with Legal, Product, Engineering, Operations, and other business functions to establish policies, standards, and control expectations, monitor compliance with regulatory requirements, and provide independent challenge to help ensure privacy risks are effectively managed while maintaining second-line independence.

About the Role:

The Compliance Manager, Privacy operates within the second line of defense and is responsible for oversight and governance of the Privacy compliance program. This role translates legal and regulatory requirements into policies, standards, and control expectations, and provides independent monitoring and challenge to support effective implementation by first-line teams.

In alignment with the company’s privacy operating model, Legal retains responsibility for regulatory interpretation and legal advisory, while Product, Engineering, and Operations own the implementation and execution of controls. This role partners with those teams to drive compliant outcomes while maintaining second-line independence.

This role does not serve as a designated Data Protection Officer (DPO) and does not hold regulatory accountability for statutory privacy roles.

What You’ll Do:

2; Support oversight of the existing Privacy compliance program across jurisdictions, with primary focus on U.S. requirements and alignment to global privacy obligations, where required suggest improvements.
2; Translate Legal guidance and regulatory requirements into policies, standards, and control expectations, ensuring clear articulation of compliance requirements for first-line teams.
2; Provide oversight and maintain existing governance frameworks and standards for core privacy program areas, including: 2; Data subject rights (DSAR) processes and SLAs
2; Data protection impact assessment (DPIA) governance and documentation standards
2; Consent and preference management expectations
2; Data retention and deletion requirements

2; Partner with Product and Engineering to advise on and review the design and implementation of privacy controls, ensuring alignment to regulatory expectations while maintaining second-line independence.
2; Provide independent oversight and effective challenge of first-line privacy control environments, including review of control design, identification of gaps, and tracking of remediation actions.
2; Oversee privacy incident and breach response processes from a governance perspective, including review of escalation, documentation, and outcomes, in coordination with Legal on notification requirements.
2; Maintain privacy risk registers and support risk assessment processes, including DPIA oversight, issue identification, and remediation tracking.
2; Monitor adherence to privacy requirements and control expectations, including data subject rights processes, consent management, and regulatory obligations, and escalate issues where gaps are identified.
2; Support audits, regulatory examinations, and bank partner reviews by coordinating second-line input, reviewing materials, and tracking remediation actions.
2; Produce and contribute to privacy monitoring and governance reporting, including metrics and risk summaries for management and risk committees (e.g., RMC, CRMC).
2; Partner with third-party risk functions to provide second-line oversight of privacy considerations in vendor and merchant onboarding and monitoring processes.
2; Collaborate with international compliance and DPO functions to support consistent application of privacy governance frameworks, without assuming DPO accountability.
2; Support privacy training and awareness by defining requirements and reviewing program effectiveness in coordination with first-line execution teams.

What We Look For:

6–10+ years of experience in privacy compliance, regulatory compliance, risk management, or a related control function, preferably within financial services, fintech, or a regulated environment.

Strong understanding of U.S. privacy laws (e.g., CCPA/CPRA, GLBA) and familiarity with international regimes (e.g., GDPR, UK GDPR).

Experience operating within a second-line of defense model, including governance, oversight, and independent challenge of first-line control environments.

Demonstrated ability to translate regulatory requirements into policies, standards, and control expectations (not direct control ownership or legal interpretation).

Experience reviewing control design and effectiveness, including participation in audits, regulatory exams, or control testing programs.

Strong cross-functional partnership skills, with the ability to influence Product, Engineering, and Operations without direct ownership.

Sound judgment and ability to escalate and manage regulatory risk appropriately.

Bachelor’s degree or equivalent practical experience; relevant certifications (e.g., CIPP, CIPM) are a plus.

Pay Grade - L

Equity Grade - 6

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills.

Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA base pay range (CA, WA, NY, NJ, CT) per year: $165,000 - $225,000

USA base pay range (all other U.S. states) per year: $146,000 - $206,000

Please note that visa sponsorship is not available for this position.

# -Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

span 400; We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:

400; span 400; Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
400; span 400; Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
400; span 400; Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
400; span 400; ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

span 400; We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

U.S. positions that could be performed in Los Angeles or San Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking Submit Application, you acknowledge that you have read Affirm s a Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Location and market context

This is a remote privacy role, so it draws from a national talent pool rather than a single metro. Remote governance and compliance roles reward candidates who can show they work effectively across time zones and distributed legal, security, and product teams. Confirm any residency, travel, or occasional-onsite expectations directly with Affirm.

About privacy roles

Privacy roles protect personal data across its lifecycle, from data mapping and DPIAs to individual-rights handling. AI systems are widening the scope of what privacy teams must review. Roles like this one are typically evaluated against frameworks such as GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices.

How to position yourself for this privacy role

Strong candidates emphasize data mapping and inventories, privacy impact assessments, rights handling, and building privacy-by-design into products and AI systems. In your resume and outreach, tie your experience to how Affirm would apply GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Want to be next in a role like this?

Roles like Manager, Privacy Compliance (remote) open regularly. Be first to know — privately. No current employer ever sees you looking.

New Privacy roles, the moment they post. Tell us where to send them.

Unsubscribe anytime, one click.

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.