| Title | Privacy Program Manager |
|---|---|
| Department | [Privacy / Legal / Compliance / Risk] |
| Reports to | [Director of Privacy / Chief Privacy Officer / General Counsel] |
| Location | [Remote / Hybrid / On-site and location] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
[Company] is hiring a Privacy Program Manager to lead [the enterprise privacy program / named privacy workstreams] across [regions, products or business units]. You will translate privacy requirements into policies, controls, operating processes, accountable ownership and measurable reporting.
The manager will work across Legal, Security, Product, Engineering, Data, HR, Marketing, Procurement and Internal Audit. Success requires privacy judgment, disciplined program design and the ability to influence leaders who do not report to you.
Key responsibilities
Key responsibilities
- Maintain the privacy framework, policies, standards and multi-year roadmap.
- Translate legal obligations into controls, processes, ownership and evidence.
- Oversee [assessments, rights requests, inventories, vendor reviews, incidents and training].
- Lead privacy work for new laws, products, acquisitions or data uses.
- Maintain issue, exception, remediation and risk-acceptance processes.
- Define metrics and report privacy risk and program performance to leadership.
- Coordinate with Legal, Security, Data Governance, Product and AI Governance.
- Manage [team members, vendors, technology and budget, if applicable].
- Prepare for audits, regulatory inquiries and executive or board reporting.
- Build privacy awareness and a network of accountable business partners.
Required qualifications
- [Five to eight] years in privacy, data protection, compliance, risk, legal, audit, security or a related field, including meaningful program ownership.
- Demonstrated ability to design or improve controls and cross-functional processes.
- Working knowledge of privacy laws relevant to [Company]'s operations.
- Experience reporting risk, performance and remediation to senior stakeholders.
- Strong prioritization, writing, facilitation and influence skills.
Preferred certifications
CIPP and/or CIPM; CIPT, CDPSE or AIGP where technically relevant.; Experience in [industry] and with [jurisdictions].; Experience implementing or governing privacy-management technology.; People, vendor or budget management experience if included in the role.; Experience with product development, data governance or AI governance.
Technical knowledge
GDPR, CCPA / CPRA, ISO/IEC 27701, NIST Privacy Framework, privacy impact assessments, data mapping, records of processing.
Essential competencies
Analysis, documentation, judgment, cross-functional collaboration, and clear communication of privacy risk.
Success in the first year
- The program has a risk-based roadmap, clear ownership and credible reporting.
- High-risk data uses receive timely review and documented decisions.
- Material issues are visible, prioritized and progressing toward closure.
- Business teams understand when and how to engage Privacy.
- Leadership can see where privacy investment is reducing risk.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in privacy program design and delivery rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live Privacy jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new Privacy jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.