Назад
Company hidden
6 дней назад

Senior Privacy & Compliance Program Manager (GRC)

115 000 - 145 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Privacy & Compliance Program Manager (GRC): Building and strengthening privacy, compliance, and data governance practices for the Thunderbird email ecosystem with an accent on vendor reviews and international privacy regulations. Focus on translating legal requirements into practical technical processes and ensuring audit-readiness for a global user base.

Location: Remote (US). Must reside in and have permanent work authorization for the United States

Salary: $115,000 - $145,000

Company

MZLA (Thunderbird), a nonprofit-owned company part of the hirify.global family, develops privacy-respecting communication and productivity tools.

What you will do

  • Coordinate privacy and compliance programs, including planning, risk tracking, and leadership reporting.
  • Translate privacy and security requirements into operational processes for products, infrastructure, and support workflows.
  • Manage vendor and tool reviews to document data flows, subprocessors, and operational risks.
  • Oversee global data governance, including DSAR workflows, records of processing, and retention practices.
  • Partner with technical teams to implement privacy-by-design practices for new products and services.
  • Support compliance and audit-readiness efforts, specifically for ISO 27001 and SOC 2 certifications.

Requirements

  • 8+ years of professional experience in software, SaaS, or technology environments.
  • 5+ years of hands-on experience in privacy operations, GRC, legal operations, or vendor governance.
  • Experience coordinating cross-functional programs across legal, engineering, and product teams.
  • Deep knowledge of international privacy requirements, specifically GDPR and EU privacy laws.
  • Technical fluency to understand data movement through cloud services, logs, and authentication systems.
  • Must reside in the US and have permanent work authorization; no visa sponsorship provided.

Nice to have

  • Experience supporting ISO 27001 or SOC 2 readiness and audits.
  • Privacy certifications such as CIPP/E, CIPP/US, or CIPM.
  • Experience working in open-source or mission-driven technology organizations.
  • Familiarity with GRC platforms and policy management tools.

Culture & Benefits

  • Fully remote work with schedule flexibility and a monthly remote work stipend.
  • Comprehensive health, dental, and vision insurance plus 401(k) contributions.
  • Generous time off: 24 days PTO, wellbeing days, and a year-end company shutdown.
  • Annual professional development stipend and access to Coursera.
  • Annual bonus program and company-provided laptop.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →