Responsibilities
- Provide strategic guidance and second line of defense oversight to improve company-wide operational processes to establish, measure, and improve privacy practices
- Support Meta's commitment to protect users' privacy by enabling and advising privacy domains to navigate the complex landscape of global and data privacy regulations
- Become a trusted partner to product, business, legal, and engineering teams across the company to develop deep insights and drive improvements into the mechanics of how teams incorporate compliance and privacy-by-design into operations and product life cycles
- Provide a second line of defense guidance and oversight to ensure Meta’s compliance with global privacy regulations and obligations across all new and modified products, services, and practices. Consult with legal partners to ensure that products and practices comply with global privacy laws and regulations
- Serve as a subject-matter expert with a deep understanding of the end-to-end (E2E) privacy compliance processes, including timelines and stakeholder involvement/expectations
- Manage the successful delivery of the external regulatory audit, ensuring all requirements are met, documentation is complete, and findings are addressed in a timely manner
- Provide compliance advisories and reviews for new safeguards, issues, remediation plans, monitors, and safeguard changes, ensuring alignment with regulatory expectations and internal standards
- Provide independent oversight to proactively identify issues, ensure visibility, and help prioritize remediation efforts within assigned safeguard domains, acting as a key escalation point and advocate for risk mitigation
- Develop long-term objectives for how we will evolve our privacy program operating model with well-documented roadmaps, goals, and objectives while delivering on immediate priorities
- Provide guidance to product, business, and engineering teams on complying with the Privacy Program and its day-to-day objectives
- Anticipate bottlenecks, provide escalation management, and ensure user privacy is not compromised
Minimum Qualifications
- 7+ years of work experience in GRC, consulting, business operations, technical program management or other operational disciplines with specialization in data privacy and cyber security either in the Tech industry, Financial Services, or Healthcare
- Prior to working knowledge of GDPR, CCPA, and familiarity with similar privacy data protection legislation and security regulations
- Experience running project management or program management initiatives (e.g., organization-wide initiatives, large-scale integration management)
- Experience in communicating with technical and business stakeholders
- Experience in responding to or supporting external audits, examinations, or regulatory inquiries
- Communications experience with simplifying concepts and developing outputs
- Track record of collaborating with cross-functional teams to drive results
- Experience identifying and resolving operational or compliance challenges in cross-functional environments
Preferred Qualifications
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
- Demonstrated experience orienting towards solutions in the context of competing perspectives
- Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
- Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)
- 10+ years of work experience in GRC, consulting, business operations, program management, or other operational disciplines with specialization in data privacy and cyber security, either in the Tech industry, Financial Services, or Healthcare
- Master's in business administration or a related field, or equivalent experience
$147,000/year to $210,000/year + bonus + equity + benefits
Learn more about this Employer on their Career Site
