Own and maintain core components of the enterprise privacy program, including governance, documentation, and operational workflows
Lead and independently conduct privacy impact assessments for new features, data uses, third-party vendors, and emerging technologies
Own and manage data subject rights processes and requests
Partner with Engineering, Operations, and Security teams to embed privacy-by-design and privacy-by-default principles into systems and development lifecycles
Maintain privacy program artifacts such as records of processing activities, data inventories, data flow diagrams, and control documentation to support audits and regulatory inquiries
Support compliance with applicable privacy and data protection laws and frameworks (e.g., GDPR, CCPA/CPRA, PIPEDA, and other relevant and emerging regulations)
Coordinate privacy risk management activities, including identifying, assessing, tracking, and remediating privacy risks and promote a culture of compliance
Collaborate with Security and Compliance teams on privacy incident preparedness, investigation, and response, including regulatory and customer notification support where required
Support third-party and vendor privacy risk management and the commercial legal team, including reviews of data processing agreements and privacy-related contractual provisions
Develop, maintain, and improve privacy policies, standards, procedures, and guidance for internal stakeholders
Design and deliver privacy training and awareness initiatives to promote a culture of privacy across the organization
Monitor regulatory developments, industry trends, and emerging privacy risks to proactively enhance the privacy program
Provide regular reporting on privacy program status, risks, and key metrics to leadership and senior stakeholders
Protect the security and privacy of Absolute and its customers
Requirements
Bachelor’s degree in law, business, information systems, compliance, information security, or a related field (or equivalent practical experience)
5+ years of experience in privacy, data protection, compliance, risk management, and/or data governance roles within a regulated or technology-driven environment
Strong working knowledge of global and domestic privacy and data protection regulations and frameworks relevant to the organization’s industry
Hands-on experience conducting and managing privacy impact assessments and operationalizing regulatory requirements
Demonstrated ability to work cross-functionally with technical and non-technical teams and translate legal or regulatory requirements into actionable controls
Strong program development and management skills, including the ability to manage multiple initiatives, prioritize risk, and drive execution in a fast-paced environment
Excellent written and verbal communication skills, with the ability to influence stakeholders at multiple levels
Experience supporting audits, regulatory examinations, and customer privacy reviews
Professional privacy certifications (e.g., CIPP, CIPM, CIPT) preferred but not required
Experience with cloud platforms, data platforms, AI/ML systems, and/or complex data ecosystems is a plus.