Skip to content
MozillaMozillaUnited States

Senior Privacy & Compliance Program Manager

Senior Privacy & Compliance Program Manager to coordinate privacy, compliance, data governance, and vendor review programs at Thunderbird/MZLA. Build practical processes for a growing open-source email company serving a global user base with strong EU presence; requires 8+ years experience and technical fluency.

Salary not listed
Remote8+ YOEOther

About the role

Responsibilities

  • Coordinate MZLA’s privacy and compliance program work, including program planning, recurring reviews, risk tracking, documentation, and leadership reporting.
  • Translate privacy, security, and compliance requirements into practical processes that fit MZLA’s products, infrastructure, support workflows, vendor ecosystem, and operating model.
  • Coordinate vendor and tool reviews, working with legal, engineering, product, support, finance, operations and other stakeholders to identify and document data flows, subprocessors, privacy, security, contractual, and operational considerations.
  • Support privacy operations and data governance for a global user base, including DSAR and privacy-rights workflows, records of processing, retention practices, privacy policy maintenance, international privacy considerations, and related documentation.
  • Help develop and maintain practical data inventories and data maps that document what data MZLA collects, where it is stored, how it is used, which vendors or systems are involved, and applicable retention practices.
  • Partner with technical teams to support privacy-by-design practices and help ensure that new products, services, tools, and data-processing activities are reviewed early and appropriately.
  • Support compliance and audit-readiness efforts, including ISO-related readiness, policy adoption, evidence tracking, control implementation, access reviews, training, and remediation follow-up.
  • Help establish recurring review practices for vendors, tools, systems, policies, and data-processing activities to ensure documentation remains current as products and operations evolve.
  • Help strengthen incident response readiness by clarifying roles, escalation paths, documentation expectations, and coordination across Legal, Infrastructure, leadership, and other relevant teams.
  • Build lightweight guidance, checklists, templates, and training materials that help teams meet privacy and compliance expectations without creating unnecessary bureaucracy.

Requirements

  • 8+ years of relevant professional experience, preferably within a software, SaaS, technology, or technical product environment.
  • 5+ years of direct or closely related hands-on experience in privacy operations, compliance program management, GRC, legal operations, security compliance, vendor governance, data governance, or a similar function.
  • Experience coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams, including work with external counsel, advisors, auditors, consultants, or vendors to move complex work forward.
  • Experience supporting vendor, tool, or subprocessor reviews, including privacy, security, legal, and operational risk considerations.
  • Experience supporting privacy operations, data governance, or user-rights workflows for products or services with international users, including areas such as GDPR or EU privacy requirements, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy maintenance.
  • Technical fluency and the ability to work with technical teams to understand how data moves through systems, including cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage.
  • Familiarity with incident response, breach readiness, or security/privacy escalation processes.
  • Strong project and program management skills, excellent written communication, sound judgment, and the ability to build pragmatic, right-sized processes for a small but growing organization.
  • Ability to learn, evaluate, and responsibly use emerging technologies, including AI-enabled tools, to improve work processes.
  • Ability to operate with initiative in areas where processes are still evolving, including identifying stakeholders, proposing next steps, clarifying ownership, and knowing when to escalate.

Nice-to-Haves

  • Experience supporting ISO 27001 readiness, SOC 2 readiness, audits, certifications, or similar compliance efforts.
  • Experience working in an open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organization.
  • Experience developing training or enablement materials for privacy, security, compliance, vendor review, or data handling.
  • Experience with GRC platforms, policy management tools, ticketing systems, vendor management tools, or other systems used to track compliance workflows.
  • Privacy certification such as CIPP/E, CIPP/US, CIPM, or similar.

Skills

privacy operationscompliance program managementGRCData Governancevendor governanceGDPRdsarISO 27001SOC 2Incident Responseprivacy by designdata mappingProject Management

Similar roles

Flexport

Site Leader

FlexportDallas, TX

Oversee operations of a large fulfillment center handling D2C and B2B orders. Lead 300+ associates and 10 managers to drive efficiency, cost reduction, safety, and continuous improvement while meeting KPIs and financial targets.

Salary not listed
On-site7+ YOEOther
Crusoe

Workplace Food & Beverage Manager

CrusoeSan Francisco, CA +1

Lead the development and execution of a unified Food & Beverage strategy across Crusoe's offices, data centers, and manufacturing sites. Own vendor transitions, guidelines, budgeting, sustainability, and program metrics while partnering with operations and leadership.

115k – 150k/yr
On-site7+ YOEOther
Skydio

Senior Learning Experience Developer

SkydioSan Mateo, CA

Design and produce immersive, simulation-driven learning experiences for drone pilots and technicians. Translate complex autonomous flight concepts into engaging multimedia training using video, animation, AR/VR, AI, and game engines. Requires 7+ years in instructional media production for technical products.

123k – 155k/yr
Hybrid7+ YOEOther
Column

Correspondent Banking Compliance

ColumnSan Francisco, CA

Support Column's correspondent banking expansion by owning end-to-end onboarding diligence, country risk assessments, ongoing monitoring, and compliance frameworks for global bank partners. Requires 6-8+ years in international financial compliance/risk, strong policy-building skills, and frequent travel.

Salary not listed
Remote6+ YOEOther
xAI

Quality Program Lead, X Safety

xAIBastrop, TX

Lead the end-to-end Quality Assurance program for content moderation at SpaceXAI, overseeing global operations, vendor frameworks, AI-driven analytics, team management, and continuous improvements to ensure policy compliance, user safety, and operational excellence in Trust & Safety workflows.

Salary not listed
On-site5+ YOEOther