# Senior Privacy & Compliance Program Manager

**Company:** [Mozilla](https://hotfix.jobs/companies/mozilla)
**Location:** Remote
**Role:** Other
**Experience:** 8+ years
**Skills:** privacy operations, compliance program management, GRC, Data Governance, vendor governance, GDPR, dsar, ISO 27001, SOC 2, Incident Response, privacy by design, data mapping, Project Management
**Posted:** 2026-07-23

> Senior Privacy & Compliance Program Manager to coordinate privacy, compliance, data governance, and vendor review programs at Thunderbird/MZLA. Build practical processes for a growing open-source email company serving a global user base with strong EU presence; requires 8+ years experience and technical fluency.

## Job Description

## Responsibilities
- Coordinate MZLA’s privacy and compliance program work, including program planning, recurring reviews, risk tracking, documentation, and leadership reporting.
- Translate privacy, security, and compliance requirements into practical processes that fit MZLA’s products, infrastructure, support workflows, vendor ecosystem, and operating model.
- Coordinate vendor and tool reviews, working with legal, engineering, product, support, finance, operations and other stakeholders to identify and document data flows, subprocessors, privacy, security, contractual, and operational considerations.
- Support privacy operations and data governance for a global user base, including DSAR and privacy-rights workflows, records of processing, retention practices, privacy policy maintenance, international privacy considerations, and related documentation.
- Help develop and maintain practical data inventories and data maps that document what data MZLA collects, where it is stored, how it is used, which vendors or systems are involved, and applicable retention practices.
- Partner with technical teams to support privacy-by-design practices and help ensure that new products, services, tools, and data-processing activities are reviewed early and appropriately.
- Support compliance and audit-readiness efforts, including ISO-related readiness, policy adoption, evidence tracking, control implementation, access reviews, training, and remediation follow-up.
- Help establish recurring review practices for vendors, tools, systems, policies, and data-processing activities to ensure documentation remains current as products and operations evolve.
- Help strengthen incident response readiness by clarifying roles, escalation paths, documentation expectations, and coordination across Legal, Infrastructure, leadership, and other relevant teams.
- Build lightweight guidance, checklists, templates, and training materials that help teams meet privacy and compliance expectations without creating unnecessary bureaucracy.

## Requirements
- 8+ years of relevant professional experience, preferably within a software, SaaS, technology, or technical product environment.
- 5+ years of direct or closely related hands-on experience in privacy operations, compliance program management, GRC, legal operations, security compliance, vendor governance, data governance, or a similar function.
- Experience coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams, including work with external counsel, advisors, auditors, consultants, or vendors to move complex work forward.
- Experience supporting vendor, tool, or subprocessor reviews, including privacy, security, legal, and operational risk considerations.
- Experience supporting privacy operations, data governance, or user-rights workflows for products or services with international users, including areas such as GDPR or EU privacy requirements, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy maintenance.
- Technical fluency and the ability to work with technical teams to understand how data moves through systems, including cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage.
- Familiarity with incident response, breach readiness, or security/privacy escalation processes.
- Strong project and program management skills, excellent written communication, sound judgment, and the ability to build pragmatic, right-sized processes for a small but growing organization.
- Ability to learn, evaluate, and responsibly use emerging technologies, including AI-enabled tools, to improve work processes.
- Ability to operate with initiative in areas where processes are still evolving, including identifying stakeholders, proposing next steps, clarifying ownership, and knowing when to escalate.

## Nice-to-Haves
- Experience supporting ISO 27001 readiness, SOC 2 readiness, audits, certifications, or similar compliance efforts.
- Experience working in an open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organization.
- Experience developing training or enablement materials for privacy, security, compliance, vendor review, or data handling.
- Experience with GRC platforms, policy management tools, ticketing systems, vendor management tools, or other systems used to track compliance workflows.
- Privacy certification such as CIPP/E, CIPP/US, CIPM, or similar.

## Similar roles

- [Site Leader](https://hotfix.jobs/jobs/2e771ae6-2086-4950-931f-cc4ffddeee2a) - Flexport - Dallas, TX
- [Workplace Food & Beverage Manager](https://hotfix.jobs/jobs/603a6d3d-d01c-4843-bd76-00640b0d542c) - Crusoe - San Francisco, CA - $115k – $150k/yr
- [Senior Learning Experience Developer](https://hotfix.jobs/jobs/5cb3ebc5-1285-4af4-b510-5cca99b23998) - Skydio - San Mateo, CA - $123k – $155k/yr
- [Correspondent Banking Compliance](https://hotfix.jobs/jobs/d73d2c01-9426-465d-bc5f-7508c882e0ce) - Column - Remote
- [Quality Program Lead, X Safety](https://hotfix.jobs/jobs/801202a0-6a71-4541-93f2-01ec82cc5da1) - xAI - Bastrop, TX

**Apply:** https://hotfix.jobs/jobs/3bd29eb1-3301-4a49-bb54-6d2b5fe418da
**Canonical:** https://hotfix.jobs/jobs/3bd29eb1-3301-4a49-bb54-6d2b5fe418da