Back to Jobs
Legal & HR Just now

Senior Privacy & Compliance Program Manager

CanadaCanada
United StatesUnited States
Full-time
{"US":"$115,000 - $145,000","Canada":"$100,000 - $125,000"}
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Data GovernanceCompliance Program ManagementPrivacy OperationsVendor GovernanceGRC

Want to know if you're a match for this job?

Calculate My Match Score

The opportunity

Thunderbird is growing beyond our free desktop and mobile applications, and we’re looking for a Senior Privacy & Compliance Program Manager to help build and strengthen the privacy, compliance, data governance, and vendor review practices that support MZLA’s products and operations.

Privacy and compliance are central to how we build and maintain user trust, particularly for a global user base with a significant presence in Europe. As MZLA expands its products and services, this role will help ensure that data is collected, used, shared, retained, and governed responsibly, in line with Thunderbird’s values and user trust commitments. You will help translate privacy, security, and compliance requirements into practical processes that fit our products and services, infrastructure, support workflows, vendor ecosystem, and operating model.

MZLA is a small, growing organization, and the right person will be a hands-on program manager who can create structure without overcomplicating the work. You will work across legal, engineering, product, support, finance, operations, and other Mozilla-wide partners to clarify ownership, track open items, identify when issues need escalation, and keep cross-functional privacy and compliance work moving.

This role requires strong judgment, excellent follow-through, and the ability to operate across legal, technical, operational, and leadership contexts. You will help ensure privacy and compliance work is well coordinated, appropriately documented, and grounded in practical processes that support user trust and responsible product development.

This role requires regular overlap with Eastern Time working hours for meetings, collaboration, and time-sensitive coordination. We welcome candidates in other time zones who can consistently maintain meaningful overlap with ET.

What you’ll do

  • Coordinate MZLA’s privacy and compliance program work, including planning, recurring reviews, risk tracking, documentation, and leadership reporting.
  • Translate privacy, security, and compliance requirements into practical processes that fit how MZLA works.
  • Coordinate vendor and tool reviews with legal, engineering, product, support, finance, operations, and other stakeholders.
  • Help document data flows, subprocessors, and privacy, security, contractual, and operational considerations.
  • Support privacy operations and data governance for a global user base, including DSAR and privacy-rights workflows.
  • Help develop and maintain practical data inventories, records of processing, retention practices, and privacy-related documentation.
  • Partner with technical teams to support privacy-by-design practices for new products, services, tools, and data-processing activities.
  • Support compliance and audit-readiness efforts, including ISO-related readiness, evidence tracking, access reviews, and remediation follow-up.
  • Help strengthen incident response readiness by clarifying roles, escalation paths, documentation expectations, and coordination needs.
  • Build lightweight guidance, checklists, templates, and training materials that help teams meet privacy and compliance expectations without creating unnecessary bureaucracy.

What you bring

  • 8+ years of relevant professional experience, preferably within a software, SaaS, technology, or technical product environment.
  • 5+ years of direct or closely related hands-on experience in privacy operations, compliance program management, GRC, legal operations, security compliance, vendor governance, data governance, or a similar function.
  • Experience coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams, including work with external counsel, advisors, auditors, consultants, or vendors to move complex work forward.
  • Experience supporting vendor, tool, or subprocessor reviews, including privacy, security, legal, and operational risk considerations.
  • Experience supporting privacy operations, data governance, or user-rights workflows for products or services with international users, including areas such as GDPR or EU privacy requirements, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy maintenance.
  • Technical fluency and the ability to work with technical teams to understand how data moves through systems, including cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage.
  • Familiarity with incident response, breach readiness, or security/privacy escalation processes.
  • Strong project and program management skills, excellent written communication, sound judgment, and the ability to build pragmatic, right-sized processes for a small but growing organization.
  • Ability to learn, evaluate, and responsibly use emerging technologies, including AI-enabled tools, to improve work processes.
  • Ability to operate with initiative in areas where processes are still evolving, including identifying stakeholders, proposing next steps, clarifying ownership, and knowing when to escalate.

Bonus points for

  • Experience supporting ISO 27001 readiness, SOC 2 readiness, audits, certifications, or similar compliance efforts.
  • Experience working in an open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organization.
  • Experience developing training or enablement materials for privacy, security, compliance, vendor review, or data handling.
  • Experience with GRC platforms, policy management tools, ticketing systems, vendor management tools, or other systems used to track compliance workflows.
  • Privacy certification such as CIPP/E, CIPP/US, CIPM, or similar.

What success looks like

Success in this role means privacy and compliance work is clear, coordinated, and easier for teams to execute. You will help create practical processes, documentation, ownership, and escalation paths for vendor reviews, DSAR workflows, data governance, and compliance readiness.

Over time, your work will strengthen user trust, reduce operational risk, and help MZLA scale its products and services without adding unnecessary bureaucracy.

Work environment

You’ll work with our passionate staff, external partners, and open-source community members from around the world to support the mission and objectives of Thunderbird.

This is a remote, full-time position that requires strong communication, documentation, and follow-through. Because this role works across legal, technical, operational, and leadership contexts, you should be comfortable collaborating across time zones and disciplines through video meetings, shared documents, issue trackers, and asynchronous communication.

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More