The opportunity
Deadline to apply: None. Applications will be received on a rolling basis.
What you'll do
Own the end-to-end privacy incident management program: detection workflows, response processes, escalation paths, communication standards, and remediation tracking.
Serve as incident commander for privacy incidents, driving clear coordination: across executive, engineering, security, legal, and other appropriate stakeholders.
Establish and run incident commander rotations within privacy, ensuring clear: ownership and effective coordination during incidents of varying severity.
Drive post-incident accountability by defining how action items are captured,: assigned, tracked, and completed across teams, ensuring follow-through on both tactical fixes and strategic improvements.
Gather, analyze, and report on incident trends and patterns to surface: systemic risks, recurring root causes, and areas where the organization is most vulnerable.
Translate trend analysis into actionable cross-functional initiatives: partner with engineering, infrastructure, security, and product teams to prioritize and implement broad fixes and preventive improvements that address root causes rather than symptoms.
What they're looking for
- Have 7+ years of experience in technical program management, incident: management, or security/privacy operations, with significant time spent in an incident response context.
- Are familiar with privacy regulation and breach-notification obligations: (GDPR, CCPA, HIPAA or similar) and comfortable working with legal counsel under privilege, or have a legal background.