Privacy Operations Lead

Deepgram•,
•$165,000 - $223,300

About The Position

Deepgram is seeking a Privacy Operations Lead to manage the operational framework of its privacy program. The role involves understanding and documenting data movement across various deployment models (hosted with and without model improvement, single-tenant Deepgram Dedicated, and self-hosted). The lead will create artifacts like data flow maps, records of processing, assessment templates, and playbooks to support Legal, Engineering, and Sales Engineering. This position requires acting as the technical expert in enterprise customer privacy reviews and is not primarily a policy-writing role. Approximately half of the work will focus on assessment and advisory, with the other half dedicated to designing and operating processes and tools for repeatable and verifiable privacy claims. Collaboration with Security and Engineering will be necessary for technical verification, with the lead defining the requirements. The role reports to the Director of Information Security and works closely with Legal, Engineering, and Solutions/Sales Engineering. Deepgram is open to calibrating the title, scope, and compensation based on demonstrated experience, recognizing this as a senior individual-contributor position.

Requirements

  • Substantial experience in privacy operations, legal operations, or technical privacy and compliance — enough that you have run assessments end to end and owned the outcome.
  • Demonstrated ownership of privacy operational systems at scale: data maps, DSAR workflows, consent management, retention processes, or the tooling behind them.
  • Technically fluent and unintimidated: you can read an architecture diagram, follow a data flow through datacenter and cloud infrastructure, understand what a log line or a retention setting actually implies, and ask the questions that expose a gap — without needing someone to translate for you.
  • Practical, applied experience with GDPR and CCPA/CPRA, and a current view of where AI regulation is heading.
  • Able to hold your own with a Fortune 500 privacy team or DPO without escalating every question.
  • Clear writer. A large share of this job is producing documents that customers, auditors, and engineers rely on.
  • Strong bias toward automating and documenting your own work rather than becoming the bottleneck for it.
  • Comfortable with ambiguity and with making a defensible call when the law is unsettled.

Nice To Haves

  • CIPM, CIPT, CIPP/E, or equivalent certification.
  • Comfort reading code (Python, Go, Rust, or TypeScript), writing SQL, or scripting your own tooling.
  • Familiarity with on-premise or colocation infrastructure, containerized (Docker) workloads, and how data residency works outside a single cloud provider; AWS familiarity a plus.
  • Experience with ML/AI data pipelines and training-data governance.
  • Privacy work in a hybrid model — multi-tenant SaaS alongside self-hosted or on-premise deployments.
  • Exposure to formal audits: SOC 2, ISO 27001, HIPAA, PCI DSS.

Responsibilities

  • Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end.
  • Be the technical voice in customer privacy reviews and vendor due diligence calls.
  • Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments — including which datacenter, region, or cloud each flow touches — and own the process that keeps them accurate as the product changes.
  • Translate GDPR, UK GDPR, CCPA/CPRA and other US state privacy laws, and emerging AI regulation (EU AI Act, state AI and automated decision-making rules) into concrete requirements that engineering and GTM teams can act on, rather than memos.
  • Define the privacy requirements for product and infrastructure changes — retention, logging and telemetry, third-party subprocessors, training-data lineage — and drive them to implementation with the owning teams.
  • Own the operating model for our privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction. You specify, instrument, test, and audit; Engineering builds.
  • Design and run operational auditing and remediation workflows, so drift between what we claim and what we do is caught by process rather than by a customer.
  • Own the subprocessor and vendor privacy review process — including colocation and infrastructure providers — and the artifacts that support our DPAs and trust center.
  • Own privacy enablement: playbooks, self-service guidance, and training for Engineering, Support, and Sales Engineering — including what Sales Engineering is and is not allowed to promise.
  • Partner with Legal on DPAs, SCCs, transfer mechanisms, and the residency commitments we make for dedicated deployments.
  • Partner with Security so that privacy evidence and security evidence (SOC 2, ISO 27001, PCI DSS) are produced once and reused.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service