Senior Privacy & Compliance Program Manager

Mozilla
$115,000 - $145,000Remote

About The Position

Thunderbird is expanding beyond its free desktop and mobile applications and is seeking a Senior Privacy & Compliance Program Manager. This role is crucial for building and strengthening privacy, compliance, data governance, and vendor review practices to support MZLA's products and operations. Privacy and compliance are central to maintaining user trust, especially with a significant European user base. The manager will translate privacy, security, and compliance requirements into practical processes for products, services, infrastructure, support, vendors, and the operating model. MZLA is a small, growing organization, so this role requires a hands-on program manager who can create structure without overcomplication. The position involves collaboration across legal, engineering, product, support, finance, operations, and Mozilla-wide partners to clarify ownership, track progress, identify escalations, and drive cross-functional privacy and compliance initiatives. The role demands strong judgment, excellent follow-through, and the ability to operate across legal, technical, operational, and leadership contexts. The goal is to ensure privacy and compliance work is well-coordinated, documented, and grounded in practical processes that support user trust and responsible product development. This role requires regular overlap with Eastern Time working hours for meetings and collaboration, and candidates in other time zones must be able to maintain meaningful overlap with ET.

Requirements

  • 8+ years of relevant professional experience, preferably within a software, SaaS, technology, or technical product environment.
  • 5+ years of direct or closely related hands-on experience in privacy operations, compliance program management, GRC, legal operations, security compliance, vendor governance, data governance, or a similar function.
  • Experience coordinating cross-functional programs across legal, engineering, product, support, finance, and operations teams, including work with external counsel, advisors, auditors, consultants, or vendors to move complex work forward.
  • Experience supporting vendor, tool, or subprocessor reviews, including privacy, security, legal, and operational risk considerations.
  • Experience supporting privacy operations, data governance, or user-rights workflows for products or services with international users, including areas such as GDPR or EU privacy requirements, DSARs, deletion or export requests, data inventories, records of processing, retention, access controls, or privacy policy maintenance.
  • Technical fluency and the ability to work with technical teams to understand how data moves through systems, including cloud services, vendor tools, support systems, logs, telemetry, authentication, access permissions, and data storage.
  • Familiarity with incident response, breach readiness, or security/privacy escalation processes.
  • Strong project and program management skills, excellent written communication, sound judgment, and the ability to build pragmatic, right-sized processes for a small but growing organization.
  • Ability to learn, evaluate, and responsibly use emerging technologies, including AI-enabled tools, to improve work processes.
  • Ability to operate with initiative in areas where processes are still evolving, including identifying stakeholders, proposing next steps, clarifying ownership, and knowing when to escalate.

Nice To Haves

  • Experience supporting ISO 27001 readiness, SOC 2 readiness, audits, certifications, or similar compliance efforts.
  • Experience working in an open-source, consumer software, communications, email, privacy-focused, or mission-driven technology organization.
  • Experience developing training or enablement materials for privacy, security, compliance, vendor review, or data handling.
  • Experience with GRC platforms, policy management tools, ticketing systems, vendor management tools, or other systems used to track compliance workflows.
  • Privacy certification such as CIPP/E, CIPP/US, CIPM, or similar.

Responsibilities

  • Coordinate MZLA’s privacy and compliance program work, including program planning, recurring reviews, risk tracking, documentation, and leadership reporting.
  • Translate privacy, security, and compliance requirements into practical processes that fit MZLA’s products, infrastructure, support workflows, vendor ecosystem, and operating model.
  • Coordinate vendor and tool reviews, working with legal, engineering, product, support, finance, operations and other stakeholders to identify and document data flows, subprocessors, privacy, security, contractual, and operational considerations.
  • Support privacy operations and data governance for a global user base, including DSAR and privacy-rights workflows, records of processing, retention practices, privacy policy maintenance, international privacy considerations, and related documentation.
  • Help develop and maintain practical data inventories and data maps that document what data MZLA collects, where it is stored, how it is used, which vendors or systems are involved, and applicable retention practices.
  • Partner with technical teams to support privacy-by-design practices and help ensure that new products, services, tools, and data-processing activities are reviewed early and appropriately.
  • Support compliance and audit-readiness efforts, including ISO-related readiness, policy adoption, evidence tracking, control implementation, access reviews, training, and remediation follow-up.
  • Help establish recurring review practices for vendors, tools, systems, policies, and data-processing activities to ensure documentation remains current as products and operations evolve.
  • Help strengthen incident response readiness by clarifying roles, escalation paths, documentation expectations, and coordination across Legal, Infrastructure, leadership, and other relevant teams.
  • Build lightweight guidance, checklists, templates, and training materials that help teams meet privacy and compliance expectations without creating unnecessary bureaucracy.

Benefits

  • Fully remote work & schedule flexibility
  • Company-provided laptop
  • Annual bonus program
  • Monthly remote work stipend
  • Annual professional development stipend
  • Access to Coursera learning platform
  • Industry conferences
  • Company all-hands and team gatherings
  • 24 days PTO per year (prorated)
  • Your birthday
  • Year-end company shutdown
  • 9 wellbeing days
  • Public holidays
  • Other paid leave
  • Quarterly wellbeing stipend for personal / family activities
  • 401(k) / RRSP contributions
  • Health, dental, & vision insurance
  • Disability insurance
  • Life insurance
  • Employee assistance program
  • Paid parental leave
  • Paid sick days
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service