CIPP/AU | Australia | IAPP
Featured Job Postings
Director of Legal & Privacy
Sovrn
AI Governance
53 days ago
Boulder, Colorado
Preferred Certifications
CIPP/US
CIPP/E
AIGP
This job is AIGP preferred. Want to improve your chance of landing this job?
Learn More
About Sovrn
Every interesting company solves essential problems for other people. Sovrn is a Software and Data business that helps Open Web businesses remain independent. We help them understand their business better, operate more efficiently, and make and keep more money.
- We believe in the freedom and free flow of information.
- We believe the Open Web is the largest source of this information.
- We believe in helping Open Web businesses remain Independent.
Through Software products and Data solutions, we help our customers:
- Understand their business better, so they can make better decisions.
- Operate their business more efficiently, so they can invest in what matters most.
- Make (and Keep) more money, so they control their own destiny.
About the Role
The Director of Legal & Privacy will lead Sovrn's legal function, including commercial contracting, privacy and data protection, intellectual property, dispute management, corporate governance support, and legal operations infrastructure. The role operates in an environment where AI tooling is central to how legal work gets done and where AI governance is increasingly central to what the legal function delivers to the business. The Director reports to the Chief Financial Officer and partners with the CFO on legal strategy, resourcing, and risk. The role works cross-functionally with sales, product, engineering, and finance, oversees Sovrn's outside privacy contractor, and manages relationships with external counsel.
What you’ll be doing:
- Draft, review, negotiate, and manage commercial agreements, including publisher, advertiser, vendor, partner, and platform contracts.
- Support sales and business development on a high-volume basis, balancing transaction speed with appropriate risk management.
- Develop and maintain contract templates, negotiation playbooks, and approval workflows.
- Advise internal stakeholders on contract terms, obligations, and business implications.
- Oversee the company's privacy program, including direct management of the outside privacy contractor's scope, deliverables, and work product.
- Maintain compliance with applicable privacy laws and frameworks, including GDPR, CCPA/CPRA, other U.S. state privacy laws, and adtech industry frameworks (IAB TCF, GPP, and related standards). Collaborate with Product leaders on new requirements to ensure compliance.
- Advise on data processing agreements, vendor diligence, sub-processor management, consent mechanisms, and transparency obligations.
- Implement and manage core legal infrastructure, including contract lifecycle management, document management, intake and triage, and reporting.
- Manage outside counsel engagements, scope, and spend.
- Own the procurement process for new and renewing spend.
- Manage the company's IP portfolio, including trademarks, patents, and trade secrets, in coordination with outside counsel.
- Support disputes, demand letters, pre-litigation matters, and handle insurance and litigation processes.
- Assist with corporate transactions, board materials, and governance documentation.
- Advise executives and functional leaders on legal, regulatory, and risk matters.
- Train the broader organization on legal processes, contract procedures, and privacy obligations.
- Software: Concord, Salesforce
A successful candidate will have:
- 10+ years of legal experience supporting technology companies, including substantive experience in adtech, martech, or digital media.
- 5+ years of in-house experience.
- 5+ years of commercial contract negotiation experience, including complex master agreements.
- Demonstrated knowledge of adtech privacy regulation, including GDPR, CCPA/CPRA, U.S. state privacy laws, and IAB frameworks.
- Working knowledge of AI governance frameworks (NIST AI RMF or ISO/IEC 42001) and emerging AI regulation, including the Colorado AI Act and EU AI Act.
- Experience drafting and negotiating AI-related contract terms, including provisions on training data, model licensing, output ownership, and AI-specific representations and indemnities.
- Hands-on experience using AI-enabled legal tools (e.g., AI-assisted contract review and drafting, AI-augmented contract lifecycle management, AI-powered legal research) and a track record of integrating them into legal workflows.
- Experience managing outside counsel and external legal or privacy contractors.
- Experience designing and implementing legal operations processes and tooling.
- Strong written and verbal communication skills, with the ability to advise senior executives and translate legal risk into business terms.
- Sound judgment and the ability to make decisions with incomplete information.
- Ability to manage multiple priorities and deadlines in a fast-paced environment with composure and consistency.
- J.D. from an accredited law school with active bar membership in good standing preferred.
- CIPP/E or CIPP/US certification preferred.
- AIGP (Artificial Intelligence Governance Professional) certification or equivalent preferred.
We understand that no candidate is perfectly qualified for any job. Experience comes in different forms, many skills are transferable, and passion goes a long way. Even more important than your resume is a clear demonstration of accountability and the ability to thrive in a fluid and collaborative environment. We expect you to learn new things in this role and encourage you to apply if your experience is close to what we're looking for.
Location: Boulder, CO. In-office for candidates residing within 20 miles of our Boulder office; hybrid for candidates residing outside that radius.
Application Deadline: Priority deadline July 1, 2026. Applications will be accepted on a rolling basis thereafter until the position is filled.
Compensation and Benefits: The base salary for this position is $165,000 to $200,000 annually. Actual base salary will depend on the candidate's education, experience, skills, and location. In addition to salary, the total compensation package includes bonus and equity. Sovrn offers a full slate of benefits from medical, dental, and vision coverage, short and long-term disability, life insurance, paid parental leave, 401(k) plan and match, 11 paid holidays, flexible vacation, and commuter benefits.
How to Apply: Submit your application through https://www.sovrn.com/careers/. If you require a reasonable accommodation to participate in any part of the application or interview process, please contact peopleops@sovrn.com.
Equal Opportunity Employer: Sovrn is proud to be an Equal Opportunity Employer and provides equal employment opportunities to all employees and applicants regardless of race, color, religion, gender, gender identity, age, national origin, disability, parental or pregnancy status, marriage and civil partnership, sexual orientation, veteran status, or any other characteristic protected by law. Reasonable accommodations will be made to meet the requirements of the Americans with Disabilities Act.
Recruitment Agencies: Sovrn does not accept agency resumes. Please do not forward resumes to our jobs alias or Sovrn employees. Sovrn is not responsible for any fees related to unsolicited resumes.
Sign Up for Weekly Job Alerts
Have the latest Privacy and AI governance job postings delievered to your inbox every week
Staff Software Engineer - AI Governance Integrations
OneTrust
AI Governance
Today
Atlanta, Georgia
Preferred Certifications
Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.
The Challenge
We’re looking for a Staff Software Engineer with a passion for solving problems to join our agile AI Governance team at OneTrust. Staff Software Engineers are responsible for developing, contributing to decisions related to design and architecture of new frontend and/or backend features while supporting existing development efforts for our industry-leading platform.
Your Mission
Development
- Support development of Java microservices/Libraries while integrating with various AI platforms for Onetrust’s AI Governance product. It will involve the designing, development, and unit testing of applications deployed to MS Azure with cloud application architecture using Core Java, REST, and the Spring ecosystem.
- Achieve at least 80% code coverage or per the revised standards set by the team.
Collaboration
- Work closely with UX, Product Managers and/or Product Owners, as well as other developers to contribute to planning and grooming sessions and drive team’s discussions on system architecture and component design.
- Support the team to ensure all committed stories for the sprint are completed per the sprint goal.
Support
- Work toward reducing total number of defects in the module/product to industry standards by catching and fixing issues early in development.
- Ensure critical and high priority CII’s are delivered per SLA.
Code Review
- Conduct peer reviews to improve code quality.
- Help junior developers follow development testing, exploratory testing, AI testing and/or test automation.
Lead
- Help build high-performing teams by mentoring the team on new technical skills.
Your Experience Includes
- Bachelor's or master's degree in computer science, Engineering, or related technical or business field.
- 8+ years of professional software engineering/development experience, or 5+ years with a Master’s Degree in relevant field
- Extensive hands-on experience and expertise in object-oriented design methodology and application development using Java/J2EE, Design Patterns, Spring MVC, SQL, Web services.
- Working experience with one or more AI platforms like Amazon SageMaker, Google Vertex, AWS Bedrock etc.
- Experience with elastic search and data streaming tools like Kafka.
- Good understanding of web services and SOA related standards like REST/OAuth/JSON.
- Moderate understanding of code and script (Python, Bash)
- Good experience with SQL and NoSQL databases
- Agile development (Scrum, XP, or Pair Programming) experience
- Ability to use a wide variety of open-source technologies and cloud services.
- Familiarity with public cloud providers such as (Azure, Google Cloud, or AWS)
Extra Awesome
- Familiarity with different databases (Relational and document) is a strong asset.
- Familiarity with continuous integration and continuous deployment (CI/CD) tools, such as Jenkins.
- Proficiency in Kubernetes, including cluster deployment, scaling, and management is highly desirable.
For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.
Where we Work
We are embracing an office-first culture, encouraging three days a week in office for most roles, with meaningful opportunities to collaborate and celebrate in person.
Each role may have specific requirements or flexibility depending on the scope of the position, so we encourage you to verify this with your recruiter during your first interview.
Benefits
As an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.
Resources
Check out the following to learn more about OneTrust and its people:
Your Data
You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview. You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.
Recruitment fraud warning: OneTrust is aware of scams involving false offers of employment with our company. The fraudulent jobs, interviews and job offers use fake websites, email addresses, group chat and text messages. Be aware that we never ask candidates for personal information, IDs or bank information during the interview process. We do not interview prospective candidates via instant message or group chat, and do not require candidates to purchase products or services, or process payments on our behalf as a condition of any employment offer. Please note that any legitimate interview availability requests will come directly from a OneTrust recruiter with an "@onetrust.com" email address. You may also receive legitimate emails from "@us.greenhouse-mail.io". Recruiters will only reach out to candidates who have applied for a role through our ATS (Greenhouse) or prospects via LinkedIn InMail. Job offers will come from a recruiter and may have a "@docusign.net" email address. For more information or if you have been targeted please reach out to askrecruiting@onetrust.com.
Our Commitment to You
When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new category. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.
OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.
Privacy Manager
Sezzle
Privacy
Today
Colombia, Remote
Preferred Certifications
CIPP/US
CIPP/C
CIPM
CIPT
This job is CIPP/US preferred. Want to improve your chance of landing this job?
Learn More
About Sezzle:
With a mission to financially empower the next generation, Sezzle is revolutionizing the shopping experience beyond payments, blending cutting-edge tech with seamless, interest-free installment plans that make shopping smarter and more accessible. We’re not just transforming payments; we’re redefining how people discover, interact with, and purchase the things they love while driving real impact on merchant sales through increased conversions and higher order values. As we continue to shape the future of fintech and retail, we’re building an innovative, dynamic team passionate about creating more than just a transaction but a truly unique shopping journey. If you’re excited about pushing boundaries in tech and delivering a game-changing experience for consumers and merchants alike, come join us at Sezzle and help create the future of shopping!
About the Role:
We are seeking a talented and motivated Privacy Manager who is best in class, with a high IQ plus a high EQ. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement.
Sezzle is building a formal, company-wide privacy program on the NIST Privacy Framework, and we are hiring the person who will build it and run it. This is a ground-floor build with the hard parts already cleared: executive sponsorship is in place, the implementation roadmap is defined, and the core program materials are drafted. Your job is to turn that foundation into an operating program, and then to own the program as it matures.
As our Privacy Manager, you will drive the implementation end to end: the enterprise data map, the privacy risk assessments, the privacy review process, the de-identification standard, and the governance rhythm that keeps it all running. This role sits at the intersection of privacy and product. The goal is not to slow the business down; it is to give every data initiative a fast, well-documented path to yes, including the data-driven products and analytics that are central to Sezzle’s strategy. You will ensure our data practices protect our users across the US and Canada while enabling our product and engineering teams to build at speed.
What You’ll Do:
- Build the program: Drive Sezzle’s implementation of the NIST Privacy Framework from roadmap to operating program, including Current and Target Profiles, gap analysis, a prioritized and costed action plan, and ongoing monitoring, aligned with US state and federal requirements (CCPA/CPRA and other state comprehensive privacy laws, GLBA, TCPA) and Canadian privacy laws (PIPEDA and Quebec’s Law 25).
- Run privacy review: Own privacy risk assessments and Privacy Impact Assessments (PIAs) for new products, features, and third-party vendors, and operate an intake and disposition process that gives every proposal a fast, documented answer: approved, approved with controls, or needs redesign.
- Own the data map and consumer rights: Build and maintain the enterprise data inventory and data map in partnership with Engineering, tracking the lifecycle of consumer information, and manage the automation and fulfillment of consumer access, deletion, and opt-out requests.
- Operationalize privacy-enhancing techniques: Administer Sezzle’s de-identification and aggregation standard and its approval workflow so that data-driven products and analytics ship with the right controls designed in from the start.
- Embed privacy-by-design: Partner directly with Engineering, Product, and Marketing teams during early-stage development so that privacy requirements are designed in, not bolted on.
- Govern, measure, and report: Run the cadence of Sezzle’s cross-functional privacy working group, maintain the program’s decision log and obligations register, track program metrics, and support executive and board-level reporting. Collaborate closely with the Information Security team to manage, investigate, and mitigate privacy incidents and cross-border data transfer risks.
What We Look For:
- Proven Builder: 4+ years of dedicated experience managing data privacy programs, including at least one program or major program component (a data inventory, a consumer rights operation, a privacy review process) that you stood up from early stage to steady state rather than inherited. High-growth fintech, e-commerce, or SaaS experience operating in both the US and Canada is ideal.
- Framework Fluency: Hands-on experience implementing a recognized privacy or security framework (NIST Privacy Framework strongly preferred; NIST CSF or ISO 27701 also relevant), including profiles or maturity assessments, gap analyses, and action plans.
- Deep Regulatory Knowledge: Strong working knowledge of major North American privacy frameworks (CCPA/CPRA and the broader US state privacy law landscape, TCPA, GLBA, PIPEDA, Quebec Law 25) and a sharp knack for translating complex legal mandates into clear, actionable business processes.
- Product-Enablement Mindset: You treat privacy as the path to yes. You are fluent in de-identification, aggregation, and other privacy-enhancing techniques as tools that let data products launch responsibly, and you can defend the line between what is de-identified and what is not.
- Cross-Functional Communication: High emotional intelligence (EQ) with the ability to influence technical and non-technical stakeholders alike, run a cross-functional working group, and present clearly to executives.
- Problem-Solving Ownership: A self-starter mindset with the ability to manage multiple high-stakes projects simultaneously in an environment where speed and agility matter.
Preferred Qualifications:
- CIPM (privacy program management) plus CIPP/US or CIPP/C; CIPT is a plus.
- Technical familiarity with modern privacy tech platforms (e.g., OneTrust, Securiti.ai, WireWheel) and data infrastructure analytics.
- Experience navigating financial regulations and compliance frameworks (e.g., GLBA, PCI-DSS) alongside traditional consumer privacy laws.
- Public-company experience, including supporting audit committee or board-level reporting.
About You:
- You have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixed.
- You’re not bound by convention - your success, and much of the fun, lies in developing new ways to do things.
- You need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-taking.
- You earn trust - you listen attentively, speak candidly, and treat others respectfully.
- You have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit wholly.
- You deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settle.
What Makes Working at Sezzle Awesome:
At Sezzle, we are more than just brilliant engineers, passionate data enthusiasts, out-of-the-box thinkers, and determined innovators. We believe in surrounding ourselves with only the best and the brightest individuals. Our culture is not defined by a certain set of perks designed to give the illusion of the traditional startup culture, but rather, it is the visible example living in every employee that we hire.
Compensation: The compensation range for the role is $4,500-$6,500 USD GROSS per month. Our ranges are very broad to accommodate all types of candidates and encourage growth. Specific compensation offered to a candidate may be dependent on factors such as education, experience, qualifications, and alignment with market data. Exceptional candidates may receive salaries outside of the posted ranges.
#Li-remote
Privacy Manager
Sezzle
Privacy
Today
Mexico, Remote
Preferred Certifications
CIPP/US
CIPP/C
CIPM
CIPT
This job is CIPP/US preferred. Want to improve your chance of landing this job?
Learn More
About Sezzle:
With a mission to financially empower the next generation, Sezzle is revolutionizing the shopping experience beyond payments, blending cutting-edge tech with seamless, interest-free installment plans that make shopping smarter and more accessible. We’re not just transforming payments; we’re redefining how people discover, interact with, and purchase the things they love while driving real impact on merchant sales through increased conversions and higher order values. As we continue to shape the future of fintech and retail, we’re building an innovative, dynamic team passionate about creating more than just a transaction but a truly unique shopping journey. If you’re excited about pushing boundaries in tech and delivering a game-changing experience for consumers and merchants alike, come join us at Sezzle and help create the future of shopping!
About the Role:
We are seeking a talented and motivated Privacy Manager who is best in class, with a high IQ plus a high EQ. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement.
Sezzle is building a formal, company-wide privacy program on the NIST Privacy Framework, and we are hiring the person who will build it and run it. This is a ground-floor build with the hard parts already cleared: executive sponsorship is in place, the implementation roadmap is defined, and the core program materials are drafted. Your job is to turn that foundation into an operating program, and then to own the program as it matures.
As our Privacy Manager, you will drive the implementation end to end: the enterprise data map, the privacy risk assessments, the privacy review process, the de-identification standard, and the governance rhythm that keeps it all running. This role sits at the intersection of privacy and product. The goal is not to slow the business down; it is to give every data initiative a fast, well-documented path to yes, including the data-driven products and analytics that are central to Sezzle’s strategy. You will ensure our data practices protect our users across the US and Canada while enabling our product and engineering teams to build at speed.
What You’ll Do:
- Build the program: Drive Sezzle’s implementation of the NIST Privacy Framework from roadmap to operating program, including Current and Target Profiles, gap analysis, a prioritized and costed action plan, and ongoing monitoring, aligned with US state and federal requirements (CCPA/CPRA and other state comprehensive privacy laws, GLBA, TCPA) and Canadian privacy laws (PIPEDA and Quebec’s Law 25).
- Run privacy review: Own privacy risk assessments and Privacy Impact Assessments (PIAs) for new products, features, and third-party vendors, and operate an intake and disposition process that gives every proposal a fast, documented answer: approved, approved with controls, or needs redesign.
- Own the data map and consumer rights: Build and maintain the enterprise data inventory and data map in partnership with Engineering, tracking the lifecycle of consumer information, and manage the automation and fulfillment of consumer access, deletion, and opt-out requests.
- Operationalize privacy-enhancing techniques: Administer Sezzle’s de-identification and aggregation standard and its approval workflow so that data-driven products and analytics ship with the right controls designed in from the start.
- Embed privacy-by-design: Partner directly with Engineering, Product, and Marketing teams during early-stage development so that privacy requirements are designed in, not bolted on.
- Govern, measure, and report: Run the cadence of Sezzle’s cross-functional privacy working group, maintain the program’s decision log and obligations register, track program metrics, and support executive and board-level reporting. Collaborate closely with the Information Security team to manage, investigate, and mitigate privacy incidents and cross-border data transfer risks.
What We Look For:
- Proven Builder: 4+ years of dedicated experience managing data privacy programs, including at least one program or major program component (a data inventory, a consumer rights operation, a privacy review process) that you stood up from early stage to steady state rather than inherited. High-growth fintech, e-commerce, or SaaS experience operating in both the US and Canada is ideal.
- Framework Fluency: Hands-on experience implementing a recognized privacy or security framework (NIST Privacy Framework strongly preferred; NIST CSF or ISO 27701 also relevant), including profiles or maturity assessments, gap analyses, and action plans.
- Deep Regulatory Knowledge: Strong working knowledge of major North American privacy frameworks (CCPA/CPRA and the broader US state privacy law landscape, TCPA, GLBA, PIPEDA, Quebec Law 25) and a sharp knack for translating complex legal mandates into clear, actionable business processes.
- Product-Enablement Mindset: You treat privacy as the path to yes. You are fluent in de-identification, aggregation, and other privacy-enhancing techniques as tools that let data products launch responsibly, and you can defend the line between what is de-identified and what is not.
- Cross-Functional Communication: High emotional intelligence (EQ) with the ability to influence technical and non-technical stakeholders alike, run a cross-functional working group, and present clearly to executives.
- Problem-Solving Ownership: A self-starter mindset with the ability to manage multiple high-stakes projects simultaneously in an environment where speed and agility matter.
Preferred Qualifications:
- CIPM (privacy program management) plus CIPP/US or CIPP/C; CIPT is a plus.
- Technical familiarity with modern privacy tech platforms (e.g., OneTrust, Securiti.ai, WireWheel) and data infrastructure analytics.
- Experience navigating financial regulations and compliance frameworks (e.g., GLBA, PCI-DSS) alongside traditional consumer privacy laws.
- Public-company experience, including supporting audit committee or board-level reporting.
About You:
- You have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixed.
- You’re not bound by convention - your success, and much of the fun, lies in developing new ways to do things.
- You need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-taking.
- You earn trust - you listen attentively, speak candidly, and treat others respectfully.
- You have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit wholly.
- You deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settle.
What Makes Working at Sezzle Awesome:
At Sezzle, we are more than just brilliant engineers, passionate data enthusiasts, out-of-the-box thinkers, and determined innovators. We believe in surrounding ourselves with only the best and the brightest individuals. Our culture is not defined by a certain set of perks designed to give the illusion of the traditional startup culture, but rather, it is the visible example living in every employee that we hire.
Compensation: The compensation range for the role is $4,500-$6,500 USD GROSS per month. Our ranges are very broad to accommodate all types of candidates and encourage growth. Specific compensation offered to a candidate may be dependent on factors such as education, experience, qualifications, and alignment with market data. Exceptional candidates may receive salaries outside of the posted ranges.
#Li-remote
Data Protection Officer - CTBC
Continental
Privacy
Today
Timișoara, TM, RO
Preferred Certifications
CIPP/E
CIPM
This job is CIPP/E preferred. Want to improve your chance of landing this job?
Learn More
Company Description
Continental is a leading tire manufacturer and industry specialist. Founded in 1871, the company generated sales of €19.7 billion in 2025 and currently employs around 78,000 people in 54 countries and markets.
ContiTech is one of the world’s leading material experts for industry applications. The Continental group sector offers its customers reliable, safe and convenient industry and service solutions using a range of materials for off-highway applications, on rails and roads, in the air, under and above the ground, in industrial environments, for the food sector and the furniture industry. With about 20,000 employees (Status as of March 2026) at more than 60 sites globally, and sales of some 6.0 billion euros (2025), the global industrial partner is active with core branches in Asia, Europe and North and South America.
Job Description
In your role as Data Protection Officer (m/f/divers), you will serve as the formally appointed DPO for ContiTech Thermopol Romania S.R.L. in accordance with GDPR Articles 37–39 and Romanian Law No. 190/2018. You will act as the central contact point for the Romanian supervisory authority (ANSPDCP), data subjects, and internal stakeholders on all matters relating to the processing and protection of personal data.
In addition to the statutory DPO mandate, you will fulfil the role of Compliance Coordinator, serving as the local liaison to the central Commercial and Data Compliance function of ContiTech. This combined position ensures both regulatory compliance and effective corporate governance.
In detail, you can expect the following tasks and responsibilities:
- Informing and advising the controller and its employees on their obligations under GDPR, Romanian Law No. 190/2018, and Binding Corporate Rules;
- Monitoring compliance with applicable data protection legislation and internal policies, including the Data Protection Manual;
- Serving as the primary contact point for ANSPDCP and handling all communications with the supervisory authority;
- Coordinating and advising on data protection impact assessments (DPIAs) for new or modified processing activities;
- Maintaining and updating the Records of Processing Activities (RoPA) in cooperation with business process owners;
- Managing the intake, verification, routing, and resolution of data subject requests (access, erasure, rectification, restriction);
- Leading the internal response to data protection incidents and breaches, including investigation, documentation, escalation, and — where required — notification to ANSPDCP and affected data subjects;
- Supporting central Data Compliance and Internal Audit in the planning and execution of audits and compliance reviews;
- Coordinating the local rollout and adoption of corporate compliance policies, procedures, and standards;
- Designing, organising, and delivering data protection training and awareness programmes for employees and management;
- Preparing regular compliance reports and KPIs for local leadership and central Data Compliance;
- Advising business owners on the data protection-compliant implementation of business transactions, projects, and vendor relationships, including cross-border data transfers;
- Monitoring changes in Romanian and EU data protection legislation and recommending necessary actions to management.
Qualifications
- Academic degree in law with demonstrated expertise in data protection law; additional qualification or certification in data protection (e.g. CIPP/E, CIPM, or equivalent) is a strong advantage;
- Minimum 3 years of professional experience in a compliance, legal, audit, or data protection function, with at least 2 years of hands-on experience applying the GDPR;
- Sound knowledge of Romanian data protection legislation, in particular Law No. 190/2018 and ANSPDCP regulatory practice;
- Experience in conducting or coordinating data protection impact assessments, managing records of processing activities, and handling data subject requests;
- Familiarity with data protection management systems, IT security principles, and information governance frameworks;
- Experience with forward-looking topics such as cyber security, cloud computing, big data, and artificial intelligence is desirable;
- Business fluent Romanian and English language skills (written and spoken); knowledge of German is an advantage;
- Strong communication and advisory skills, with the ability to interact effectively with stakeholders at all organisational levels, including senior leadership and regulatory authorities;
- High level of integrity and the ability to operate independently, as required by GDPR Article 38(3), free from instructions regarding the exercise of DPO tasks;
- Proactive, structured, and self-organised way of working, with the ability to manage multiple priorities and deadlines;
- Willingness to travel.
Applications from severely handicapped people are welcome.
Additional Information
What we offer:
- The 13-th salary – Paid once a year, in December;
- Meal tickets - With a value of 40 Ron;
- Hybrid schedule – Work-life balance is important, so we offer a flexible schedule. Please agree on this with your superior;
- Private Health Insurance – Health is the most important, so we offer you a medical subscription through Signal Iduna;
- Referral bonuses - We encourage colleagues to refer new candidates to us and, at the same time, to get the chance to receive a bonus;
- Bookster - Feed your body and your mind. You can borrow books and you’ll receive them at the office;
- Sports benefits - It’s important to stay active, so we offer you the
- 7Card;
- Discounts at our partners – We collaborate with different vendors, and we receive discounts for various products/ services like rubbers, restaurants, kindergartens, etc;
- System for Rewarding Improvement Ideas – We have an internal improvement program (Continental Idea Management) that gives you the opportunity to come up with ideas and to be honored with an attractive bonus (this is established by the CIM team according to your improvement idea);
- Happy days – If you or your child is getting married, or you become a parent, you receive some extra free days;
- Life events celebration - If your family is growing, we praise your newborn with a bonus;
- Unfortunate events - In case of unhappy events in your life, we support you by offering you free days and financial support (handled on a case-by-case basis);
- Extra vacation days – You begin with 22 vacation days/year, and starting with the 3rd year with us, we offer you 1 more day of vacation and, afterward from 2 to 2 years you’ll get one more extra day (the maximum you can achieve is 27);
- Professional development - Many opportunities to develop yourself within the company;
- Diversity and multicultural mindset - We encourage you to join us no matter who, where, or what you are. We have colleagues from different nations and a variety of languages are poken in our company.
Ready to drive with Continental? Take the first step and fill in the online application.
Full-Stack Engineer, Privacy
Wheely
Privacy
Today
Λευκωσία, Nicosia, Cyprus
Preferred Certifications
About Wheely
Wheely is redefining premium transportation across major cities in Europe, the US, and the Middle East. We blend cutting-edge technology with the craft of five-star chauffeuring to deliver an experience trusted by more than 100,000 active riders and 1,200 corporate accounts.
We’re a profitable, fast-growing scale-up with $43M raised and over $100M in annual revenue. Having recently launched in New York City, we’re expanding rapidly across the US and EMEA. If you take pride in your craft and want to help shape the next chapter of our growth, we'd love to hear from you.
A small core-engineering team devoted to protecting our clients' privacy at the highest level. We build privacy-first systems that keep users' location data inaccessible, even to us, and push that bar further with features no other ride-hailing service offers. Privacy is a core principle at Wheely and a key competitive advantage as we grow across Europe and the US. We're looking for a Full-Stack Engineer to help build it.
Responsibilities
- Work on privacy-focused systems and architecture that keep users' location data inaccessible — even to us.
- Work across the stack using React, TypeScript, and Node.js or Golang to deliver high-quality solutions.
- Collaborate closely with Product Managers, Designers, and Software Engineers to shape technical solutions from concept through production.
Requirements
- 3+ years of experience as a Full-Stack or Frontend Engineer with backend experience.
- Commercial experience with Node.js. Golang is nice to have.
- Strong frontend development experience with TypeScript, React, React Query, Redux or alternative state management libraries (e.g. MobX).
- Solid understanding of HTML, CSS, JavaScript, and modern browser APIs.
- Familiarity with modern frontend tooling (Vite/Webpack, ESLint, and package managers such as npm/pnpm).
- Experience with automated testing, such as end-to-end tests (Playwright, Selenium), UI/Component tests (e.g. using Jest), or snapshot tests.
- STEM (technical) degree.
Our current stack: Go microservices, shrinking Ruby monolith, Node.js, TypeScript, React, React Query, Vite, MongoDB, PostgreSQL, RabbitMQ, GRPC, Thrift, Redis, AWS, Terraform, K8S.
What we Offer
- Office-based role in Nicosia, four days a week with flexible start and finish times, plus one remote day of your choice
- Competitive salary
- Employee stock options plan
- Private medical and dental insurance
- Daily Lunch allowance
- Latest-generation MacBook Pro and 4k display
- Professional development stipend
- Relocation support, including visa sponsorship and allowance
All of your personal information will be collected stored and processed in accordance with Wheely’s Candidate Privacy Notice