Privacy & Security Program Manager
About Nanit:
Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the world's most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their baby's sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.
About the Role:
We're seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanit's privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customers' data and keep Nanit ahead of an evolving regulatory landscape. You'll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.
What You'll Be Doing:
- Develop, maintain and implement Nanit's privacy and security policies, standards and processes to ensure compliance with applicable laws, regulations and industry frameworks (e.g., CCPA/CPRA and other U.S. state privacy laws, GDPR, COPPA, and relevant security frameworks such as SOC 2, ISO 27001).
- Conduct and support regular privacy and security risk assessments, audits and gap analyses across systems, vendors, products and business processes, and drive remediation of identified gaps.
- Collaborate with stakeholders across the organization to assess AI-related privacy, security and compliance risks.
- Manage the third-party/vendor risk management program, including privacy and security due diligence, contract review support, ongoing monitoring, and enforcement of Nanit's data protection requirements.
- Partner with Product and Engineering teams to embed privacy-by-design and security-by-design principles into new features and products, including data mapping, privacy impact assessments (PIAs/DPIAs), and secure development practices.
- Monitor emerging privacy and security regulatory developments and industry standards, and advise the Chief Legal & Administrative Officer and Chief Technology Officer and other business stakeholders on impact and required action.
- Lead the company's response to security and privacy inquiries from customers, partners and regulators, including questionnaires, audits and due diligence requests.
- Support incident response efforts for privacy and security incidents, including investigation, documentation, remediation tracking and stakeholder communication.
- Develop and deliver privacy and security metrics, dashboards and reporting for senior management and, as needed, the board of directors.
- Design and deliver company-wide training and awareness programs on privacy, data security and compliance best practices.
- Act as a thoughtful business partner who supports a fast-moving culture, flexible teamwork, and pragmatic, scalable solutions that support growth while protecting the company.
Who You Are:
- Bachelor's degree in a related field; relevant certifications (e.g., CIPP, CIPM, CISSP, CIPT, CISM) preferred.
- 3-5+ years of experience in privacy program management, information security, or a related compliance function, ideally spanning both in-house and cross-functional environments.
- Hands-on experience supporting or operating privacy and/or security programs aligned to frameworks such as SOC 2, ISO 27001/27701, NIST CSF, or similar.
- Working knowledge of consumer privacy laws (e.g., CCPA/CPRA, GDPR, COPPA) and a willingness to build deeper subject-matter expertise over time.
- Practical experience with, or exposure to, security incident response, vendor risk management, and identity/access management concepts across on-premise and cloud environments.
- Able to rapidly interpret relevant laws, regulations and technical requirements, and translate them into practical, actionable and business-friendly guidance.
- Excellent stakeholder management, communication and collaboration skills; able to explain complex privacy/security concepts to both technical and non-technical audiences.
- Strong organizational skills, a problem-solving mindset, attention to detail, and the ability to exercise sound judgment in ambiguous environments.
- Strong technical orientation with an understanding of modern cloud architectures and data flows, and the ability to leverage emerging technologies and AI-powered tools to strengthen privacy, security and compliance programs.
Why You'll Love Working Here:
- Hybrid in office schedule
- Remote work from home month in August
- Flexible PTO (we trust you to take the time you need)
- Equity options so you can share in our growth
- Paid parental leave for all new parents
- Employee discounts on Nanit products
- Work from home stipend
- Monthly team events
EEO, Salary and Location:
This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.
Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanit's total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, we'll consider your location, experience, and other job-related factors.
We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.
Skills
As published by greenhouse · 8 questions · 2 written answers
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (6)
- Preferred First Name optional
- LinkedIn Profile optional
- Do you now or in the future require Nanit to sponsor you to work in the United States, Canada, or the United Kingdom?
- What is your desired pay?
- Which city/state are you located in?
- Were you referred for the role by an existing Nanit employee? If yes, please add name(s). optional
Written answers (2)
- Do you have 3-5+ years of experience in privacy program management, information security, or a related compliance function?
- Why are you interested in Nanit?