Senior Manager, Privacy
JOB SUMMARY
The Senior Manager, Privacy plays a critical leadership role in establishing, implementing, and managing Step Up for Students' enterprise privacy program. This position is responsible for developing and maintaining privacy governance frameworks, policies, controls, and processes that support the protection of sensitive organizational, employee, and family data while ensuring compliance with applicable privacy laws, regulations, and industry standards. The Senior Manager, Privacy serves as the organization's subject matter expert (SME) for privacy risk management and collaborates closely with Information Technology, Information Security, Compliance, Legal, Internal Audit, Product, Operations, and business leaders to strengthen data protection practices and promote a culture of privacy awareness across the organization. This role is responsible for identifying and assessing privacy risks, monitoring compliance requirements, supporting investigations, overseeing privacy-related incidents, and implementing privacy controls that align with organizational objectives. The Senior Manager, Privacy will also support enterprise readiness initiatives, including privacy assessments, audit activities, risk evaluations, and SOC 2 readiness efforts. The ideal candidate will possess a strong understanding of privacy frameworks, data governance, regulatory compliance, information security concepts, and risk management principles, along with the ability to translate complex privacy requirements into practical and scalable business solutions.
KEY RESPONSIBILITIES
Developing Lead the development, implementation, and continuous enhancement of the organization's privacy program, governance framework, and supporting policies.
Serve as the organization's privacy subject matter expert and trusted advisor on privacy-related matters and regulatory requirements.
Develop and maintain privacy policies, standards, procedures, and controls that align with organizational objectives and compliance requirements.
Conduct privacy risk assessments and evaluate privacy implications associated with business operations, systems, products, and organizational initiatives.
Partner with Information Technology, Information Security, Compliance, Legal, and business stakeholders to ensure privacy requirements are embedded into operational processes and technology solutions.
Support the development and implementation of privacy monitoring, reporting, and incident management processes.
Lead investigations related to privacy concerns, data handling practices, and potential privacy incidents, ensuring appropriate documentation and resolution.
Develop recommendations to mitigate privacy risks and improve organizational privacy controls.
Establish privacy metrics, reporting mechanisms, and dashboards to provide leadership visibility into privacy program performance and risk exposure.
Support external audits, assessments, and regulatory reviews related to privacy, data governance, and information protection.
Assist in preparing the organization for SOC 2 and other compliance readiness initiatives where privacy controls are applicable.
Collaborate with Internal Audit, Risk Management, and Compliance teams to strengthen the organization's control environment.
Develop and deliver privacy awareness training and educational initiatives to support employees understanding of privacy obligations and best practices.
Monitor changes in privacy regulations, emerging risks, and industry trends to ensure ongoing organizational compliance.
Identify opportunities to improve privacy processes, governance, reporting, and risk management capabilities across the enterprise.
Support the evaluation and implementation of Governance, Risk, and Compliance (GRC) tools and privacy management technologies.
Partner with leadership to develop strategic privacy initiatives that support organizational growth and operational excellence.
EDUCATION & EXPERIENCE
REQUIRED
Bachelor's degree in Information Security, Information Systems, Cybersecurity, Business Administration, Risk Management, Legal Studies, Compliance, or a related field.
Equivalent professional experience may be considered in lieu of formal education.
Minimum of 8-10 years of progressive experience in privacy, compliance, risk management, information security, audit, governance, or related disciplines.
Proven experience designing, implementing, or managing enterprise privacy programs and privacy governance frameworks.
Experience conducting privacy risk assessments and developing privacy control strategies.
Strong knowledge of federal, state, and industry privacy and data protection laws, regulations, and standards, including experience interpreting and applying privacy requirements to organizational policies, controls, and business operations.
Experience supporting audits, assessments, and compliance reviews. Experience working cross-functionally with technology, legal, compliance, risk, and operational business partners.
PREFERRED
Experience supporting compliance with privacy regulations such as FERPA, HIPAA, CCPA, COPPA, PPRA, and other applicable privacy and data protection requirements.
Experience supporting data governance, cybersecurity, risk management, or compliance initiatives.
Experience supporting SOC 2 readiness initiatives and related compliance programs. Experience evaluating or implementing Governance, Risk, and Compliance (GRC) tools and privacy management technologies.
Professional certifications such as CIPP, CIPM, CIPT, CISSP, CRISC, or related certifications.
KEY COMPETENCIES
Deep knowledge of privacy governance, privacy frameworks, and applicable federal, state, and industry privacy regulations relevant to the organization's operations and data protection obligations.
Strong understanding of risk management, compliance, internal controls, and regulatory requirements.
Ability to assess complex privacy risks and develop practical risk mitigation strategies.
Strong analytical, problem-solving, and critical-thinking skills.
Ability to influence stakeholders and drive cross-functional collaboration.
Strong project management and organizational skills.
Ability to develop scalable processes, controls, and governance structures.
Excellent written and verbal communication skills, including executive-level reporting and presentations.
Ability to translate complex privacy and regulatory requirements into practical business solutions.
Experience developing metrics, dashboards, and reporting mechanisms to demonstrate program effectiveness.
Self-motivated and capable of managing multiple priorities in a fast-paced and evolving environment.
Strong attention to detail and commitment to maintaining confidentiality and data protection standards.
Ability to build and foster strong business partnerships throughout the organization.
CORE VALUES
Step Up For Students believes strongly in two key core values to carry out their mission of “We empower families to pursue and engage in the most appropriate learning options for their children.”:
Everyone is an asset.
Every event is an improvement opportunity.
To maintain a positive and effective organizational culture, employees are expected to demonstrate these two core values in their everyday work.
WORKING CONDITIONS/EQUIPMENT USE
Home Work is performed indoors in a typical office environment - not substantially exposed to adverse environmental conditions.
Must be able to lift up to fifteen (15) pounds.
Frequent use of office machines to include telephone, computer, and printer.