The all-in-one sales & marketing platform that agencies can white-label. CRM, Email, 2-way SMS, Funnel Builder, & more!
Sr. Privacy Program Specialist
Location
United States
Posted
65 days ago
Salary
$109K - $137K / year
Seniority
Senior
Job Description
Sr. Privacy Program Specialist
HighLevel
About Us HighLevel is an AI powered, all-in-one white-label sales & marketing platform that empowers agencies, entrepreneurs, and businesses to elevate their digital presence and drive growth. We are proud to support a global and growing community of over 2 million businesses, comprised of agencies, consultants, and businesses of all sizes and industries. HighLevel empowers users with all the tools needed to capture, nurture, and close new leads into repeat customers. As of mid 2025, HighLevel processes over 4 billion API hits and handles more than 2.5 billion message events every day. Our platform manages over 470 terabytes of data distributed across five databases, operates with a network of over 250 microservices, and supports over 1 million hostnames. Our People With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment. We are building more than software; we are building a global community rooted in creativity, collaboration, and impact. We take pride in cultivating a culture where innovation thrives, ideas are celebrated, and people come first, no matter where they call home. Our Impact As of mid 2025, our platform powers over 1.5 billion messages, helps generate over 200 million leads, and facilitates over 20 million conversations for the more than 1 million businesses we serve each month. Behind those numbers are real people growing their companies, connecting with customers, and making their mark - and we get to help make that happen. About the role: HighLevel is an all-in-one sales and marketing platform serving over 60,000 customers across 140 countries. We help marketing agencies, entrepreneurs, and small businesses capture leads, nurture customer relationships, and close deals. As we scale, we need a Sr. Privacy Program Specialist to run and continuously improve our privacy compliance operations. You will take ownership of our existing privacy program: managing data subject rights requests, conducting privacy assessments, coordinating DPA reviews, overseeing our consent management platform, and keeping tracking technologies in check. When new privacy regulations emerge, you'll assess what HighLevel needs to do and work with the legal team to make it happen. The right candidate is operationally minded, detail-oriented, and always looking for ways to make processes more efficient. You should be comfortable managing multiple workstreams, coordinating across teams, and building systems that scale without constant oversight. What You’ll Be Doing: Privacy Program Operations - Own the day-to-day operation of HighLevel's privacy program, ensuring compliance processes run smoothly and efficiently - Manage and optimize our consent management platform, ensuring it accurately reflects HighLevel's data practices and regulatory requirements - Build and maintain privacy program documentation, including records of processing activities, data inventories, and compliance evidence - Monitor for new privacy regulations and assess their impact on HighLevel, working with legal counsel to determine necessary changes - Track regulatory deadlines, certification renewals, and compliance milestones Data Subject Rights Requests - Own the end-to-end data subject rights request (DSR) process, from intake through fulfillment and response - Build and refine DSR workflows to improve response times, reduce manual effort, and ensure consistent handling - Coordinate with engineering and product teams to fulfill complex requests requiring technical data retrieval - Maintain DSR metrics and reporting to demonstrate compliance and identify process improvements Privacy Assessments - Own the operational workflow for Data Protection Impact Assessments (DPIAs) and Privacy Impact Assessments (PIAs), creating and managing the end-to-end process from intake through completion. - Develop and maintain assessment templates, intake processes, and taking systems that enable assessments to scale without bottlenecks. - Work with product and engineering teams to gather necessary information and document privacy considerations - Track assessment findings and ensure remediation items are addressed DPA Management & Vendor Privacy - Coordinate DPA reviews with commercial counsel, managing the intake, tracking, and completion of data processing agreements - Maintain DPA templates and clause libraries, flagging deviations for legal review - Support vendor privacy assessments, ensuring third parties meet HighLevel's data protection requirements - Track DPA obligations and renewal dates Marketing & Tracking Compliance - Own the operational process for managing tracking technologies, pixels, and cookies deployed across HighLevel properties, building workflows that give the legal team visibility without creating bottlenecks for marketing - Work with the marketing team to establish a process for identifying and flagging new tracking technologies as they’re added to the consent management platform - Ensure tracking implementations align with consent requirements and privacy disclosures - Coordinate cookie banner updates and consent preference changes with relevant teams - Monitor for unauthorized tracking deployments and coordinate remediation - Continuously improve tracking compliance processes, identifying opportunities for automation and clear handoffs between teams What You’ll Bring: - Bachelor's degree - 5 years of experience in privacy program operations, with hands-on responsibility for DSRs, privacy assessments, or DPA management - Experience with consent management platforms (OneTrust, TrustArc, Transcend, or similar) - Understanding of GDPR, CCPA/CPRA, and other major privacy regulations, sufficient to operationalize legal requirements - Familiarity with tracking technologies, cookies, and tag management from a compliance perspective - Strong project management skills and attention to detail with the ability to manage multiple concurrent workstreams - Hands-on experience using AI tools to build automations or streamline compliance workflows and scale operations - Strong written communication skills for documentation, reporting, and cross-functional coordination Preferred Qualifications: - CIPP/US, CIPP/E, or CIPM certification - Experience at a SaaS, marketing technology, or B2B platform company - Familiarity with HIPAA privacy requirements - Experience building or improving privacy program automation - Exposure to privacy engineering concepts or technical privacy implementations - Experience at a public company or company preparing for IPO What We’re Looking For (The Intangibles): - Process optimizer. You see a manual workflow and immediately start thinking about how to automate it. You measure success by how much time you've saved, not by how many tasks you've completed. - Reliable operator. DSRs have deadlines. Assessments have to get done before launch. You deliver consistently, on time, without needing to be chased. People trust that if it's on your plate, it's handled. - Regulatory translator. You can read a new privacy law and figure out what it means operationally. You understand compliance well enough to build the first draft of the response plan. - Detail-oriented without losing the forest. You catch the errors in a data inventory, but you also know which errors matter and which ones don't. You prioritize based on risk, not just completeness. - Cross-functional navigator. You'll work with marketing, engineering, product, and commercial legal constantly. You build relationships quickly, communicate clearly, and get what you need without creating friction. - Self-sufficient. You don't need hand-holding. When you encounter something new, you research it, figure out the answer, and move forward. You escalate to legal when you should, but you handle everything you can on your own. - Curious about privacy. You stay current on privacy developments because you're genuinely interested, not just because it's your job. You bring new ideas for improving the program. - AI Fluent. You don't just know about AI tools, you actively experiment with them and find ways to incorporate them into your daily work. When faced with a repetitive task, your first instinct is to see if AI can handle it or make it faster. You embrace new AI capabilities rather than being skeptical, and you're always looking for the next tool that could streamline privacy operations Success Metrics: - DSRs are fulfilled within regulatory deadlines with consistent, documented processes - DPIAs and PIAs are completed before product launches, with findings addressed and tracked - DPA review coordination is efficient, with commercial counsel receiving well-organized intake and timely follow-up - Consent management platform accurately reflects HighLevel's data practices and is updated promptly when practices change - Marketing team has clear visibility into tracking compliance requirements, with unauthorized deployments identified and remediated quickly - Privacy program processes become measurably more efficient over time, with reduced manual effort and faster turnaround - New privacy regulations are assessed promptly, with clear operational plans developed before deadlines - Privacy documentation and records are audit-ready at all times This role is ideal for a privacy professional who gets satisfaction from running efficient compliance operations and wants to own a program rather than just execute tasks. The salary range for this position is $109000 - $137500 annually. Equal Employment Opportunity Information The company is an Equal Opportunity Employer. As an employer subject to affirmative action regulations, we invite you to voluntarily provide the following demographic information. This information is used solely for compliance with government record keeping, reporting, and other legal requirements. Providing this information is voluntary and refusal to do so will not affect your application status. This data will be kept separate from your application and will not be used in the hiring decision. #LI-Remote #LI-TA1
Related Guides
Related Categories
Related Job Pages
More Compliance Jobs
• Responsible for providing regulatory strategic support for global regulatory activities for innovative biologics • Serve as regulatory CMC representative on development and marketed product teams • Manage interactions with Health Authorities for assigned project(s) • Coordinate preparation and review technical reports and CMC sections of global submissions • Ensure compliance with regulatory requirements and strategies • Maintain knowledge of global competitive landscape and regulatory environment
Practice Lead – GRC Assurance
SprintoSprinto helps SaaS companies become info-sec compliant, unblock sales deals, and pass security reviews easily
• Build the function - Create delivery operating model: intake, scoping, SOWs, QA, SLAs, change control, and reporting. - Build reusable IP: templates, playbooks, mapping libraries, workshop agendas, and QA rubrics. - Hire and lead a team of specialists; build service-line pods over time. • Deliver and scale service lines (phased) - Phase 1: framework digitisation & control/check mapping inside Sprinto. - Phase 2: packaged services for risk assessment, privacy (DPIA), policy review, internal audits, and audit readiness support. - Phase 3: scale into security assurance programs and partner-led offerings (e.g., VAPT program management, vendor governance, QA, and customer outcomes). • Own commercial outcomes - Define service packaging and pricing models (fixed-fee tiers, retainer options where relevant). - Own utilization, margins, capacity planning, delivery forecasting, and predictable throughput. - Partner with Sales/SE/CS to attach services appropriately and improve enterprise deal conversion + retention. • AI-enabled service productisation - Create “AI-assisted playbooks” for repeatable services (DPIA, risk assessment, policy review, internal audit checklists). - Build structured input forms/checklists that juniors can fill out, enabling consistent output. - Define QA guardrails (mandatory source inputs, validation steps, human approval gates). - Maintain an internal library of prompts/templates and continuously improve them based on audit/customer feedback. • Ensure quality and manage risk - Establish acceptance criteria and review mechanisms for deliverables. - Define boundaries and disclaimers to avoid uncontrolled liability. - Build partner qualification standards and a QA framework for third-party-delivered services.
CMMC Compliance Lead
AeroVironmentAeroVironment is a global leader in intelligent, multi-domain robotic systems.
• Serve as AV’s subject matter expert on CMMC 2.0 requirements, assessment objectives, scoping rules, and evidence expectations. • Lead detailed gap analyses across technical, administrative, and physical controls to identify deficiencies and required remediation. • Translate CMMC practices into clear, actionable technical requirements for IT, Engineering, Security, Facilities, HR, and other impacted teams. • Guide and validate the implementation of required controls, ensuring alignment with CMMC and NIST SP 800‑171 assessment criteria. • Support CUI scoping activities including asset inventory validation, boundary definition, and data flow mapping. • Support the development, implementation, and maintenance of cybersecurity compliance programs aligned with CMMC, SOX, UKCE, ITAR, EAR, and other regulatory requirements. • Maintain compliance with external regulations and internal policies, ensuring consistent application across all in‑scope systems and processes. • Develop and implement compliance policies, procedures, and standards for cybersecurity, and assist other functional organizations in developing their own. • Coordinate with IT Infrastructure, Enterprise Systems, Legal, Risk Management, and other departments to ensure compliance requirements are understood and executed. • Lead the creation, refinement, and maintenance of compliance documentation including SSPs, POA&Ms, ConMon materials, policies, procedures, and evidence artifacts. • Establish structured evidence collection and artifact management processes to ensure audit readiness. • Perform internal readiness assessments, mock audits, and control testing to prepare AV for C3PAO evaluation. • Oversee compliance audits and assessments, ensuring timely remediation and accurate reporting. • Collaborate with external advisors, consultants, and assessors to support readiness and certification activities. • Conduct risk assessments and provide recommendations to mitigate cybersecurity and compliance risks. • Assess and report progress toward compliance objectives, including readiness status and control maturity. • Advise leadership on compliance risks, technical challenges, and factors that may impact certification timelines or sustainment. • Generate reports for senior cybersecurity leadership and contribute to executive‑level updates. • Provide guidance and training to employees on cybersecurity compliance matters, including role‑based CMMC responsibilities. • Develop awareness materials and communication strategies to support compliance adoption across the organization. • Represent the cybersecurity function in meetings, planning sessions, and cross‑functional initiatives.
Virtual Special Education Teacher
ACCEL SchoolsWe open, turnaround, and manage K-12 public charter schools.
About the Team The Virtual Preparatory Academy of Oklahoma is a K-12 tuition-free online public school in the state of Oklahoma. At VPA Oklahoma, we empower students to be their best by enabling them to learn in ways that are right for them – using innovative technology at home, at their proper level, and at their own pace. We are seeking teachers who are excited to create a rigorous and nurturing classroom environment that prioritizes student learning and social-emotional development. ACCEL Schools uses a cutting-edge 21st-century curriculum, which can be accessed online and through a variety of traditional methods. Please note – while this is an online school position and all instruction occurs virtually, travel and face to face attendance will be required several times per year to support in person state testing and student events. The Virtual Special Education Teacher supports the educational and behavioral goals of all students with a focus on students with an Individualized Education Program. Eligibility: Open to residents of Oklahoma About the Opportunity - Assist with the implementation of the Individualized Education Plan (IEP) for each student served - Write IEPs in a timely manner - Participate in the Multi-Tiered System of Supports (MTSS) - Maintain all student records and files according to federal, state and local mandates. - Complete all necessary paperwork within timelines to be compliant, - Complete progress reports as required - Complete all components of all paperwork - Work 1:1, in small groups or in whole class sessions with students - Administer Transition Assessments - Write lessons plans to accommodate goals in the student’s IEP - Teach all subjects following the school’s course of study or as assigned - Schedule and participate in IEP and other meetings for students with disabilities - Prepare and administer all standardized tests, benchmark assessments and evaluation assessments as directed - Work with the teaching staff to improve standardized and proficiency testing results - Maintain confidentiality concerning all student information and any professional matters - Keep accurate records on each student such as grade books and progress reports, lesson plans, attendance records, and behavior/discipline records - Collaborate with parents, teachers, psychologists, parents, Administrator, and professionals outside of school - Work with Related Services to keep evaluations current, updated every three years - Provide resources for classroom teachers for areas of disability - Attend, participate in and/or chaperone school activities such as faculty meetings (before or after school hours), open houses, commencement exercises, student activities - Attend professional developments as assigned - Other duties as assigned About You - Masters’ Degree Preferred - Required three years of teaching experience, at least 2 of which are in special education - Current Oklahoma certification/licensure in appropriate area - Strong content knowledge in one or more content areas - Familiarity with state proficiency testing state teaching standards - Understanding of and/or willingness to learn the MTSS process - Prior experience working with a diverse student body - Excellent written and verbal communication skills that reflect professionalism and tact at all times - Genuine care for children and a passion for teaching - Proficiency in computer applications, including Google Docs, MS Office Suite, e-mail, and internet applications - Prior experience with software and databases used to maintain Individuals with Disabilities Education Act (IDEA) compliance including Power School Special Programs - Ability to learn new technologies and acquire new skills through independent study, professional training, and from more senior team members - Strong ability to gather, analyze, and interpret student data to make sound educational decisions - Ability to handle confidential information responsibly and exhibit sound judgment while maintaining that confidentiality - Ability to and willingness to work occasional evenings - Valid driver’s license and ability to perform occasional local and in-state travel - Ability to pass federal, state and local background checks - Knowledge of co-teaching models and the ability to co-teach About Us “We believe that every child should be able to be anything they want in life, regardless of their birthplace and circumstances.” – Ron Packard, CEO & Founder ACCEL Schools is a network of 80+ high-performing, public charter schools serving PK-12 students. We proudly advocate for school choice and work to address educational inequities throughout the United States. Our schools are inclusive and widely differ to reflect the unique values of the many urban, suburban, and rural communities we serve. Our brick-and-mortar, virtual, and hybrid schools specialize in closing educational gaps and offer innovative models such as career-technical education, sports training, bilingual programming, and more. We have been recognized and praised by legislators, authorizers, and researchers for providing exceptional education options to students in historically under-resourced communities. We offer the following benefits: Life benefits – time & peace of mind - Paid time off - Retirement contributions - Optional Basic Life and AD&D insurance - Voluntary life insurance (employee, spouse, child) - Discounted childcare at Early Learning Academies locations Health benefits – stay well & thrive - Medical, dental, and vision insurance - Employee Assistance Program - Voluntary short-term disability insurance - Voluntary long-term disability insurance Career benefits – keep growing - Career advancement opportunities throughout Pansophic Learning and our strong network of 4,000+ instructors and education professionals EQUAL EMPLOYMENT OPPORTUNITY It is our policy to abide by all federal, state and local laws prohibiting employment discrimination based solely on a person’s race, color, religious creed, sex, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental and/or intellectual disability, age, military status, veteran status (including protected veterans), marital status, registered domestic partner or civil union status, familial status, gender (including sex stereotyping and gender identity or expression), medical condition, genetic information, sexual orientation, or any other protected status except where a reasonable, bona fide occupational qualification exists. #LI-AB1




