Program Manager, Privacy Risk Assessment

MetaMenlo Park, CaliforniaOn-siteFull-timeStaff, 8–12 yearsListed 1 week ago

Apply now

About this role

Meta's Privacy Risk Assessment team plays a critical role in evaluating privacy risks across a wide range of initiatives, including product launches, partnerships, data integrations, and corporate transactions. In this role, you will lead privacy risk assessments across diverse workstreams, identifying data protection risks, evaluating privacy posture, and partnering with Legal, Policy, Engineering, and cross-functional teams to drive risk mitigation strategies. You will operate with a high degree of independence, exercising judgment across complex, time-sensitive initiatives where privacy risk intersects with regulatory compliance, product development, and business strategy.

Responsibilities

Lead end-to-end privacy risk assessments across product launches, partnerships, data integrations, and corporate transactions, evaluating data practices, consent frameworks, data retention policies, and regulatory compliance posture
Identify, document, and communicate privacy risks associated with proposed initiatives, including risks related to data transfers, third-party sharing, sensitive data categories, and cross-border data flows
Develop and maintain structured privacy risk assessment frameworks and playbooks tailored to different initiative types and risk profiles
Partner with Legal, Policy, Engineering, and Product teams to ensure that privacy risk findings are integrated into decision-making, product design, and implementation planning
Advise cross-functional partners on complex privacy matters, translating regulatory requirements and privacy principles into actionable guidance
Track and manage privacy risk remediation commitments across active initiatives, ensuring timely follow-through and appropriate documentation
Contribute to team-level goals by helping to define short, mid, and long-term priorities for the privacy risk assessment program
Engage leaders and cross-functional stakeholders to build alignment on privacy risk findings and support informed decision-making
Help Meta meet its legal and regulatory obligations by ensuring that initiatives are evaluated against applicable data protection laws, including GDPR, CCPA, and other global privacy frameworks

Qualifications

6+ years of experience in privacy program management, privacy compliance, risk management, or a related field with direct exposure to data protection or regulatory compliance
Experience conducting privacy risk assessments, compliance reviews, or due diligence across product launches, partnerships, or corporate transactions
Experience analyzing data practices, data flows, and privacy controls across complex technical environments and translating findings into structured risk assessments
Experience working cross-functionally with Legal, Engineering, and Policy stakeholders to drive risk mitigation and decision-making in ambiguous, time-sensitive contexts
Familiarity with global privacy regulations and frameworks, including GDPR, CCPA, or equivalent data protection laws
Bachelor's Degree or equivalent experience Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Experience managing privacy risk assessments at a technology company, law firm, or consulting firm across diverse initiative types
Experience using AI tools or automation to improve risk assessment workflows, documentation quality, or operational efficiency
Familiarity with privacy-by-design principles and experience evaluating privacy controls in consumer-facing technology products or platforms
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Relevant privacy certifications such as CIPP, CIPM, or CIPT
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)