Strategic Risk Program Manager, Privacy

MetaNew York City, New YorkOn-siteFull-timeStaff, 8–12 yearsListed 2 days ago

Apply now

About this role

Meta is seeking a Strategic Risk Program Manager to lead privacy risk governance and program strategy across the company's global product and infrastructure portfolio. In this role, you will define and operationalize frameworks for identifying, assessing, and mitigating privacy risks at scale, partnering with legal, policy, engineering, and product teams to embed risk management practices into how Meta builds and ships products. You will drive cross-functional alignment on privacy risk posture, influence executive decision-making, and shape the long-term direction of Meta's privacy risk programs in a complex and rapidly evolving regulatory environment.

Responsibilities

Define and own the strategic framework for privacy risk identification, assessment, prioritization, and mitigation across Meta's product and infrastructure landscape
Lead cross-functional programs that translate privacy regulatory requirements and internal policy commitments into scalable operational processes
Partner with legal, policy, engineering, and product teams to embed privacy risk controls into product development lifecycles and launch processes
Develop and maintain privacy risk reporting mechanisms, including executive-level dashboards and governance committee materials that communicate risk posture and program health
Drive alignment across organizational boundaries on privacy risk decisions, escalation paths, and accountability structures
Identify systemic gaps in privacy risk coverage and design programs to close them, including tooling, process, and policy improvements
Represent privacy risk program strategy in cross-functional forums, regulatory engagement preparation, and senior leadership reviews
Establish metrics and key performance indicators to measure the effectiveness of privacy risk programs and drive continuous improvement
Mentor other program managers on privacy risk methodology, governance best practices, and cross-functional program execution
Anticipate emerging privacy risks from new product areas, technologies, and regulatory developments and proactively shape program responses

Qualifications

8+ years of experience in privacy program management, risk management, or compliance program management within a technology company or regulated industry
Experience designing and operationalizing risk governance frameworks, including risk assessment methodologies, control libraries, and escalation structures
Experience driving cross-functional programs with full accountability across legal, policy, engineering, and product stakeholders in ambiguous and complex environments
Experience communicating privacy risk strategy and program status to executive audiences through written materials, briefings, and governance forums
Experience translating privacy regulatory requirements (such as GDPR, CCPA, or equivalent frameworks) into operational program requirements and controls Familiarity with privacy engineering concepts such as data minimization, purpose limitation, privacy by design, and data flow mapping
Experience working within a privacy accountability or consent order compliance program at a large-scale technology company
Recognized privacy certification such as CIPP, CIPM, or CIPT
Experience building or scaling privacy risk tooling, intake processes, or risk register systems across a large organization
Experience adhering to and implementing responsible, ethical AI practices (e.g., risk assessment, bias mitigation, quality and accuracy reviews)
Demonstrated ongoing AI skill development (e.g., prompt/context engineering, agent orchestration) and staying current with emerging AI technologies
Demonstrated ability to integrate AI tools to optimize/redesign workflows and drive measurable impact (e.g., efficiency gains, quality improvements)