Support oversight of the existing Privacy compliance program across jurisdictions, with primary focus on U.S. requirements and alignment to global privacy obligations.
Translate Legal guidance and regulatory requirements into policies, standards, and control expectations for first-line teams.
Provide independent oversight and effective challenge of first-line privacy control environments, including review of control design and identification of gaps.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. They are a remote-first company with competitive benefits including health care coverage, flexible spending wallets, and stock purchase plans.
Coordinates and administers privacy and compliance programs to ensure adherence to regulatory requirements.
Partners with internal teams to interpret requirements, implement compliant solutions, and monitor activities.
Develops policies, tracks corrective actions, and supports audits to maintain program effectiveness.
Capital Blue Cross is a health insurance company that improves the health and well-being of members and communities. It is an independent licensee of the Blue Cross Blue Shield Association and has been voted a 'Best Place to Work in PA' by employees.
Manage multi-jurisdictional compliance execution including HIPAA, GDPR, PIPEDA, and emerging privacy laws.
Lead IT operations and service delivery including user onboarding, device management, and identity & access management.
Drive vendor risk management and BAA/DPA lifecycle, ensuring breach notification timelines and data deletion commitments.
Practice Better is an all-in-one platform helping health and wellness practitioners run their businesses and scale their impact. We are a remote-first team headquartered in Toronto, made up of curious, driven, and empathetic people, trusted by thousands of practitioners worldwide.
Own end-to-end management of core privacy programs including data subject requests, privacy impact assessments, and cookie compliance.
Identify and implement process improvements, leveraging AI to automate routine tasks and maintain auditable records.
Serve as a key connector between Privacy Legal, Privacy Engineering, and cross-functional partners to translate global privacy requirements into operations.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. The company is large and mission-driven, with a culture focused on increasing the GDP of the internet.
Manage Omada’s HIPAA privacy program, including policy development, incident investigations, and breach response.
Drive privacy-by-design across digital products, embedding privacy into development and clinical operations.
Provide expert guidance on consumer privacy compliance, AI governance, and interoperability frameworks.
Omada Health is reverse engineering the way healthcare is delivered in America, putting the space between doctor visits at the center of care. They have served more than two million members since launch across 2,000+ employers, health plans, and health systems, and have been certified as a Great Place to Work.
Lead Trulioo's global privacy strategy and data protection program as the designated Data Protection Officer for Europe.
Embed privacy by design into product development, commercial contracting, and enterprise risk management.
Partner with Product, Engineering, Legal, and go-to-market teams to drive responsible AI governance and data use.
Trulioo is a global leader in digital identity verification, enabling organizations to quickly onboard customers, optimize costs, and combat fraud. With over 5 billion people and 700 million business entities verified across 195 countries, the company is a BC Top Employer fostering an inclusive, collaborative, and people-first culture with offices in Vancouver, San Diego, and Dublin.
Manage the Compliance and Security workstream within a telecom transformation program, coordinating SOC 2, ISO/IEC 27001, and GDPR readiness activities.
Build and maintain the workstream plan with milestones, deliverables, and RAID logs, while driving evidence collection and control-owner alignment.
Facilitate workshops, track remediation across multiple domains, and ensure alignment with adjacent program streams and governance forums.
Miratech helps visionaries change the world as a global IT services and consulting company supporting digital transformation for large enterprises. With nearly 1000 professionals operating across 25+ countries and a 99% project success rate, their culture emphasizes relentless performance and growth.
Coordinate compliance and accountability systems across MAP's global medicine access operations, maintaining review processes and documentation.
Track corrective actions, monitor operational metrics, and support organizational readiness for audits and external assessments.
Collaborate cross-functionally with Programs, Finance, HR, and other teams to strengthen consistency and transparency in compliance processes.
MAP International is a global health nonprofit that provides essential medicines and health supplies to those in need. The organization operates with a distributed team across multiple functions, emphasizing a culture of compliance, accountability, and operational integrity.
Manage export compliance operations including restricted party screening and sanctions checks to ensure adherence to U.S. EAR and OFAC regulations.
Support global privacy operations by maintaining data processing agreements, SCCs, and privacy documentation.
Coordinate compliance evidence for customer diligence, audits, and certifications like SOC 2 and ISO 27001.
Horizon3.ai is a fast-growing cybersecurity company that helps organizations proactively find and fix exploitable attack vectors with its NodeZero platform. It is a remote team of former special operations cyber operators and startup engineers committed to a culture of respect, collaboration, ownership, and results.
Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.
Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.
Serve as a subject matter expert on Canadian consumer protection and payment regulations, providing advisory support to Product, Legal, Risk, and Operations teams.
Oversee Canadian regulatory reporting, lead compliance risk assessments, and evaluate control effectiveness to ensure program alignment.
Maintain and enhance Canada-specific policies, procedures, and control documentation while partnering cross-functionally on remediation efforts.
Affirm is reinventing credit to make it more honest and friendly, offering consumers the flexibility to buy now and pay later without hidden fees or compounding interest. We are a global fintech company with a remote-first culture, dedicated to delivering honest financial products.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Serve as a primary compliance resource embedded in the Alma-to-Spring Health integration, mapping control environments and building a unified compliance organization.
Own and lead enterprise-level compliance programs including SOC 2 Type II, HITRUST, HIPAA, GDPR, ISO 27001, ISO 42001, and ITGC-SOX.
Develop and operationalize Spring Health's AI governance program, including policies, risk frameworks, and AI-specific compliance documentation.
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. With outcomes independently validated by JAMA Network Open, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.
Leads a high-impact engineering pillar for compliance and risk systems, translating regulatory obligations into scalable solutions.
Oversees delivery of compliance automation, AI solutions, and risk controls while managing team growth and health.
Partners with Legal, Cyber, and Compliance stakeholders to drive technical roadmaps and ensure regulatory adherence.
NBCUniversal is a leading media and entertainment company, creating and distributing content across film, television, streaming, and theme parks. As a subsidiary of Comcast, it operates globally with a large workforce and champions an inclusive culture.
Draft, review, and negotiate a high volume of commercial agreements including client MSAs, SOWs, NDAs, vendor agreements, and DPAs.
Own legal operations across the group, including employment documentation, corporate compliance, and privacy programs.
Serve as the primary legal point person, partnering with sales, HR, and finance to support a growing business.
Red Antler Group is a connected ecosystem of creative companies that help ambitious brands grow, from emerging ventures to global leaders. The group includes Red Antler, Fat Earth, and WildFruit, working together to turn creativity into lasting impact for businesses at every stage.
Conduct hands-on compliance audits of digital platforms against global privacy regulations such as GDPR, CCPA, and COPPA.
Design and execute independent audit methodologies to test user protections, content moderation, and data handling practices.
Present detailed findings and strategic recommendations to clients and their leadership through executive briefings.
Coalfire solves clients' hardest cybersecurity challenges through advisory, assessment, and automation. They are a team of passionate problem-solvers with offices across the US and UK.
Own and manage the compliance program including SOC 2 and ISO 27001 readiness and audits.
Lead risk assessments, control testing, and enterprise risk management processes.
Partner with Engineering, Security, Product, Legal, HR, and Operations to embed compliance into business processes.
Calendly is a scheduling platform used by millions to automate meetings and streamline time management. They are a rapidly growing SaaS company fostering a culture of learning and high performance.
Support compliance work plan execution and joint venture administration across multiple practice areas.
Conduct legal research and draft summaries, memoranda, and legal documents for attorney review.
Coordinate litigation support, regulatory filings, and internal knowledge management activities.
Nakupuna Companies provides professional services to government and commercial clients, with a focus on native Hawaiian values and community. The company is a mid-sized organization that emphasizes collaboration, integrity, and employee development.
Act as a central coordination point for vendor, client, insurance, and security compliance, ensuring data accuracy and regulatory alignment.
Manage onboarding workflows, including vendor submissions, client data collection, and system updates in SharePoint and internal platforms.
Prepare insurance certificates, clearance docs, and support the Security Clearances team with compliance documentation.
Jobgether is a platform that uses AI-powered matching to connect candidates with hiring companies. The partner company is a dynamic consulting environment with a collaborative, process-driven culture, where you'll work across finance, safety, IT, and risk functions.
Advise internal business teams on compliance with privacy laws and regulations, including CCPA, HIPAA, and GDPR.
Draft, review, and negotiate privacy-related agreements and data processing addenda.
Develop and implement privacy policies, conduct impact assessments, and guide incident response.
EVERSANA provides commercialization services to the life sciences industry, helping bring innovative therapies to market. With over 7,000 employees, they serve more than 650 clients and are certified as a Great Place to Work globally.