Amazon's Seller Privacy Program is seeking a Principal Risk Manager to lead centralized privacy strategy and compliance across Worldwide Selling Partner Services (SPS). In this role, you will serve as the single-threaded owner of Seller privacy compliance spanning hundreds of applications across 5+ VP organizations, driving long-term strategy and near-term execution to protect Sellers' data rights under GDPR, CCPA, and emerging global regulations.
You will operate at the intersection of regulatory risk, technical systems, and business priorities - defining the privacy roadmap, resolving organizational ambiguity, and influencing cross-VP decision-making without direct authority. This is a high-judgment, high-impact role where the business problem, solution, and risk strategy are often undefined, and you will be expected to create clarity, build mechanisms, and drive results at scale. You will write strategic documents for VP audiences, lead escalations up to VP level, and represent Sellers in Amazon-wide privacy decisions. If you thrive in ambiguity, can influence at the highest levels, and want to protect Sellers' data rights - we want to talk to you.
Key job responsibilities
- Own SPS Privacy strategy, priorities, mechanisms, and execution across all Seller data processing activities worldwide
- Drive compliance with GDPR, CCPA, and emerging privacy regulations across hundreds of SPS applications
- Influence 5+ VP organizations to prioritize privacy investments, navigating tension between Seller experience, legal requirements, and competing business priorities
- Resolve organizational ambiguity and ownership gaps requiring Director/VP alignment across multiple technical and business teams
- Lead strategic escalations to VP/SVP leadership with high-quality written documents informing risk exposure and compliance posture
- Define and own annual privacy goals, including
- Data Subject Access Requests (DSAR), Account Closure and Data Deletion (ACDDR), and automation coverage targets
- Partner with Amazon Privacy, Legal, and Privacy Bar Raisers to define obligations and influence tooling roadmaps
- Monitor emerging regulatory enforcement actions and proactively de-risk the business
- Make high-judgment trade-offs between compliance deadlines, business opportunity, and resource constraints in a historically under-invested domain
A day in the life
You might start your day checking goal progress across your privacy portfolio, then shift to authoring a VP-level status update on compliance posture. Mid-morning, you're drafting a cycle planning document that frames trade-offs between a compliance deadline and competing business goals, or writing an escalation document to unblock a critical dependency. After lunch, you're influencing cross-functional stakeholders - Engineering, Legal, Product - to achieve delivery commitments and keep priorities on track. By end of day, you're reporting progress to VP audiences, reviewing communications for accuracy and strategic framing, and identifying what needs to escalate versus what you can solve through your network. No two days are alike, and the problems are rarely pre-defined.
BASIC QUALIFICATIONS
- Bachelor's degree or equivalent in Risk Management, Business Administration, Security Management, or a related field
- 10+ years of risk management, audit, legal, compliance, operations, or a similar discipline experience
- Experience working cross-functionally with tech and non-tech teams
- Experience using data and metrics to back up assumptions and develop business cases
- Experience with cross functional project or program delivery
- 8+ years of communicating with and presenting to executive and senior audiences experience
- Experience in Privacy Law
- Experience communicating with customers, technical, regulatory, business teams, and management to collect requirements, describe product features, and technical designs
PREFERRED QUALIFICATIONS
- Experience with data privacy operations including Data Subject Access Requests (DSAR) and data deletion/retention frameworks
- CIPP/E, CIPP/US, CIPM, or other recognized privacy certification
- Experience with privacy-by-design principles and their application in large-scale technology environments
- Experience managing regulatory escalations involving Data Protection Authorities (e.g., ICO, EU DPAs)
- Familiarity with Amazon's development lifecycle and data management systems
The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at https://amazon.jobs/en/benefits.
USA, CA, San Diego - 144,200.00 - 195,000.00 USD annually
USA, WA, Seattle - 144,200.00 - 195,000.00 USD annually