About the roleWe're looking for a Privacy Program Engineer to own the technical core of our privacy program. We've achieved ISO 27001, ISO 27701, ISO 42001, and SOC 2 Type II, and we run active GDPR and CCPA/CPRA programs - now we need someone to run the machinery that keeps all of it working, and to make that machinery largely run itself.
This is a privacy role with real technical depth - you'll write scripts, queries, and automation. From day one you'll own real workstreams: data subject requests, the data inventory and ROPA, hands-on privacy reviews for new vendors and features.. You'll report to our Privacy Lead and be a key owner of large portions of our privacy program, as well as the key technical expert on the privacy team.
This is not a ticket queue with a title. We're a small team at a company that builds AI infrastructure, and we intend to leverage it - you'll own the direction and design of the technical systems, automations, and tools that help us meet our privacy obligations at Fireworks.
Who this role is for- You build systems, not queues. You've used AI tooling, automation, scripting, or workflow platforms to eliminate manual privacy work.
- You're technical enough to be dangerous. You read code to understand what a service actually does with data. You can query a database without asking for help. You've automated something real with code, a workflow engine, or an LLM-based agent and you know how to build scalable tools running against production systems and data.
- You take a project and run with it. Given a rough problem and a deadline, you come back with it done. You're not afraid to make tactical decisions and judgement calls.
- You take extreme ownership. You're comfortable owning something outright and figuring it out - your workstreams are yours. You surface problems early, fix them, and make sure they don't recur.
What you'll do- Build the privacy automation layer: scripts, scheduled jobs, API integrations, and LLM-based agents that handle request routing, evidence collection, assessment intake, and control monitoring.
- Own the data subject rights (DSR) program and the system behind it: build the intake, identity verification, fan-out across data stores, and fulfillment tracking as an automated pipeline rather than a checklist, with the audit trail generated as a byproduct.
- Build and maintain a data inventory and ROPA that derives from the environment rather than from interviews: pull from cloud APIs, warehouse metadata, IaC, and service catalogs so the map updates when the systems do, and reconcile drift.
- Embed privacy into how we build: review designs and PRs for data handling, advise on de-identification, pseudonymization, tokenization, field-level encryption, and access scoping, and give engineers a concrete pattern to use rather than a policy to read.
- Own retention and deletion as an engineering problem: translate retention requirements into concrete rules per data store, work with engineering on enforcement in pipelines and backups, and build the verification that proves deletion actually happened.
- Support consent management and preference handling across our web properties and product surfaces.
- Solve AI data problems directly: trace how customer data moves through training, fine-tuning, inference, and logging; validate zero-retention and isolation claims against what the platform actually does; and build the checks that keep those claims true as the platform changes.
- Take on additional privacy projects as the program evolves; we're a growing team with dynamic priorities.
How the role will grow- Process ownership - move from operating established processes to owning entire workstreams end to end.
- Automation ownership - take the lead on privacy tooling and agent design as the program's automation surface grows.
- Advisory depth - advise product and engineering teams directly on technical privacy-by-design decisions.
- Growing influence - represent privacy in cross-functional projects, be the go-to technical privacy SME, and help shape where the program goes next.
What we're looking for- 4-7 years of experience in privacy, GRC, IT audit, information security, or a closely related field, with meaningful hands-on privacy work.
- Working knowledge of GDPR and CCPA/CPRA, and familiarity with ISO 27701, ISO 27001, ISO 42001, SOC 2, and NIST.
- Hands-on experience with technical privacy operations: data subject requests, ROPA or data inventory maintenance, privacy impact assessments, or retention enforcement.
- Evidence that you automate your own work - AI tooling, scripts, workflow builders, or aggressive use of a privacy/GRC platform's automation features. Tell us what you built and what it replaced.
- Working proficiency in SQL and at least one scripting language - enough to query a warehouse, call an API, parse a schema, and automate a recurring task without help.
- Hands-on familiarity with cloud environments (AWS, GCP, or Azure): IAM and access scoping, logging, data stores and their retention behavior, and how to find where data actually lives and how it's used.
- Strong written communication; you can translate privacy requirements into language engineers, customers, and non-technical employees understand.
Nice to have- Built something with an LLM API or agent framework that other people relied on.
- Experience with de-identification or synthetic data techniques.
- Exposure to data lineage or catalog tooling (dbt, DataHub, Atlan, Monte Carlo, OpenMetadata).
- Worked on a privacy or security problem at an AI/ML company specifically - model data flows, inference logging, training data provenance.
- Startup or fast-growing SaaS background.