Position Summary:Trulioo is seeking a commercially minded and execution-oriented Senior Director, Global Privacy & Data Protection to lead our global privacy strategy, data protection program, and designated Data Protection Officer.
Reporting to the Chief Risk and Strategy Officer, this role will actively lead how privacy, data protection, AI governance, and responsible data use are embedded across Trulioo's products, operations, commercial motions, and governed by leading practices. This is a senior leadership role for a privacy executive who can operate in scaling, agile environments and partnering with Product, Engineering, Legal, Security, Enterprise Risk, Sales, Marketing, and Customer Success.
The ideal candidate brings extensive expertise in GDPR, U.S. state privacy laws, and Canadian privacy laws, with experience in emerging areas including, but not limited to, biometrics, AI, age verification, data retention, data classification, and emerging identity technologies.
This will be a full-time, permanent position working on a hybrid model from one of our North American offices or fully remote.
What You'll Be Doing:Global Privacy Strategy & DPO- Build and lead Trulioo's global privacy and data protection strategy across priority markets, products, customers, and operating environments.
- Serve as Trulioo's designated Data Protection Officer for Europe, providing independent, credible, and commercially practical advice on GDPR and related obligations.
- Advise executive leadership, as needed, on privacy risk, regulatory change, customer expectations, and strategic trade-offs tied to product innovation and market expansion.
- Represent Trulioo in privacy-related engagements with regulators, enterprise customers, industry groups, and other external stakeholders.
- Act as a strategic advisor on privacy and data protection implications as Trulioo expands into new operating regions, verticals, and expands the product catalog.
- Monitor global privacy developments and translate implications into practical guidance for products, operations, market expansion, and customer commitments.
Privacy Program Operations & Governance- Mature Trulioo's privacy program, including PIAs, DPIAs, records of processing, data subject rights, vendor privacy reviews, and cross-border transfer mechanisms. Integrate privacy by design into product development, commercial contracting, customer onboarding, third-party management, enterprise risk management, and agile operating rhythms.
- Own and evolve key privacy and data governance policies, including data retention, data classification, information classification and protection, data handling, and responsible data use.
- Lead privacy incident readiness and response, including investigation support, breach assessment, regulatory notification analysis, remediation, and post-incident improvement.
- Develop practical reporting, metrics, and executive-level insights that create visibility into privacy risks, regulatory readiness, and program maturity.
Commercial Enablement, Product, & Engineering Advisor- Partner with Product and Engineering to embed privacy by design into agile product development, architecture decisions, data flows, and release processes.
- Provide guidance on privacy risks tied to identity verification, fraud prevention, biometrics, document verification, data enrichment, AI, machine learning, and emerging identity technologies.
- Serve as a senior privacy advisor to Sales, Customer Success, Marketing, Solutions, and Legal in support of enterprise due diligence, RFPs, audits, and strategic customer engagements.
- Help shape responsible AI governance, including privacy impact analysis, consumer data use, automated processing, transparency, and controls for responsible product deployment.
- Lead or support negotiation of DPAs, SCCs, data transfer terms, privacy schedules, customer commitments, vendor terms, and partner arrangements.
- Support commercialization by validating privacy positioning, customer-facing claims, contractual commitments, and market- specific privacy requirements.
- Build privacy thought leadership that strengthens Trulioo's credibility with customers, regulators, partners, and industry stakeholders.
Team Leadership & Cross-Functional Influence- Lead, coach, and develop a high-performing privacy team with strong judgment, business orientation, and operational discipline.
- Create clear decision-making frameworks that allow teams to move quickly while managing privacy and data protection risk effectively.
- Foster a culture of responsible innovation, practical risk management, and accountable data use across the organization.
What You'll Bring:- 15+ years of experience in privacy, data protection, technology law, regulatory advisory, or related legal and risk leadership roles, including significant in-house experience.
- Extensive expertise in GDPR, European data protection expectations, U.S. state privacy laws, and Canadian privacy laws.
- Demonstrated ability to serve as a senior privacy leader or Data Protection Officer in a complex, global technology environment.
- Experience advising Product, Engineering, Security, Legal, and go-to-market teams on privacy by design, data protection risk, product launches, and customer-facing commitments.
- Practical experience with PIAs, DPIAs, data mapping, transfer mechanisms, DPAs, SCCs, vendor risk, data subject rights, retention, and privacy incident response.
- Strong understanding of privacy issues tied to emerging identity technology and use cases including biometrics, identity, AI, behavior analysis, automated processing, fraud prevention, and device intelligence.
- Track record building or maturing privacy program operations in agile, high-growth, regulated, or enterprise SaaS environments.
- Executive presence, sound judgment, and the ability to translate regulatory complexity into clear business decisions.
- Strong people leadership skills, with the ability to build capability, set direction, and raise the operating maturity of a privacy function.
- Law degree or equivalent legal/privacy qualification; membership in good standing with a relevant law society or bar is strongly preferred.
Nice to Have:- Experience in RegTech, FinTech, identity verification, fraud prevention, payments, financial services, or enterprise SaaS.
- Working knowledge of privacy and data protection frameworks in Asia-Pacific, India, China, and Latin America.
- Experience supporting AI governance, responsible AI programs, model governance, or data ethics frameworks.
- Familiarity with information security, data governance, cybersecurity, enterprise risk, or public-company readiness programs.
- Privacy certifications such as CIPP/E, CIPP/US, CIPP/C, CIPM, CIPT, or equivalent credentials.
- Experience speaking externally, publishing privacy insights, or representing a company in industry forums.
Interview Process:At Trulioo, we strive to create an interview experience that is transparent, engaging, and respectful of your time. Our process is designed to help us learn more about your skills and experience while giving you insight into our team, culture, and the impact of the work we do.
Here's what you can expect throughout the interview process:
- Recruiter Interview: 30 minutes
- Hiring Manager Interview: 45 minutes
- Panel Interview: 60 minutes
- Chief People Officer Interview: 45 minutes
- Final Executive Interview: 30 minutes