5+ years in privacy compliance or risk management with operational experience in privacy regulations.
Experience with regulatory impact assessments for privacy and AI laws.
Proficient in risk-based compliance monitoring methodologies and overseeing PIAs/DPIAs.
Skilled in maturing privacy governance through metrics and reporting to leadership.
Experience in privacy incident investigations and collaboration with legal teams.
Familiarity with GRC tooling is preferred.
CIPM, CIPP/E or equivalent IAPP certification is required.
Responsibilities
Own and maintain privacy controls in GRC systems and manage privacy rights requests.
Maintain an obligations library for legal, regulatory, and contractual privacy requirements.
Operate the privacy rights request process within statutory deadlines, ensuring compliance from intake to fulfillment.
Report on privacy posture and regulatory developments to security leadership monthly.
Benefits
Long-Term Incentive (LTI) Program.
Robust suite of employee benefits.
Full Job Description
Location: We prioritize hiring in or near the SF Bay Area, New York City and Dallas.
Responsibilities & opportunities in this role:
Own closure and ongoing maintenance of privacy controls in GRC system and privacy rights requests in Datagrail or similar tool.
Maintain the obligations library of legal, regulatory and contractual privacy obligations mapped to controls and owners, including incoming regulation and a written operational position per requirement. Legal determinations remain with Legal.
Operate the privacy rights request process (access, deletion, correction, objection) within statutory deadlines, from intake and identity verification through fulfilment and record keeping.
Report privacy posture and the regulatory horizon to security leadership monthly.
Ideal candidates have/are:
5+ years in privacy compliance or privacy risk management, including hands-on operationalisation of privacy regulations across business functions.
Experience conducting regulatory impact assessments for emerging privacy and AI or automated decision-making laws: applicability, business impact, implementation requirements and operational readiness.
Experience building and applying a risk-based compliance monitoring methodology, and overseeing PIAs and DPIAs for quality, data classification and supporting evidence.
Experience maturing privacy governance through metrics and reporting (KRIs, KCIs, KPIs) and presenting privacy risk posture to leadership.
Experience supporting privacy incident investigations and control testing; comfortable partnering with Legal and knowing which questions belong to them.
Experience with GRC tooling preferred.
CIPM, CIPP/E or equivalent IAPP certification.
Compensation
Groq is committed to providing competitive compensation through our Total Cash philosophy, which incorporates potential bonus value directly into base pay. The total cash salary range for this position, which is inclusive of the potential bonus value, is $154,900 - $208,700, with individual placement determined by your geographic location, experience, skills, and alignment with internal compensation standards. This range is specific to candidates located in the United States. Compensation for international candidates will vary based on local market dynamics. Beyond cash compensation, Groq also offers a Long-Term Incentive (LTI) Program and a robust suite of employee benefits.
About Groq
Groq is a semiconductor company that specializes in developing processing units for artificial intelligence and machine learning applications. The company was founded in 2016 by Jonathan Ross, Douglas Wightman, and Martin Snelgrove. Groq's processing units are designed to be faster and more efficient than traditional CPUs and GPUs. The company has received funding from several venture capital firms, including Social Capital and Wing Venture Capital. Groq is headquartered in Mountain View, California.