Deepgram logo
Deepgram·

Privacy Operations Lead - Deepgram

Fully remoteFull-timeSeniorUTC-8–-4USA only#privacy#gdpr#complianceEquity

Company Overview

Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are 'Powered by Deepgram'. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software.

The Opportunity

Deepgram is looking for a Privacy Operations Lead to own the operational backbone of our privacy program. Deepgram processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out, single-tenant Deepgram Dedicated deployments, and fully self-hosted deployments.

You will be the person who knows, in operational detail, how data moves through each of those models and turns that knowledge into durable artifacts like data flow maps, records of processing, assessment templates, and playbooks. You will also be the technical voice in enterprise customer privacy reviews.

This role reports to the Director of Information Security and works closely with Legal, Engineering, and Solutions/Sales Engineering. This is a senior individual-contributor role.

Responsibilities

  • Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end.
  • Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments.
  • Translate GDPR, UK GDPR, CCPA/CPRA, and emerging AI regulation (EU AI Act) into concrete requirements for engineering and GTM teams.
  • Define privacy requirements for product and infrastructure changes — retention, logging, third-party subprocessors, training-data lineage.
  • Own the operating model for privacy controls: retention/deletion enforcement, DSAR workflows, consent/opt-out handling, and de-identification.
  • Design and run operational auditing and remediation workflows to prevent drift between claims and reality.
  • Own the subprocessor and vendor privacy review process.
  • Drive privacy enablement through playbooks, guidance, and training for Engineering, Support, and Sales Engineering.
  • Partner with Legal on DPAs, SCCs, transfer mechanisms, and residency commitments.
  • Partner with Security to align privacy evidence with compliance frameworks (SOC 2, ISO 27001).

Skills Needed

  • Substantial experience in privacy operations, legal operations, or technical privacy and compliance.
  • Demonstrated ownership of privacy operational systems at scale (data maps, DSAR workflows, consent management, retention processes).
  • Technically fluent: able to read architecture diagrams, follow data flows through datacenter and cloud infrastructure, and understand log lines.
  • Practical, applied experience with GDPR, CCPA/CPRA, and emerging AI regulations.
  • Strong written communication skills and ability to produce clear documents for customers, auditors, and engineers.
  • Strong bias toward automating and documenting work.
  • Comfortable with ambiguity and making defensible calls.

Nice to Have

  • CIPM, CIPT, CIPP/E, or equivalent certification.
  • Comfort reading code (Python, Go, Rust, TypeScript) or writing SQL/scripting.
  • Familiarity with on-premise, colocation, or containerized (Docker) infrastructure.
  • Experience with ML/AI data pipelines and training-data governance.
  • Privacy work in hybrid models (multi-tenant SaaS alongside self-hosted/on-prem deployments).
  • Exposure to formal audits (SOC 2, ISO 27001, HIPAA, PCI DSS).

Timezone overlap

UTC-8–-4

Benefits

Equity

Open to

US

Sign in to track applications and earn points.

More roles at Deepgram

Similar remote roles