SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Deepgram is the leading platform for Voice AI, providing real-time APIs for speech-to-text, text-to-speech, and voice agents at scale. The company has processed over 50,000 years of audio and serves 1,300+ organizations including Twilio, Cloudflare, and others.
You will own the written and evidentiary backbone of Deepgram's compliance program, covering both privacy and security compliance. This is a single seat deliberately combining both halves to leverage the underlying facts: the same data about how Deepgram handles audio answers a DPIA, a SOC 2 control, and a Fortune 500 questionnaire.
You will own privacy program operational work including customer and prospect privacy risk assessments, DPIAs, transfer impact assessments, data flow maps, retention and deletion enforcement, DSAR workflows, consent handling, and subprocessor reviews. You will translate GDPR, UK GDPR, CCPA/CPRA, and emerging AI regulation (EU AI Act, state AI rules) into concrete requirements for engineering and GTM teams.
You will own audit evidence end-to-end for SOC 2, ISO 27001, and PCI DSS, including what evidence is required, who produces it, and whether it satisfies reviewers. You will build control mappings across frameworks so one control and one piece of evidence satisfies multiple standards and customer questionnaires. You will own security questionnaires, RFP security sections, and maintain answer libraries.
You will author and own the lifecycle of internal policies and standards, own public-facing posture documents (Trust Center, AI Safety statement, Model Cards, Privacy Policy, deployment documentation), and own the documentation system itself—versioning, review, and traceability. You will design operational auditing workflows to catch drift between claims and reality, and run compliance and privacy training.
Context matters: Deepgram processes sensitive audio across hosted (with/without model-improvement), single-tenant dedicated deployments with regional residency, and fully self-hosted deployments. Your statements must be precise about which deployment model they apply to.
Writing is the core skill. You will produce documents that survive skeptical readers—auditors, enterprise security reviewers, customer DPOs, engineers. Where claims need technical verification, you define what must be proven and partner with Security Engineering; you are not expected to do the engineering work yourself.
This role reports to the Director of Information Security and works closely with Security Engineering, Legal, Research, and Solutions/Sales Engineering. Deepgram operates at the pace of AI with an AI-first mindset; change is rapid and you should expect your day-to-day work to evolve quickly.
REQUIREMENTS:
- Substantial experience in privacy operations, GRC, security compliance, or technical compliance documentation—enough to have carried assessments or an audit cycle end-to-end and owned the outcome.
- Exceptional writer. This is the central requirement, not a soft skill. Ability to turn messy technical reality into documents a skeptical auditor, customer, or engineer will accept.
- Demonstrated ownership of compliance operational systems at scale: data maps, DSAR workflows, evidence collection, answer libraries, policy sets, or tooling behind them.
- Hands-on involvement in at least one formal audit (SOC 2, ISO 27001, or PCI DSS) as the person producing and defending evidence, not only as a reader of the report.
- Practical, applied experience with GDPR and CCPA/CPRA, and current view of where AI regulation is heading.
- Technical fluency: ability to read architecture diagrams, follow data flows through cloud infrastructure, understand log lines and retention settings, and ask questions that expose gaps—without needing translation.
- Ability to hold your own with Fortune 500 privacy teams, security reviewers, or DPOs without escalating every question.
- Startup-friendly judgment: knowing which questionnaire answers are worth fighting for and which to concede, and when a policy needs a carve-out rather than a mandate.
- Bias toward building systems and templates rather than becoming the bottleneck for every request.
- Comfortable with ambiguity and making defensible calls when law or standards are unsettled.
NICE TO HAVE:
- Certifications such as CIPM, CIPT, CIPP/E, CISA, or ISO 27001 Lead Implementer/Auditor.
- Experience with compliance automation platforms (Vanta, Drata, or similar) and trust center tooling.
- Familiarity with AI governance frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act) and model documentation practice.
- Experience with ML/AI data pipelines and training-data governance.
- Compliance work in hybrid models (multi-tenant SaaS alongside self-hosted or on-premise deployments).
- Comfort with SQL, light scripting, or AI and agentic tooling to pull and assemble evidence rather than filing tickets.
- Exposure to HIPAA or FedRAMP.