SlipstreamJobsFresh Startup & VC-Backed Jobs

Privacy Operations Lead

Deepgram - Remote - Remote - posted 2026-10-01

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Deepgram is the leading platform for Voice AI, providing real-time APIs for speech-to-text, text-to-speech, and voice agents at scale. The company processes sensitive audio data across multiple deployment models: hosted with optional model improvement, zero-retention hosted, single-tenant dedicated deployments with regional data residency, and fully self-hosted deployments. Infrastructure spans bare-metal datacenters and AWS overflow capacity. You will own the operational backbone of Deepgram's privacy program, serving as the technical expert who understands in operational detail how data moves through each deployment model. Your core responsibility is translating that knowledge into durable, repeatable artifacts: data flow maps, records of processing, assessment templates, playbooks, and self-service guidance that Legal, Engineering, and Sales Engineering can use independently. Key responsibilities include: - Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end; be the technical voice in customer privacy reviews and vendor due diligence. - Build and maintain accurate data flow maps and records of processing across all deployment models, tracking which datacenter, region, or cloud each flow touches, and own the process keeping them current as the product evolves. - Translate GDPR, UK GDPR, CCPA/CPRA, and emerging AI regulation (EU AI Act, state AI rules) into concrete, actionable requirements for engineering and go-to-market teams. - Define privacy requirements for product and infrastructure changes—retention, logging, telemetry, third-party subprocessors, training-data lineage—and drive implementation with owning teams. - Own the operating model for privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction. You specify and audit; Engineering builds. - Design and run operational auditing and remediation workflows to catch drift between claims and reality through process rather than customer discovery. - Own the subprocessor and vendor privacy review process, including colocation and infrastructure providers, and maintain artifacts supporting DPAs and the trust center. - Create privacy enablement materials: playbooks, self-service guidance, and training for Engineering, Support, and Sales Engineering, including scope boundaries. - Partner with Legal on DPAs, SCCs, transfer mechanisms, and residency commitments for dedicated deployments. - Partner with Security to produce privacy and security evidence (SOC 2, ISO 27001, PCI DSS) once and reuse across programs. This is a senior individual-contributor role. The company is open on level and will calibrate title, scope, and compensation to demonstrated experience. The role reports to the Director of Information Security and works closely with Legal, Engineering, and Solutions/Sales Engineering. Deepgram operates with an AI-first mindset. All team members are expected to actively use and experiment with advanced AI tools, integrate them into daily workflows, and continuously push boundaries. The pace is rapid, and day-to-day work evolves quickly. This role requires comfort with experimentation, adaptation, quick thinking, and continuous learning. REQUIREMENTS: - Substantial experience in privacy operations, legal operations, or technical privacy and compliance, with demonstrated end-to-end assessment ownership and accountability for outcomes. - Proven ownership of privacy operational systems at scale: data maps, DSAR workflows, consent management, retention processes, or underlying tooling. - Technical fluency and confidence: ability to read architecture diagrams, follow data flows through datacenter and cloud infrastructure, understand log lines and retention settings, and identify gaps without requiring translation. - Practical, applied experience with GDPR and CCPA/CPRA, with current knowledge of AI regulation trends. - Ability to engage confidently with Fortune 500 privacy teams and DPOs without escalating routine questions. - Strong written communication skills; a significant portion of this role involves producing documents relied upon by customers, auditors, and engineers. - Strong bias toward automating and documenting work rather than becoming a bottleneck. - Comfort with ambiguity and ability to make defensible decisions when legal frameworks are unsettled. NICE TO HAVE: - CIPM, CIPT, CIPP/E, or equivalent privacy certification. - Comfort reading code (Python, Go, Rust, TypeScript), writing SQL, or scripting tooling. - Familiarity with on-premise or colocation infrastructure, containerized (Docker) workloads, and data residency outside single cloud providers; AWS experience a plus. - Experience with ML/AI data pipelines and training-data governance. - Privacy work in hybrid models combining multi-tenant SaaS with self-hosted or on-premise deployments. - Exposure to formal audits: SOC 2, ISO 27001, HIPAA, PCI DSS.

Similar roles