Privacy Manager
- Role
- Security
- Experience
- Mid
Open to CO only. Set where you work from to check your eligibility.
No BS summary
Privacy program manager with 4+ years building data privacy programs, ideally in high-growth fintech, e-commerce, or SaaS across the US and Canada. Needs hands-on privacy/security framework implementation and strong North American privacy regulatory knowledge. Colombia remote role.
Core skills
Required skills
Optional skills
About Sezzle:
With a mission to financially empower the next generation, Sezzle is revolutionizing the shopping experience beyond payments, blending cutting-edge tech with seamless, interest-free installment plans that make shopping smarter and more accessible. We’re not just transforming payments; we’re redefining how people discover, interact with, and purchase the things they love while driving real impact on merchant sales through increased conversions and higher order values. As we continue to shape the future of fintech and retail, we’re building an innovative, dynamic team passionate about creating more than just a transaction but a truly unique shopping journey. If you’re excited about pushing boundaries in tech and delivering a game-changing experience for consumers and merchants alike, come join us at Sezzle and help create the future of shopping!
About the Role:
We are seeking a talented and motivated Privacy Manager who is best in class, with a high IQ plus a high EQ. This role presents an exciting opportunity to thrive in a dynamic, fast-paced environment within a rapidly growing team, with abundant prospects for career advancement.
Sezzle is building a formal, company-wide privacy program on the NIST Privacy Framework, and we are hiring the person who will build it and run it. This is a ground-floor build with the hard parts already cleared: executive sponsorship is in place, the implementation roadmap is defined, and the core program materials are drafted. Your job is to turn that foundation into an operating program, and then to own the program as it matures.
As our Privacy Manager, you will drive the implementation end to end: the enterprise data map, the privacy risk assessments, the privacy review process, the de-identification standard, and the governance rhythm that keeps it all running. This role sits at the intersection of privacy and product. The goal is not to slow the business down; it is to give every data initiative a fast, well-documented path to yes, including the data-driven products and analytics that are central to Sezzle’s strategy. You will ensure our data practices protect our users across the US and Canada while enabling our product and engineering teams to build at speed.
What You’ll Do:
- Build the program: Drive Sezzle’s implementation of the NIST Privacy Framework from roadmap to operating program, including Current and Target Profiles, gap analysis, a prioritized and costed action plan, and ongoing monitoring, aligned with US state and federal requirements (CCPA/CPRA and other state comprehensive privacy laws, GLBA, TCPA) and Canadian privacy laws (PIPEDA and Quebec’s Law 25).
- Run privacy review: Own privacy risk assessments and Privacy Impact Assessments (PIAs) for new products, features, and third-party vendors, and operate an intake and disposition process that gives every proposal a fast, documented answer: approved, approved with controls, or needs redesign.
- Own the data map and consumer rights: Build and maintain the enterprise data inventory and data map in partnership with Engineering, tracking the lifecycle of consumer information, and manage the automation and fulfillment of consumer access, deletion, and opt-out requests.
- Operationalize privacy-enhancing techniques: Administer Sezzle’s de-identification and aggregation standard and its approval workflow so that data-driven products and analytics ship with the right controls designed in from the start.
- Embed privacy-by-design: Partner directly with Engineering, Product, and Marketing teams during early-stage development so that privacy requirements are designed in, not bolted on.
- Govern, measure, and report: Run the cadence of Sezzle’s cross-functional privacy working group, maintain the program’s decision log and obligations register, track program metrics, and support executive and board-level reporting. Collaborate closely with the Information Security team to manage, investigate, and mitigate privacy incidents and cross-border data transfer risks.
What We Look For:
- Proven Builder: 4+ years of dedicated experience managing data privacy programs, including at least one program or major program component (a data inventory, a consumer rights operation, a privacy review process) that you stood up from early stage to steady state rather than inherited. High-growth fintech, e-commerce, or SaaS experience operating in both the US and Canada is ideal.
- Framework Fluency: Hands-on experience implementing a recognized privacy or security framework (NIST Privacy Framework strongly preferred; NIST CSF or ISO 27701 also relevant), including profiles or maturity assessments, gap analyses, and action plans.
- Deep Regulatory Knowledge: Strong working knowledge of major North American privacy frameworks (CCPA/CPRA and the broader US state privacy law landscape, TCPA, GLBA, PIPEDA, Quebec Law 25) and a sharp knack for translating complex legal mandates into clear, actionable business processes.
- Product-Enablement Mindset: You treat privacy as the path to yes. You are fluent in de-identification, aggregation, and other privacy-enhancing techniques as tools that let data products launch responsibly, and you can defend the line between what is de-identified and what is not.
- Cross-Functional Communication: High emotional intelligence (EQ) with the ability to influence technical and non-technical stakeholders alike, run a cross-functional working group, and present clearly to executives.
- Problem-Solving Ownership: A self-starter mindset with the ability to manage multiple high-stakes projects simultaneously in an environment where speed and agility matter.
Preferred Qualifications:
- CIPM (privacy program management) plus CIPP/US or CIPP/C; CIPT is a plus.
- Technical familiarity with modern privacy tech platforms (e.g., OneTrust, Securiti.ai, WireWheel) and data infrastructure analytics.
- Experience navigating financial regulations and compliance frameworks (e.g., GLBA, PCI-DSS) alongside traditional consumer privacy laws.
- Public-company experience, including supporting audit committee or board-level reporting.
About You:
- You have relentlessly high standards - many people may think your standards are unreasonably high. You are continually raising the bar and driving those around you to deliver great results. You make sure that defects do not get sent down the line and that problems are fixed so they stay fixed.
- You’re not bound by convention - your success, and much of the fun, lies in developing new ways to do things.
- You need action - speed matters in business. Many decisions and actions are reversible and do not need extensive study. We value calculated risk-taking.
- You earn trust - you listen attentively, speak candidly, and treat others respectfully.
- You have backbone; disagree, then commit - you can respectfully challenge decisions when you disagree, even when doing so is uncomfortable or exhausting. You have conviction and are tenacious. You do not compromise for the sake of social cohesion. Once a decision is determined, you commit wholly.
- You deliver results - you focus on the key inputs and deliver them with the right quality and in a timely fashion. Despite setbacks, you rise to the occasion and never settle.
What Makes Working at Sezzle Awesome:
At Sezzle, we are more than just brilliant engineers, passionate data enthusiasts, out-of-the-box thinkers, and determined innovators. We believe in surrounding ourselves with only the best and the brightest individuals. Our culture is not defined by a certain set of perks designed to give the illusion of the traditional startup culture, but rather, it is the visible example living in every employee that we hire.
Compensation: The compensation range for the role is $4,500-$6,500 USD GROSS per month. Our ranges are very broad to accommodate all types of candidates and encourage growth. Specific compensation offered to a candidate may be dependent on factors such as education, experience, qualifications, and alignment with market data. Exceptional candidates may receive salaries outside of the posted ranges.
#Li-remote
What you'll do
- Drive Sezzle’s implementation of the NIST Privacy Framework from roadmap to operating program, including Current and Target Profiles, gap analysis, a prioritized and costed action plan, and ongoing monitoring.
- Align the privacy program with US state and federal requirements including CCPA/CPRA, other state comprehensive privacy laws, GLBA, TCPA, and Canadian privacy laws including PIPEDA and Quebec’s Law 25.
- Own privacy risk assessments and Privacy Impact Assessments for new products, features, and third-party vendors.
- Operate an intake and disposition process that gives every proposal a documented answer: approved, approved with controls, or needs redesign.
- Build and maintain the enterprise data inventory and data map in partnership with Engineering.
- Track the lifecycle of consumer information.
- Manage the automation and fulfillment of consumer access, deletion, and opt-out requests.
- Administer Sezzle’s de-identification and aggregation standard and its approval workflow.
- Ensure data-driven products and analytics ship with the right privacy controls designed in from the start.
- Partner directly with Engineering, Product, and Marketing teams during early-stage development so privacy requirements are designed in.
- Run the cadence of Sezzle’s cross-functional privacy working group.
- Maintain the program’s decision log and obligations register.
- Track privacy program metrics.
- Support executive and board-level reporting.
- Collaborate with the Information Security team to manage, investigate, and mitigate privacy incidents and cross-border data transfer risks.
What they require
- 4+ years of dedicated experience managing data privacy programs.
- Experience standing up at least one privacy program or major program component from early stage to steady state, such as a data inventory, consumer rights operation, or privacy review process.
- Ideal: high-growth fintech, e-commerce, or SaaS experience operating in both the US and Canada.
- Hands-on experience implementing a recognized privacy or security framework, including profiles or maturity assessments, gap analyses, and action plans.
- Strong working knowledge of major North American privacy frameworks including CCPA/CPRA, the broader US state privacy law landscape, TCPA, GLBA, PIPEDA, and Quebec Law 25.
- Ability to translate complex legal mandates into clear, actionable business processes.
- Fluency in de-identification, aggregation, and other privacy-enhancing techniques as tools for responsible data product launches.
- Ability to defend the line between what is de-identified and what is not.
- High emotional intelligence with the ability to influence technical and non-technical stakeholders.
- Ability to run a cross-functional working group.
- Ability to present clearly to executives.
- Self-starter mindset with the ability to manage multiple high-stakes projects simultaneously in a fast and agile environment.
- Relentlessly high standards and ability to drive others to deliver results.
- Ability to prevent defects and ensure problems are fixed permanently.
- Ability to develop new ways to do things and not be bound by convention.
- Bias for action and comfort with calculated risk-taking.
- Ability to listen attentively, speak candidly, and treat others respectfully.
- Ability to respectfully challenge decisions, disagree and commit.
- Tenacity and conviction without compromising for social cohesion.
- Focus on key inputs and ability to deliver quality results on time despite setbacks.
- Preferred: CIPM plus CIPP/US or CIPP/C; CIPT is a plus.
- Preferred: technical familiarity with modern privacy tech platforms and data infrastructure analytics.
- Preferred: experience navigating financial regulations and compliance frameworks alongside traditional consumer privacy laws.
- Preferred: public-company experience, including supporting audit committee or board-level reporting.
Benefits
- Opportunity to build and run Sezzle’s formal company-wide privacy program from the ground floor.
- Executive sponsorship is in place, the implementation roadmap is defined, and core program materials are drafted.
- Opportunity to work in a dynamic, fast-paced environment within a rapidly growing team.
- Abundant prospects for career advancement.
- Culture focused on hiring high-standard, high-performing individuals.
Sezzle is a fintech company focused on interest-free installment plans and shopping/payment experiences for consumers and merchants.