Privacy & AI Governance Program Manager
As a key leader in Orion’s privacy and AI governance efforts, you will spearhead privacy initiatives and coordinate cross-team collaboration to ensure privacy processes are followed from start to finish. Serving as Orion’s operational hub for privacy, you will own the programs, processes, and documentation that keep the organization regulatory-ready and auditable. You will partner closely with Legal, Information Security, and business leaders to build and scale privacy operations, while also leading the organization’s AI governance program from a privacy perspective—setting expectations for how AI systems use personal information, reviewing AI use cases for privacy risk, and keeping Orion ahead of emerging AI-privacy requirements.
This role includes crisis management responsibilities, such as coordinating cross-functional responses and stakeholder involvement. The position is hybrid, requiring three or more days per week on-site at one of Orion’s office locations. Candidates should be within commutable distance to an office.
Responsibilities
- Serve as the primary privacy liaison and subject matter expert enterprise-wide, partnering with business and functional leaders to embed privacy considerations into decisions, product development, and operations.
- Develop, improve, and promote the privacy framework in alignment with leadership’s vision, directing and coordinating the privacy program, including associated organizational risks.
- Foster a culture of privacy compliance through policies, processes, and procedures, providing guidance to resolve privacy issues raised by business and functional areas.
- Oversee and direct privacy planning and procedure development, including managing privacy policies in coordination with Legal, Risk, and Information Security.
- Identify potential areas of privacy vulnerability and risk, develop corrective action plans, provide risk mitigation guidance, and report to the Data Protection Officer.
- Design, develop, and deliver privacy training programs for new hires and existing employees, including incident awareness, annual compliance training, and role-specific guidance.
- Manage responses to potential privacy issues in collaboration with Orion’s Legal Department, Information Security Team, and relevant business lines.
- Act as the organization’s primary privacy investigator, managing the full lifecycle of potential privacy incidents—from intake and triage to investigation, root cause analysis, client notification, and remediation tracking.
- Implement the Privacy Incident Response Plan as needed.
- Manage the Data Subject Rights Request (DSSR) process, including reviewing, validating, and responding to requests, and maintaining a repository of requests and responses.
- Report on data privacy matters to leadership and key collaborators, escalating privacy risks as required.
- Maintain working knowledge of and operationalize requirements under CCPA/CPRA, Reg S-P (amended), CIPA, and emerging state privacy laws.
- Coordinate with the Information Security Team to assist in vendor risk assessments related to privacy.
- Assist with Data Privacy Impact Assessments for new and existing business lines, products, and services.
- Participate in Orion committee meetings to provide privacy-related input.
- Build and maintain Records of Processing Activities (ROPA), documenting how personal information is collected, used, shared, and retained across Orion’s business lines.
- Identify and implement process improvements across the privacy program, developing structured workflows, playbooks, and response libraries, and leveraging AI tooling to automate routine tasks and sustain consistent, high-quality privacy operations.
- Establish, track, and report on privacy program metrics to measure compliance and operational performance across business lines.
- Manage cookie and online-tracking compliance, including consent mechanisms, in coordination with Legal and business lines.
- Monitor legal and regulatory developments in privacy laws and coordinate with Legal, Information Security, and business units to operationalize new requirements.
- Lead and mature the organization’s AI governance program and framework, defining responsible-AI principles, policies, and standards in coordination with Legal, Risk, Information Security, and business leaders.
- Maintain an inventory of AI and automated decision-making systems that process personal information, and operate a privacy intake, review, and approval workflow for new and existing AI use cases.
- Conduct privacy reviews and impact assessments for AI and machine-learning use cases involving personal information, evaluating data minimization, purpose limitation, transparency, and risks related to automated decision-making and profiling.
- Operationalize privacy-related requirements of emerging AI regulations (e.g., automated decision-making and profiling rules under CCPA/CPRA and the Colorado AI Act).
- Partner with Enterprise Risk Management, Legal, Compliance, Information Security, and Technology teams to manage incidents and crisis response activities.
- Support enterprise-wide crisis management and operational resiliency initiatives through response planning, stakeholder coordination, and participation in crisis activities.
Requirements
- Prioritizes tasks based on business importance and risk mitigation.
- Knowledge of the investment advisor industry, operations, and regulatory landscape.
- Knowledge of federal and state privacy laws, rules, and regulations applicable to investment advisory and fintech business lines.
- Experience developing new policies and procedures in response to regulatory or operational changes.
- Ability to learn and adapt to new systems and processes with limited direct training.
- Strong multitasking skills with careful attention to detail.
- Works effectively both individually and within a team environment.
- Works with a sense of urgency to meet deadlines and address competing priorities.
- Proficient in Microsoft Office software (Word, Excel, PowerPoint, Outlook).
- Effective written, listening, and verbal communication skills.
- Strong problem-solving and organizational skills.
- Ability to own and manage relationships with stakeholders at all levels of the organization.
- Proven track record of operationalizing and scaling cross-functional, organization-wide programs from the ground up.
- Analyzes complex problems to identify root causes and trends, translating complex requirements into simple, usable documentation and workflows.
- Works effectively in a fast-paced, high-growth environment with tight timelines and shifting priorities.
- Experience using AI tools to accelerate day-to-day privacy operations.
- Familiarity with global data-protection frameworks (e.g., GDPR) as applicable to Orion’s operations.
- Knowledge of privacy requirements applicable to AI, including automated decision-making and profiling rules under laws such as CCPA/CPRA and the Colorado AI Act.
- Understanding of core AI and machine-learning concepts and associated data-privacy risks, such as the use of personal information in training and inference, profiling, and transparency.
- Experience managing high-priority incidents and coordinating cross-functional crisis response efforts.
- Strong ability to make risk-informed decisions under pressure and effectively communicate with executive leadership during crisis situations.
- Minimum of a Bachelor’s degree; J.D. preferred.
- Minimum of 5 years of relevant experience.
Skills
- AI Governance
- Data Privacy
- Data Protection
- Incident Response
- Information Security
- Privacy Compliance
- Privacy Laws
- Risk Assessments
- Risk Management
Pay
$83,076.00 - $127,179.00. The pay listed is estimated at the time of posting and may vary depending on geographic location, job-related knowledge, skills, and experience.
Benefits
- Health, dental, vision, and disability coverage starting on day one.
- 401(k) plan with employer match.
- Paid parental leave.
- Pet benefits, including pawternity leave and pet insurance.
- Student loan repayment.