CrawlJobs Logo

Privacy By Design Manager

United Kingdom, London Employment contract · Job Posted June 09, 2026
Apply Position
Job Link Share

Job Description

As a Privacy by Design Manager in the Vodafone Secure & Privacy by Design team, you will be part of a global team which provides world class by design advisory and compliance support to a wide range of internal stakeholders. You will join our Group Privacy & Responsible AI Team and lead the transformation agenda (process, operating model, tooling, and metrics), while also providing by design and assurance support across the business.

Job Responsibility

  • Privacy transformation (process ownership, improvement & simplification): Lead and own simplification and redesign of global privacy processes (e.g., DPIA, LIA, TIA and ROPA) and the supporting templates, playbooks and guidance, applying project/programme management discipline (scope, plan, milestones, and stakeholder governance) to drive delivery and adoption
  • Operating model, decision thresholds & demand management: Lead and own the operating model for privacy engagement, including entry/exit criteria, proportionate decision thresholds and demand triage
  • Support Responsible AI (RAI) processes: Lead and contribute to RAI process workstreams to improve and embed AI risk assessment processes into day-to-day delivery
  • Automation & tooling: Lead delivery of privacy automation and tooling improvements
  • work with Technology, Cyber Security and tool owners to embed privacy logic into enterprise workflows (e.g. OneTrust)
  • Metrics, insights & reporting: Lead operational metrics, dashboards and reporting to track demand, cycle times, completion, incidents and risk trends for management reporting
  • Audit actions, controls & quality: Partner with internal audit and own closure of audit actions, including root cause analysis and sustained remediation
  • Stakeholder enablement & culture: Lead enablement to embed privacy by design ways of working, including training and awareness
  • Market engagement: Lead engagement with local market privacy contacts to align delivery of global privacy and AI risk assessments
  • Supplier compliance & scalable enablement: Lead scalable supplier enablement, embedding privacy and responsible AI requirements into supplier governance through standards, templates and guidance
  • Privacy and RAI Operational Support: Provide operational support to the Privacy by Design team

Requirements

  • Strong experience in privacy, with proven ability to lead process improvement or transformation initiatives and drive adoption across a matrix organisation
  • Strong understanding of relevant legislation including the GDPR, ePrivacy Directive and related regulatory expectations, with the ability to translate requirements into practical, scalable and proportionate processes
  • Hands-on experience conducting and assuring privacy assessments (e.g., DPIAs, LIAs, TIAs) and maintaining core privacy records (e.g., ROPA), ideally using workflow tooling such as OneTrust
  • Metrics driven mindset: ability to define KPIs, analyse operational data (e.g., volumes, cycle time, risk trends) and produce management ready reporting to drive continuous improvement
  • Tooling and automation awareness (e.g., privacy tooling and workflow platforms), with the ability to identify and implement opportunities to standardise and automate low-risk or repeatable activities (OneTrust and Jira experience is advantageous)
  • Excellent organisation skills, able to handle multiple requests with differing priorities and stakeholders
  • Excellent command of English, and excellent interpersonal, oral and written communication and public speaking skills
  • Comfortable working in a matrix organisation with tolerance for ambiguity. Persistence to drive change over time
  • Courage to ‘stand up and be counted’ even when view is unpopular at a more senior level
  • Ability to analyse complex information and identify key and relevant points, including communicating in a relevant and easy to understand manner with different audiences
  • Privacy accreditation such as the CIPP/E, CIPM or CIPT

Nice to have

OneTrust and Jira experience is advantageous

What we offer

  • Yearly bonus: 10%
  • Annual leave: 28 days + bank holidays + the opportunity to buy/sell/carry over 5 days/year
  • Charity days: 5 days/year
  • Maternity leave: 52 weeks: the first 13 weeks are fully paid, followed by 26 weeks of half pay
  • Private pension: You can contribute up to 5% of your basic pay with 2:1 matching from Vodafone up to 10%
  • Access to: private medical, private dental, free health assessments, share save scheme
  • Additional discounts: Vodafone retail, gym, cinema, cycle to work, season ticket loan

Looking for more opportunities?

Search for other job offers that match your skills and interests.

Similar Jobs for

Privacy By Design Manager

8 matching positions

Senior Manager - Secure by Design

We are seeking a Senior Tester to deliver high-quality testing services within t...
Location
Location
India , Bangalore
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 10–15 years of experience in IT security, with strong expertise in Security Architecture
  • Proficient in Information Security Risk Assessment, including Cloud, Data Centre, and Application Security
  • Familiar with OWASP “Security by Design” and Risk Frameworks
  • Experienced with standards/frameworks such as ISO27001, ISO22301, ISO31001, NIST 800-53, OWASP
  • Strong stakeholder management and communication skills
  • Able to simplify complex problems and deliver innovative solutions
  • Advantageous if certified in CISA, CISM, ISO 27001/31001, or ITIL/SCRUM/Lean Six Sigma
  • Knowledge of GDPR, Data Privacy, and Information Protection
  • Experience in telecoms or IP networks is a plus
Job Responsibility
Job Responsibility
  • Conduct security assessments and define requirements for new products and services
  • Provide expert guidance on security architecture and design across business units
  • Act as a cyber coach to agile projects and program teams globally
  • Ensure compliance with Vodafone’s security standards for internal and external stakeholders
  • Collaborate with cross-functional teams including Risk & Compliance, Ethical Hacking, and Security Operations
  • Influence the risk posture of products and services and support commercial launch decisions
  • Promote security as a business enabler and differentiator
What we offer
What we offer
  • Opportunity to be a part testing initiatives in a global telecom environment
  • Exposure to diverse technologies including CRM, Billing, and Middleware
  • Collaboration with international teams and stakeholders
  • Involvement in strategic and operational decision-making
  • A chance to contribute to innovation and continuous improvement in testing practices
Read More
Arrow Right

Legal Operations, Contracts Manager, and Privacy Program Manager

This is a rare opportunity to join as the first dedicated legal operations hire ...
Location
Location
United States , Los Angeles
Salary
Salary:
120000.00 - 155000.00 USD / Year
suno.ai Logo
Suno
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 4–7 years of experience as a paralegal, legal operations professional, or privacy program manager
  • Experience building or significantly improving legal processes and workflows
  • Strong understanding of commercial contracts (SaaS, vendor, licensing agreements)
  • Working knowledge of privacy regulations (CCPA/CPRA, GDPR) and DSR management
  • Experience with contract lifecycle management tools (Ironclad, DocuSign CLM, or similar)
  • Exceptional organizational skills and attention to detail
  • Ability to work independently and prioritize in a fast-paced environment
  • Bachelor's degree required
  • paralegal certificate or privacy certification (CIPP/US, CIPM) a plus
  • A genuine interest in AI and/or music
Job Responsibility
Job Responsibility
  • Design and implement our commercial contracts workflow—from intake to signature to filing
  • Route contracts for review and signature, managing stakeholder communications and timelines
  • Maintain our contract repository and ensure proper organization and accessibility
  • Negotiate routine commercial agreements (NDAs, vendor contracts, SaaS agreements) with attorney oversight
  • Create and maintain contract templates, playbooks, and self-service resources for the business
  • Build legal operations infrastructure from scratch—you'll define our processes, not inherit them
  • Implement and manage legal technology tools (CLM, matter management, e-billing)
  • Develop metrics and reporting to track legal team performance and workload
  • Manage outside counsel relationships, including engagement letters and invoice review
  • Create intake processes that make it easy for the business to work with legal
What we offer
What we offer
  • Company Equity Package
  • 401(k) with 3% Employer Match & Roth 401(k)
  • Medical, Dental, & Vision Insurance (PPO w/ HSA & FSA options)
  • 11 Paid Holidays + Unlimited PTO & Sick Time
  • 16 Weeks of Paid Parental Leave
  • Creative Education Stipend
  • Generous Commuter Allowance
  • In-Office Lunch
  • Fulltime
Read More
Arrow Right

Group Product Manager, Privacy and Trust

As Group Product Manager, Privacy and Trust, you will own enterprise consent, pr...
Location
Location
United States , Austin, Texas; Mountain View, California; Warren, Michigan
Salary
Salary:
159400.00 - 245700.00 USD / Year
gm.com Logo
General Motors
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of digital/software product management experience, with at least 3+ years owning enterprise platforms, APIs, or backend services consumed by multiple internal product teams
  • 3+ years of experience as a people manager of product managers, or equivalent experience leading senior PMs and complex multi-PM platform programs
  • Demonstrated experience in privacy, consent, identity, compliance, or another regulated platform domain, with a strong understanding of how regulation translates into product and engineering requirements
  • Strong technical fluency with distributed systems, microservices, event-driven architectures, API design, and data platforms
  • able to make informed trade-offs and partner credibly with senior engineering leaders
  • Proven ability to balance the needs of many downstream consumers with platform-wide consistency, performance, and total cost of ownership at significant scale
  • Strong analytical skills with the ability to define platform metrics and SLOs, and to interpret operational and adoption data to drive decisions
  • Excellent written communication, with the ability to produce structured, data-informed narratives that align legal, engineering, and product stakeholders
  • Demonstrated success leading cross-functional initiatives in fast-paced, matrixed organizations.
Job Responsibility
Job Responsibility
  • Own the long-term product vision, architecture priorities, and multi-year roadmap for the platform, balancing regulatory requirements, downstream consumer needs, reliability, and total cost of ownership
  • Lead and grow a team of product managers covering the major consent, privacy and preferences areas (consent management, legal terms and agreements, preferences, and platform services), setting strategy and developing PM talent on the team
  • Establish and operate the platform reliability and quality bar, including SLOs, production readiness reviews, incident reduction targets, observability, and a clear path to 99.9%+ availability for read endpoints
  • Define the onboarding and self-service model for new consumers of the platform, reducing time-to-onboard a new jurisdiction or product and minimizing duplicated compliance logic across teams
  • Act as the voice of the customer and ensure digital products follow best in class privacy and trust practices, even when you don't directly own the product
  • Actively monitor emerging trends, incorporate data, research, and market analysis to inform, define, prioritize, and drive execution of product roadmap that spans privacy initiatives, data handling, consent experiences, and privacy controls
  • Operate as the single point of accountability for the platform and team across consumers (mobile, web, in-vehicle), prioritizing roadmap intake, brokering trade-offs, and unblocking critical programs
  • Define and monitor platform KPIs (latency, availability, consent throughput, onboarding time, audit/compliance coverage, P1 incidents, downstream adoption) and communicate platform health, progress, and trade-offs to senior leadership.
What we offer
What we offer
  • Incentive pay program
  • medical, dental, vision, Health Savings Account, Flexible Spending Accounts, retirement savings plan, sickness and accident benefits, life insurance, paid vacation & holidays, tuition assistance programs, employee assistance program, GM vehicle discounts
  • company vehicle evaluation program
  • relocation benefits.
  • Fulltime
Read More
Arrow Right

Secure By Design - VOIS

We are seeking an experienced Information Security professional to support secur...
Location
Location
India , Pune
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5–8 years of IT experience
  • strong exposure to perimeter security, network engineering, and security management
  • experienced in information security risk assessment across cloud platforms (AWS, Azure, GCP, Oracle), data centres, and applications
  • knowledgeable in security principles, protocols, and technologies such as PKI, SSL, IKEv1 & v2, sandboxing, and cloud security controls
  • familiar with global security frameworks and assurance models
  • aware of data privacy and information protection requirements, including GDPR
  • comfortable working in complex, cross-functional environments
  • telco industry experience is advantageous
  • professional certifications such as CCNA, CISM, CISSP, ISO 27001, or ISO 31001 are desirable
Job Responsibility
Job Responsibility
  • Conduct information security risk assessments across cloud, data centre, and application environments
  • provide security architecture guidance and technical design recommendations to internal teams during the design and build phases
  • evaluate business requirements and proposed technical designs to identify risks, define secure alternatives, and recommend optimal security solutions
  • apply recognised security frameworks and standards such as ISO 27001, ISO 31001, NIST, CIS, SANS, and NIST SP 800-53
  • support secure development practices aligned with OWASP 'Security by Design' principles
  • assess and advise on perimeter security controls, including firewalls, VPNs, proxies, and network security solutions
  • monitor and interpret the global threat landscape, including advanced persistent threats, to inform risk-based decisions
  • create clear reports, dashboards, and presentations to communicate security posture, trends, and performance to stakeholders
  • collaborate across teams, influencing outcomes through strong interpersonal and negotiation skills
What we offer
What we offer
  • Opportunities to work on large-scale, global security initiatives within a leading telecoms environment
  • exposure to diverse technologies, cloud platforms, and international stakeholders
  • a collaborative and inclusive workplace that values learning, innovation, and professional growth
  • the chance to influence security strategy and design decisions at an early stage
  • Fulltime
Read More
Arrow Right

Secure by Design - Artificial Intelligence

We are seeking a Secure by Design – Artificial Intelligence professional to ensu...
Location
Location
India , Bangalore
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • Experienced IT and cyber security professional with deep expertise in securing Office IT products and services
  • Strong understanding of AI governance, AI security frameworks, Microsoft Copilot, LLM risk management, prompt security, and AI lifecycle governance
  • Proficient in agile working methods and knowledgeable across endpoint, cloud, and modern collaboration ecosystems
  • Skilled in secure identity management and familiar with Office IT‑driven technology environments
  • Able to communicate complex security concepts clearly to technical and non‑technical stakeholders
  • Holds a university degree in Information Security or equivalent
  • Possesses one or more relevant certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor, GIAC, TOGAF, SABSA or equivalent
  • Brings 5+ years of cyber security experience and 10+ years of experience with Microsoft Office 365, Microsoft Security services, and associated technologies
  • Has 5+ years of cloud security experience
Job Responsibility
Job Responsibility
  • Oversee the Group SPDA assessment process from initiation to sign‑off and guide product teams throughout
  • Review HLDs, BSRs, risk items, and penetration test findings to identify necessary security and privacy controls
  • Collaborate with Local Privacy, Corporate Security, and Secure by Design teams to ensure complete SPDA coverage
  • Ensure SPDA outcomes are reflected in Risk Registers and Personal Data Processing Registers
  • Support and coordinate the penetration testing lifecycle—from onboarding to final reporting
  • Maintain awareness of the AIB Platform architecture, capabilities, and existing security controls to align AI use cases
  • Apply knowledge of AI/GenAI methods such as RAG pipelines, LLM‑enabled automation, and AI agents within SPDA considerations
  • Track mitigation plans through to closure or escalate them to cyber risk governance where required
  • Provide security validation across environments (lab to pre‑prod to prod)
  • Ensure ongoing alignment of SPDA activities with GDPR requirements and Vodafone security policies
What we offer
What we offer
  • Exposure to cutting‑edge AI security practices and enterprise‑scale secure‑by‑design frameworks
  • Opportunity to influence security strategy for high‑impact global products and AI platforms
  • Cross‑functional collaboration with cyber security, architecture, privacy, ethical hacking, and product teams
  • Development within a global organisation committed to innovation and secure digital transformation
Read More
Arrow Right

Secure‑By‑Design (AI & Office IT) Security Lead - VOIS

We are seeking an experienced cyber security professional to ensure that Vodafon...
Location
Location
India , Pune
Salary
Salary:
Not provided
vodafone.com Logo
Vodafone
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • An experienced cyber security professional with a strong background in securing Office IT, cloud-based services, and enterprise collaboration platforms
  • Knowledgeable in AI governance and AI security, including risk management for large language models, prompt security, lifecycle governance, and secure enterprise deployment
  • Comfortable working in agile delivery environments and complex technology landscapes spanning desktop, web, mobile, and cloud services
  • Confident communicating security risks and requirements clearly to both technical teams and non-technical stakeholders at all organisational levels
  • Qualified in information security or a related discipline, with recognised professional certifications and several years of practical cyber security and cloud security experience
Job Responsibility
Job Responsibility
  • Own and lead the Secure by Design assessment process from initial demand through to formal sign-off, supporting product and delivery teams throughout
  • Review solution and design documentation, including high-level designs, security requirements, risk items, and penetration test results, to identify appropriate security and privacy controls
  • Coordinate with privacy, corporate security, and Secure by Design stakeholders to ensure complete and consistent assessment coverage
  • Ensure assessment outcomes are accurately reflected in risk registers and personal data processing records
  • Support and coordinate penetration testing activities from onboarding through to final reporting and remediation tracking
  • Apply in-depth understanding of AI and GenAI use cases, including retrieval-augmented generation, AI agents, and large language model automation, and assess their security and privacy implications
  • Maintain awareness of enterprise AI platforms, their architecture, and existing security controls to ensure alignment when onboarding or modifying AI-related capabilities
  • Track mitigation actions through to closure, escalating unresolved risks through appropriate cyber risk governance forums
  • Support security approvals across development, pre-production, and production environments when enabling new capabilities
  • Provide guidance to internal teams, suppliers, and third parties to ensure alignment with Vodafone security standards and regulatory obligations, including GDPR
What we offer
What we offer
  • The opportunity to influence the security posture of global, AI-enabled products and services used by millions of customers and colleagues
  • Exposure to cutting-edge AI and GenAI technologies within a large, complex enterprise environment
  • Collaboration with diverse, international teams across cyber security, privacy, technology, and business functions
  • A role where security is positioned as a business enabler and differentiator, not a barrier
  • Fulltime
Read More
Arrow Right

Manager – Privacy Risk Enablement

The Privacy Program Enablement Manager will play a key role within the Digital T...
Location
Location
United Kingdom , London; Brighton
Salary
Salary:
Not provided
americanexpress.com Logo
Amex
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 5+ years of relevant experience in privacy risk, operational risk, compliance, or related governance functions
  • Experience strengthening and scaling privacy-related processes within a financial services or highly regulated environment
  • Demonstrated ability to think strategically while executing tactically
  • Strong understanding of risk frameworks, controls, and governance processes
  • Proven ability to influence and drive alignment across multiple stakeholders in a matrixed organization
  • Strong organizational skills with the ability to manage multiple priorities effectively
  • Excellent written and verbal communication skills
  • High degree of personal accountability, initiative, and resilience
  • Solutions-oriented mindset with strong analytical and problem-solving capabilities
  • Employment eligibility to work with American Express in the UK is required
Job Responsibility
Job Responsibility
  • Partner with stakeholders across business and risk teams to enhance enterprise-wide privacy risk assessment processes in alignment with the AMEX risk framework
  • Identify and implement best practices to strengthen the monitoring and management of privacy risk across regions and business units
  • Develop and enhance clear, actionable guidance related to privacy risk and controls, including supporting training and enablement materials for business partners
  • Integrate privacy risk activities into existing enterprise processes, governance forums, and technology tools
  • Serve as a subject matter expert (SME) in privacy risk identification, documentation, assessment, and control implementation
  • Support the design and continuous improvement of tools that facilitate privacy risk tracking, control management, and reporting
  • Drive updates to privacy guidance documentation, ensuring alignment with internal policy requirements and external regulatory expectations
  • Promote awareness, engagement, and accountability for privacy risk management across stakeholders in a matrixed environment
What we offer
What we offer
  • Competitive base salaries
  • Bonus incentives
  • Support for financial-well-being and retirement
  • Comprehensive medical, dental, vision, life insurance, and disability benefits (depending on location)
  • Flexible working model with hybrid, onsite or virtual arrangements depending on role and business need
  • Generous paid parental leave policies (depending on your location)
  • Free access to global on-site wellness centers staffed with nurses and doctors (depending on location)
  • Free and confidential counseling support through our Healthy Minds program
  • Career development and training opportunities
  • Fulltime
Read More
Arrow Right

Privacy Manager

Bentley Systems is seeking a Privacy Manager to join our growing Corporate Respo...
Location
Location
Ireland , Dublin
Salary
Salary:
Not provided
bentley.com Logo
Bentley Systems
Expiration Date
Until further notice
Flip Icon
Requirements
Requirements
  • 3+ years privacy experience, with a track record of developing, implementing, or significantly contributing to a privacy program (in-house or from a top-tier consultancy firm), ideally within a global setting
  • Specialist privacy qualifications, such as an IAPP certification (e.g., CIPP/E, CIPM) or a Law or IT degree or higher, or a diploma focused on data protection would be a distinct advantage
  • Demonstrated ability to communicate complex privacy requirements clearly and persuasively to diverse stakeholders, fostering engagement, collaboration and driving change
  • Experience building relationships and influencing cross-functional teams and leadership within a global enterprise environment
  • A proactive and collaborative colleague who thrives on working independently while connecting with global colleagues
Job Responsibility
Job Responsibility
  • Take full ownership of our established global privacy program
  • Be a Strategic Partner and collaborate across the business including product, technology, infosec, legal and leadership teams to embed a "privacy-by-design" culture, providing expert guidance on a range of compliance matters
  • Be a key advisor on emerging digital regulations and play a central role in developing and implementing our AI responsible use program
  • Utilise your knowledge of European privacy regulations to help navigate the deltas in APAC and other international regions, ensuring our global strategy is both consistent and locally relevant
  • Create and deliver dynamic, engaging privacy training that resonates with different teams, from engineers to marketers, translating complex requirements into actionable business practices
  • Oversee core privacy functions, including Data Protection Impact Assessments (DPIAs), risk reviews, and data subject rights requests, ensuring efficiency and excellence
What we offer
What we offer
  • A great Team and culture
  • An exciting career as an integral part of a world-leading software company providing solutions for architecture, engineering, and construction
  • An attractive salary and benefits package
  • A commitment to inclusion, belonging and colleague wellbeing through global initiatives and resource groups
  • A company committed to making a real difference by advancing the world’s infrastructure for better quality of life
Read More
Arrow Right