← Back to jobs

Director, Data Privacy

Company
Envestnet
Location
Remote
Work type
Full Time
Posted
2026-08-12

Job description

The Team You’ll Join

The Data Privacy team at Envestnet helps safeguard one of the company’s most important assets—data. Working closely with Legal, Security, Product, and Engineering teams, they embed privacy-by-design principles into business processes, technology solutions, and client experiences while ensuring compliance with evolving privacy regulations. Through privacy impact assessments, risk management, policy development, and incident response support, the team plays a critical role in protecting customer trust and strengthening the company’s security posture. It’s an exciting environment for professionals who are passionate about the intersection of technology, risk, compliance, and innovation in a rapidly evolving regulatory landscape

How You’ll Contribute

This role serves as the secondary US-based leader for Envestnet Enterprise's data privacy function, reporting into the CISO/CTO organization, and acts as a senior leader and eventually succession-ready backup to existing privacy leadership. Success is measured by the maturity and consistency of privacy program execution (assessments, policy, incident support), by measurable reduction in existing leader's time spent on day-to-day tactical privacy matters, and by effective people leadership of distributed team members (including India-based staff) with direct management responsibility for team development, performance, and career growth.

Own and mature Envestnet's US-based data privacy program, ensuring alignment with CCPA California Consumer Privacy Act (CCPA) /CPRA, California Privacy Rights Act state privacy laws, and applicable global regulations.
Serve as a senior leader and "right hand" to privacy/security leadership — providing coverage, continuity, and long-term succession potential for the privacy function.
Directly manage and develop distributed privacy team members (including India-based teammates), including performance management, career development, and day-to-day leadership.
Build and scale the privacy team through effective hiring, onboarding, and talent development to meet growing organizational needs.
Lead privacy impact assessments (PIAs/DPIAs), data mapping, and privacy-by-design reviews in partnership with Product and Engineering.
Support privacy-related incident response and breach notification processes in coordination with the security organization.
Develop, maintain, and operationalize privacy policies, standards, and procedures reflecting the evolving regulatory landscape.
Conduct third-party/vendor privacy risk assessments and support related contract review.
Partner cross-functionally with Legal, Security, Engineering, and Product to embed privacy requirements into business operations.
Represent the privacy function in relevant cybersecurity governance forums and reporting.

What You’ll Need to Bring

Bachelor's degree in a relevant field, or equivalent professional experience.
8+ years of experience in data privacy program management, ideally within financial services, fintech, or a similarly regulated industry.
3+ years of direct people management experience, including hiring, performance management, and developing technical/privacy professionals.
Demonstrated working knowledge of US privacy/data protection regulations (CCPA/CPRA, GLBA, state privacy laws) and familiarity with global frameworks (e.g., GDPR).
Active privacy certification (e.g., CIPP/US, CIPM, or CIPT) or equivalent demonstrated expertise.

Nice-to-Haves

Proven ability to lead, mentor, and develop distributed teams across multiple time zones while maintaining strong program execution.
Based in the continental US, with flexibility to support both Eastern and Pacific (and IST to an extent) time zone collaboration.

Original source