Privacy Manager
Bitgo · New York, United States · 2026-05-07
About this role
<div class="content-intro"><p>BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage. Since our founding in 2013, we have focused on enabling our clients to securely navigate the digital asset space. With a global presence and multiple Trust companies, BitGo serves thousands of institutions, including many of the industry's top brands, exchanges, and platforms, and millions of retail investors worldwide. As the operational backbone of the digital economy, BitGo handles a significant portion of Bitcoin network transactions and is the largest independent digital asset custodian, and staking provider, in the world. For more information, visit&nbsp;<a class="c-link" href="http://www.bitgo.com/" target="_blank" data-stringify-link="http://www.bitgo.com" data-sk="tooltip_parent">www.bitgo.com</a>.</p></div><p><span style="font-size: 12pt;">Partnering with BitGo Legal Department to build a global privacy program and execution for all internal and external privacy needs and requests. Privacy is an explicit, designated Security responsibility. BitGo is global and needs a single, accountable owner to operationalize privacy, reduce reliance on contractors, and meet regulatory requirements.</span></p> <p><span style="font-size: 12pt;"><em>This role will require being full-time onsite at our New York City office to support collaborative team dynamics and innovative problem-solving.</em></span></p> <p><span style="font-size: 12pt;"><strong>What you would do</strong></span></p> <ul> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Run privacy request operations end-to-end</span></h3> </li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Serve as the Data Protection Officer where required by law</span></h3> </li> <li style="font-size: 12pt; font-weight: bold;"><strong><span style="font-size: 12pt;">Lead the preparation and submission of mandatory data protection impact assessments (DPIAs) and/or privacy risk assessments (PRAs) to supervisory authorities when required by law.</span></strong></li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Partner with Legal in lock step</span></h3> </li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Build and maintain core privacy program governance (lean but audit-ready)</span></h3> </li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Vendor and procurement privacy</span></h3> </li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Personal data incident support</span></h3> </li> <li style="font-size: 12pt;"> <h3><span style="font-size: 12pt;">Metrics and continuous improvement</span></h3> </li> </ul> <p><span style="font-size: 12pt;"><strong>What success would look like (first 6 months)</strong></span></p> <ul> <li style="font-size: 12pt;"><span style="font-size: 12pt;">A single global intake and case workflow is live, with documented triage rules, deadlines, templates, and evidence retention.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Contractor reliance is materially reduced for routine privacy requests and program maintenance.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Data inventory and processing records are maintained and used in real workflows (requests, product reviews, vendor reviews).</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Privacy reviews are embedded into product and vendor change processes with predictable turnaround.</span></li> <li style="font-size: 12pt;"><span style="font-size: 12pt;">Executive-ready metrics exist and show improving cycle time and decreasing backlog.</span></li> </ul> <p><span style="font-size: 12pt;"><strong>Required qualifications</strong></span></p> <ul> <li>7 or more years with proven ability to build and run a privacy program with operational responsibility and hands-on execution of privacy requests at scale.</li> <li>Demonstrated ability to operate as a high-autonomy individual contributor in a lean environment.</li> <li>Strong experience partnering with attorneys and translating legal requirements into operational controls.</li> <li>Working knowledge of global privacy regulatory expectations, including but not limited to GLBA, GDPR, CCPA/CPRA, LGPD, PIPEDA, and how to implement them in practical workflows.</li> <li>Strong technical fluency: systems, data flows, access control concepts, logging, and incident handling collaboration.</li> <li>Oversee the formal creation and maintenance of the Record of Processing Activities (ROPA), including its periodic review and updates to ensure compliance with Article 30 of the GDPR (or equivalent local mandates).</li> <li>Excellent writing and documentation discipline (regulator-ready and…
Similar jobs
- Senior Technical Program Manager, PrivacyRobinhood · New York
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.