Live opening · Posted 5 days ago

Privacy, Security, and AI Compliance Specialist

Napster Corp. · United States (Remote)
Linkedin Yes
You are 5 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 5 days ago
CompanyNapster Corp.
LocationUnited States (Remote)
Salary401(k), +4 benefits
Work modeYes
SourceLinkedin
Listed5 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
17 min from Linkedin publishing this role to us finding it
18 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
73,783 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

Privacy, Security, and AI Compliance Specialist
Napster
Location: Remote - Anywhere in US (CST, EST) or UK
About Napster
Napster is an AI-first platform company. We build and deploy AI agents across consumer, enterprise, and developer products, and we run hardware in public spaces. As the company continues to grow across global markets and expand its technology and product offerings, we are building scalable operational, security, privacy, AI governance, and compliance programs that support the business today and position us for future growth.
We are looking for a Privacy, Security and AI Compliance Specialist to help run and maintain Napster’s privacy, security, AI governance, and compliance framework across our global organization.
The Role
The Privacy, Security and AI Compliance Specialist will be responsible for assisting with implementing, operating, and maintaining Napster’s privacy fundamentals, security, PIMS procedures, incident handling, data mapping, vendor/privacy risk, and AI governance compliance programs across our global operations.
This is a hands-on role for someone who is comfortable taking day-to-day charge of the documentation, and registers behind several compliance programs at once. You will help support and maintain Napster’s Privacy Information Management System (PIMS), Information Security Management System (ISMS), and AI Management System (AIMS), and assist with compliance efforts across ISO 27001, ISO 27701, ISO 42001, SOC 2, and other applicable privacy and security frameworks.
Working under the Operations Department, you’ll work closely with other teams to translate regulatory, contractual, and certification requirements into practical processes that can scale with the company.
Responsibilities
Privacy & Compliance
Support the operation and maintenance of Napster's Privacy Information Management System (PIMS) and supporting privacy compliance framework, as defined by the program.
Maintain the documented scope of Napster's privacy and information security management systems across entities, systems, products, and business operations, and flag changes that require a scope decision.
Maintain data maps, records of processing activities, retention requirements, and data subject request processes across applicable jurisdictions.
Document and review controller and processor classifications for new and existing controllers and processors as relevant, and the appropriate privacy controls for Napster’s processing activities.
Conduct privacy reviews and Data Protection Impact Assessments (DPIAs) for new products, features, vendors, and the record of processing activities (ROPA).
Operate and refine the processes that align Napster's day-to-day operations with applicable privacy, security, regulatory, and contractual requirements.
Maintain the documented process for the full personal data lifecycle, including collection, use, retention, transfer, return, and secure disposal, end-to-end.
Assist with the data subject request process, including intake, identity verification, response within statutory deadlines, and auditable record-keeping.
Maintain PIMS governance documentation, including defined roles and decision rights, documented PIMS objectives, and a tracker showing status against those objectives.
Compile and report PIMS performance metrics defined by the program as requested.
Certifications & Audit Readiness
Assist with Napster’s compliance certification and attestation programs, including ISO 27001, ISO 27701, ISO 42001, and SOC 2, along with compliance with data protection legislation.
Assist with readiness and gap assessments.
Assist with the maintenance of audit-ready policies, standards, procedures, controls, and supporting documentation.
Source of Truth & Ongoing Operation
Maintain the register of approved vendors, sub-processors, and tools, including which are approved for which markets, whether a vendor has infrastructure in the required region, and under what data residency and transfer conditions.
Act as the first point of contact for internal teams on whether a given vendor, tool, or processing activity is approved for a given market or use case, and give a clear answer with alternatives where they exist.
Maintain the map of how personal data flows across our global operations, and keep it current as vendors and clients change.
AI Governance & Compliance
Maintain the AI system inventory, covering purpose, data sources, model provenance, and deployment surface for each system.
Maintain the record of Napster’s role for each AI system, as provider, deployer, or both, together with its risk classification.
Coordinate AI impact assessments, including fundamental rights assessments where required, and keep the resulting records.
Maintain the AI regulatory obligation tracker across the EU AI Act, US state AI and automated decision-making laws, and sector-specific AI rules, and translate obligations into requirements for the teams that own them.
Support AI incident identification, escalation, and regulatory reporting procedures, and maintain the external channel for reporting adverse impacts.
Maintain the record of approved AI vendors and model providers, including responsible-AI attestations, training-data restrictions, and market limitations.
Support stakeholders on AI transparency obligations, including agent disclosure, synthetic content marking, and rights relating to automated decision-making.
This role does not cover AI model quality assurance. Testing model behavior, red-teaming, and evaluating model outputs sit with other teams. This role sets and maintains the governance record around those activities.
Privacy, Legal & Contractual Compliance
Establish and document the lawful basis supporting applicable processing activities.
Manage the privacy and security requirements associated with Data Processing Agreements (DPAs), Article 28 processor terms, Standard Contractual Clauses (SCCs), international data transfers, and security schedules.
Partner closely with Legal on regulatory interpretation, contractual privacy and security requirements, breach notification obligations, and negotiated customer or partner agreements.
Help ensure Napster’s privacy and security practices remain aligned with GDPR, UK GDPR, CCPA/CPRA, and other applicable global privacy requirements.
Risk, Incident & Third-Party
Operate Napster’s third-party and vendor risk management program, including onboarding assessments, risk tiering, ongoing monitoring, and periodic reassessments.
Support and maintain privacy and security incident response procedures and documentation.
Track incident response procedures against applicable regulatory and contractual reporting and notification requirements.
Oversee enterprise customer and partner security reviews, including security questionnaires, diligence requests, and supporting documentation.
Identify emerging compliance risks and work with stakeholders to develop practical remediation plans.
What We’re Looking For
8+ years of experience in privacy, security compliance, IT audit, GRC, or a related field, including direct responsibility for building or managing a privacy or security compliance program.
Strong knowledge of security and privacy frameworks, such as ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIST Cybersecurity Framework, NIST SP 800-53, and SOC 2 Trust Services Criteria.
Strong understanding of ISO/IEC 27701 as a standalone Privacy Information Management System standard, and of how a PIMS aligns with an ISO/IEC 27001 ISMS.
Strong understanding of ISO/IEC 42001 as a standalone AI Management System standard, and of how an AIMS aligns with an ISO/IEC 27001 ISMS.
Practical, hands-on experience using AI tools, whether at work or independently, with the ability to explain how AI-assisted compliance or analytical work was independently validated against authoritative source material.
Experience maintaining compliance registers, trackers, and evidence libraries across more than one framework at a time, with the analytical judgment to spot when a record no longer matches reality.
Hands-on experience operating data subject request workflows and personal data lifecycle controls, including retention, transfer, secure disposal, and privacy program objectives and metrics.
Working knowledge of global privacy regulations, including GDPR, UK GDPR, and CCPA/CPRA.
Experience applying lawful basis, controller and processor classifications, international transfer requirements, and other privacy principles to real-world business operations.
Demonstrated experience working with and scaling ISO, NIST, SOC 2, or similar compliance programs.
Experience performing risk assessments, internal audits, privacy reviews, and DPIAs.
Experience reviewing and operationalizing Data Processing Agreements, security schedules, and related privacy and security terms in partnership with Legal.
Working knowledge of cloud infrastructure and SaaS security controls across AWS, Azure, GCP, or similar environments.
Experience supporting external audits and certificatio

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App