Privacy, Security, and AI Compliance Specialist
Software Engineering, Data Science, Compliance / Regulatory
United States
Privacy, Security, and AI Compliance Specialist
Napster
Location: Remote - Anywhere in US (CST, EST) or UK
About Napster
Napster is an AI-first platform company. We build and deploy AI agents across consumer, enterprise, and developer products, and we run hardware in public spaces. As the company continues to grow across global markets and expand its technology and product offerings, we are building scalable operational, security, privacy, AI governance, and compliance programs that support the business today and position us for future growth.
We are looking for a Privacy, Security and AI Compliance Specialist to help run and maintain Napster’s privacy, security, AI governance, and compliance framework across our global organization.
The Role
The Privacy, Security and AI Compliance Specialist will be responsible for assisting with implementing, operating, and maintaining Napster’s privacy fundamentals, security, PIMS procedures, incident handling, data mapping, vendor/privacy risk, and AI governance compliance programs across our global operations.
This is a hands-on role for someone who is comfortable taking day-to-day charge of the documentation, and registers behind several compliance programs at once. You will help support and maintain Napster’s Privacy Information Management System (PIMS), Information Security Management System (ISMS), and AI Management System (AIMS), and assist with compliance efforts across ISO 27001, ISO 27701, ISO 42001, SOC 2, and other applicable privacy and security frameworks.
Working under the Operations Department, you’ll work closely with other teams to translate regulatory, contractual, and certification requirements into practical processes that can scale with the company.
Responsibilities
Privacy & Compliance
- Support the operation and maintenance of Napster's Privacy Information Management System (PIMS) and supporting privacy compliance framework, as defined by the program.
- Maintain the documented scope of Napster's privacy and information security management systems across entities, systems, products, and business operations, and flag changes that require a scope decision.
- Maintain data maps, records of processing activities, retention requirements, and data subject request processes across applicable jurisdictions.
- Document and review controller and processor classifications for new and existing controllers and processors as relevant, and the appropriate privacy controls for Napster’s processing activities.
- Conduct privacy reviews and Data Protection Impact Assessments (DPIAs) for new products, features, vendors, and the record of processing activities (ROPA).
- Operate and refine the processes that align Napster's day-to-day operations with applicable privacy, security, regulatory, and contractual requirements.
- Maintain the documented process for the full personal data lifecycle, including collection, use, retention, transfer, return, and secure disposal, end-to-end.
- Assist with the data subject request process, including intake, identity verification, response within statutory deadlines, and auditable record-keeping.
- Maintain PIMS governance documentation, including defined roles and decision rights, documented PIMS objectives, and a tracker showing status against those objectives.
- Compile and report PIMS performance metrics defined by the program as requested.
Certifications & Audit Readiness
- Assist with Napster’s compliance certification and attestation programs, including ISO 27001, ISO 27701, ISO 42001, and SOC 2, along with compliance with data protection legislation.
- Assist with readiness and gap assessments.
- Assist with the maintenance of audit-ready policies, standards, procedures, controls, and supporting documentation.
Source of Truth & Ongoing Operation
- Maintain the register of approved vendors, sub-processors, and tools, including which are approved for which markets, whether a vendor has infrastructure in the required region, and under what data residency and transfer conditions.
- Act as the first point of contact for internal teams on whether a given vendor, tool, or processing activity is approved for a given market or use case, and give a clear answer with alternatives where they exist.
- Maintain the map of how personal data flows across our global operations, and keep it current as vendors and clients change.
AI Governance & Compliance
- Maintain the AI system inventory, covering purpose, data sources, model provenance, and deployment surface for each system.
- Maintain the record of Napster’s role for each AI system, as provider, deployer, or both, together with its risk classification.
- Coordinate AI impact assessments, including fundamental rights assessments where required, and keep the resulting records.
- Maintain the AI regulatory obligation tracker across the EU AI Act, US state AI and automated decision-making laws, and sector-specific AI rules, and translate obligations into requirements for the teams that own them.
- Support AI incident identification, escalation, and regulatory reporting procedures, and maintain the external channel for reporting adverse impacts.
- Maintain the record of approved AI vendors and model providers, including responsible-AI attestations, training-data restrictions, and market limitations.
- Support stakeholders on AI transparency obligations, including agent disclosure, synthetic content marking, and rights relating to automated decision-making.
This role does not cover AI model quality assurance. Testing model behavior, red-teaming, and evaluating model outputs sit with other teams. This role sets and maintains the governance record around those activities.
Privacy, Legal & Contractual Compliance
- Establish and document the lawful basis supporting applicable processing activities.
- Manage the privacy and security requirements associated with Data Processing Agreements (DPAs), Article 28 processor terms, Standard Contractual Clauses (SCCs), international data transfers, and security schedules.
- Partner closely with Legal on regulatory interpretation, contractual privacy and security requirements, breach notification obligations, and negotiated customer or partner agreements.
- Help ensure Napster’s privacy and security practices remain aligned with GDPR, UK GDPR, CCPA/CPRA, and other applicable global privacy requirements.
Risk, Incident & Third-Party
- Operate Napster’s third-party and vendor risk management program, including onboarding assessments, risk tiering, ongoing monitoring, and periodic reassessments.
- Support and maintain privacy and security incident response procedures and documentation.
- Track incident response procedures against applicable regulatory and contractual reporting and notification requirements.
- Oversee enterprise customer and partner security reviews, including security questionnaires, diligence requests, and supporting documentation.
- Identify emerging compliance risks and work with stakeholders to develop practical remediation plans.
What We’re Looking For
- 8+ years of experience in privacy, security compliance, IT audit, GRC, or a related field, including direct responsibility for building or managing a privacy or security compliance program.
- Strong knowledge of security and privacy frameworks, such as ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIST Cybersecurity Framework, NIST SP 800-53, and SOC 2 Trust Services Criteria.
- Strong understanding of ISO/IEC 27701 as a standalone Privacy Information Management System standard, and of how a PIMS aligns with an ISO/IEC 27001 ISMS.
- Strong understanding of ISO/IEC 42001 as a standalone AI Management System standard, and of how an AIMS aligns with an ISO/IEC 27001 ISMS.
- Practical, hands-on experience using AI tools, whether at work or independently, with the ability to explain how AI-assisted compliance or analytical work was independently validated against authoritative source material.
- Experience maintaining compliance registers, trackers, and evidence libraries across more than one framework at a time, with the analytical judgment to spot when a record no longer matches reality.
- Hands-on experience operating data subject request workflows and personal data lifecycle controls, including retention, transfer, secure disposal, and privacy program objectives and metrics.
- Working knowledge of global privacy regulations, including GDPR, UK GDPR, and CCPA/CPRA.
- Experience applying lawful basis, controller and processor classifications, international transfer requirements, and other privacy principles to real-world business operations.
- Demonstrated experience working with and scaling ISO, NIST, SOC 2, or similar compliance programs.
- Experience performing risk assessments, internal audits, privacy reviews, and DPIAs.
- Experience reviewing and operationalizing Data Processing Agreements, security schedules, and related privacy and security terms in partnership with Legal.
- Working knowledge of cloud infrastructure and SaaS security controls across AWS, Azure, GCP, or similar environments.
- Experience supporting external audits and certification activities, including evidence collection, fieldwork coordination, and remediation tracking, and working directly with customers, vendors, and internal stakeholders.
- Strong written communication skills with the ability to develop clear, audit-ready documentation.
- Ability to operate independently, manage competing priorities, and drive execution in a fast-moving environment.
Preferred Qualifications
- CIPP/E, CIPP/US, CIPP/C, CIPP/A, CDPO, CIPM, CIPT, CISSP, CISA, CRISC, AIGP, ISO Working knowledge of ISO 27001 / ISO 27001 / ISO 42001 implementation , or similar certification - Lead Implementer or equivalent experience preferred.
- Experience with compliance automation platforms such as Vanta, Drata, or Secureframe.
- Experience implementing or supporting AI governance frameworks, including ISO 42001, the EU AI Act, or the NIST AI Risk Management Framework.
- Experience managing privacy and security compliance across multiple jurisdictions and legal entities.
- Experience supporting EU and Middle East operations.
- Experience responding to enterprise customer security and compliance reviews within a B2B, SaaS, technology, or platform business.
- Analytical or compliance-analysis background, with strong project coordination skills: able to run recurring compliance work across several teams and hold owners to deadlines.
- Experience directly supporting a designated Data Protection Officer (DPO) and Information Security leadership.
Success in This Role
Success in this role means supporting a privacy and security compliance program that is practical, scalable, and embedded into how Napster operates.
You will strengthen visibility across Napster's privacy and security controls, support the certification and attestation efforts led by the program, enhance audit readiness,reduce compliance risk by surfacing gaps early, and execute the repeatable processes that allow the company to expand into new markets, and launch new products without unnecessary operational friction.
In the first year, the priority is centralizing the day-to-day upkeep of documentation, and registers, that currently sit with multiple departments. Some parts of the year will involve assisting with review and audit cycles end to end within the program's calendar; others will be steady maintenance and record-keeping.
Most importantly, you will help scale the compliance needed to support Napster's continued growth.
Why Join Napster?
This is an opportunity to build, not simply maintain.
You will have the ability to shape Napster’s global privacy and security compliance program from the ground up and work directly with teams across Napster.
As Napster expands its global footprint and develops new technology and AI-enabled products, this role will play an important part in creating the governance, controls, and operational infrastructure necessary to support that growth.
If you have wanted more hands-on exposure to AI than a traditional compliance function allows, this is that role. We are an AI-first company, and this work sits close to how our AI products are built, shipped, and governed.
Benefits
- Paid Time-Off: We offer flexible vacation time with 10 company holidays.
- Health Plans: We offer robust medical, dental, and vision plans for you and your dependents. Disability, life insurance, and FSA benefits are also available
- Wellness: Access to Teladoc and an EAP
- Parental Leave: Paid leave
- Retirement Savings: Contribute pretax earnings to our 401(k) Plan
Our Culture
- Impact: Play a crucial role in our growth journey.
- Culture: Join a vibrant team valuing creativity and collaboration.
- Growth: Thrive in a fast-paced, dynamic environment.
- Reward: Enjoy competitive compensation, equity opportunities, and comprehensive benefits.
- Ready to shape our future? Apply now and be part of something extraordinary!
We’re looking for more forward-thinking, collaborative people to be part of our innovation journey and mission to push the boundaries of technology. If you’re ready to help us achieve this vision, we’d love to hear from you! At Napster Corp, we're looking for people who are invigorated by our values and driven to change the world, not those who simply check off boxes.
Napster Corp embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees. We strive to build a company that reflects a global audience.
CCPA Notice for California Job Candidates: Please review our CCPA notice at
https://www.napster.ai/policy-docs/ccpa-notice-for-job-candidates