Privacy, Security, and AI Compliance Specialist
Napster Corp.
Job Description
Privacy, Security, and AI Compliance Specialist
\n \nNapster
\n \nLocation: Remote - Anywhere in US (CST, EST) or UK
\n \nAbout Napster
\nNapster is an AI-first platform company. We build and deploy AI agents across consumer, enterprise, and developer products, and we run hardware in public spaces. As the company continues to grow across global markets and expand its technology and product offerings, we are building scalable operational, security, privacy, AI governance, and compliance programs that support the business today and position us for future growth.
\n \nWe are looking for a Privacy, Security and AI Compliance Specialist to help run and maintain Napster’s privacy, security, AI governance, and compliance framework across our global organization.
\n \nThe Role
\nThe Privacy, Security and AI Compliance Specialist will be responsible for assisting with implementing, operating, and maintaining Napster’s privacy fundamentals, security, PIMS procedures, incident handling, data mapping, vendor/privacy risk, and AI governance compliance programs across our global operations.
\n \nThis is a hands-on role for someone who is comfortable taking day-to-day charge of the documentation, and registers behind several compliance programs at once. You will help support and maintain Napster’s Privacy Information Management System (PIMS), Information Security Management System (ISMS), and AI Management System (AIMS), and assist with compliance efforts across ISO 27001, ISO 27701, ISO 42001, SOC 2, and other applicable privacy and security frameworks.
\n \nWorking under the Operations Department, you’ll work closely with other teams to translate regulatory, contractual, and certification requirements into practical processes that can scale with the company.
\n \nResponsibilities
\nPrivacy & Compliance
\n- \n
- Support the operation and maintenance of Napster's Privacy Information Management System (PIMS) and supporting privacy compliance framework, as defined by the program. \n
- Maintain the documented scope of Napster's privacy and information security management systems across entities, systems, products, and business operations, and flag changes that require a scope decision. \n
- Maintain data maps, records of processing activities, retention requirements, and data subject request processes across applicable jurisdictions. \n
- Document and review controller and processor classifications for new and existing controllers and processors as relevant, and the appropriate privacy controls for Napster’s processing activities. \n
- Conduct privacy reviews and Data Protection Impact Assessments (DPIAs) for new products, features, vendors, and the record of processing activities (ROPA). \n
- Operate and refine the processes that align Napster's day-to-day operations with applicable privacy, security, regulatory, and contractual requirements. \n
- Maintain the documented process for the full personal data lifecycle, including collection, use, retention, transfer, return, and secure disposal, end-to-end. \n
- Assist with the data subject request process, including intake, identity verification, response within statutory deadlines, and auditable record-keeping. \n
- Maintain PIMS governance documentation, including defined roles and decision rights, documented PIMS objectives, and a tracker showing status against those objectives. \n
- Compile and report PIMS performance metrics defined by the program as requested. \n
Certifications & Audit Readiness
\n- \n
- Assist with Napster’s compliance certification and attestation programs, including ISO 27001, ISO 27701, ISO 42001, and SOC 2, along with compliance with data protection legislation. \n
- Assist with readiness and gap assessments. \n
- Assist with the maintenance of audit-ready policies, standards, procedures, controls, and supporting documentation. \n
Source of Truth & Ongoing Operation
\n- \n
- Maintain the register of approved vendors, sub-processors, and tools, including which are approved for which markets, whether a vendor has infrastructure in the required region, and under what data residency and transfer conditions. \n
- Act as the first point of contact for internal teams on whether a given vendor, tool, or processing activity is approved for a given market or use case, and give a clear answer with alternatives where they exist. \n
- Maintain the map of how personal data flows across our global operations, and keep it current as vendors and clients change. \n
AI Governance & Compliance
\n- \n
- Maintain the AI system inventory, covering purpose, data sources, model provenance, and deployment surface for each system. \n
- Maintain the record of Napster’s role for each AI system, as provider, deployer, or both, together with its risk classification. \n
- Coordinate AI impact assessments, including fundamental rights assessments where required, and keep the resulting records. \n
- Maintain the AI regulatory obligation tracker across the EU AI Act, US state AI and automated decision-making laws, and sector-specific AI rules, and translate obligations into requirements for the teams that own them. \n
- Support AI incident identification, escalation, and regulatory reporting procedures, and maintain the external channel for reporting adverse impacts. \n
- Maintain the record of approved AI vendors and model providers, including responsible-AI attestations, training-data restrictions, and market limitations. \n
- Support stakeholders on AI transparency obligations, including agent disclosure, synthetic content marking, and rights relating to automated decision-making. \n
This role does not cover AI model quality assurance. Testing model behavior, red-teaming, and evaluating model outputs sit with other teams. This role sets and maintains the governance record around those activities.
\n \nPrivacy, Legal & Contractual Compliance
\n- \n
- Establish and document the lawful basis supporting applicable processing activities. \n
- Manage the privacy and security requirements associated with Data Processing Agreements (DPAs), Article 28 processor terms, Standard Contractual Clauses (SCCs), international data transfers, and security schedules. \n
- Partner closely with Legal on regulatory interpretation, contractual privacy and security requirements, breach notification obligations, and negotiated customer or partner agreements. \n
- Help ensure Napster’s privacy and security practices remain aligned with GDPR, UK GDPR, CCPA/CPRA, and other applicable global privacy requirements. \n
Risk, Incident & Third-Party
\n- \n
- Operate Napster’s third-party and vendor risk management program, including onboarding assessments, risk tiering, ongoing monitoring, and periodic reassessments. \n
- Support and maintain privacy and security incident response procedures and documentation. \n
- Track incident response procedures against applicable regulatory and contractual reporting and notification requirements. \n
- Oversee enterprise customer and partner security reviews, including security questionnaires, diligence requests, and supporting documentation. \n
- Identify emerging compliance risks and work with stakeholders to develop practical remediation plans. \n
What We’re Looking For
\n- \n
- 8+ years of experience in privacy, security compliance, IT audit, GRC, or a related field, including direct responsibility for building or managing a privacy or security compliance program. \n
- Strong knowledge of security and privacy frameworks, such as ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIST Cybersecurity Framework, NIST SP 800-53, and SOC 2 Trust Services Criteria. \n
- Strong understanding of ISO/IEC 27701 as a standalone Privacy Information Management System standard, and of how a PIMS aligns with an ISO/IEC 27001 ISMS. \n
- Strong understanding of ISO/IEC 42001 as a standalone AI Management System standard, and of how an AIMS aligns with an ISO/IEC 27001 ISMS. \n
- Practical, hands-on experience using AI tools, whether at work or independently, with the ability to explain how AI-assisted compliance or analytical work was independently validated against authoritative source material. \n
- Experience maintaining compliance registers, trackers, and evidence libraries across more than one framework at a time, with the analytical judgment to spot when a record no longer matches reality. \n
- Hands-on experience operating data subject request workflows and personal data lifecycle controls, including retention, transfer, secure disposal, and privacy program objectives and metrics. \n
- Working knowledge of global privacy regulations, including GDPR, UK GDPR, and CCPA/CPRA. \n
- Experience applying lawful basis, controller and processor classifications, international transfer requirements, and other privacy principles to real-world business operations. \n
- Demonstrated experience working with and scaling ISO, NIST, SOC 2, or similar compliance programs. \n
- Experience performing risk assessments, internal audits, privacy reviews, and DPIAs. \n
- Experience reviewing and operationalizing Data Processing Agreements, security schedules, and related privacy and security terms in partnership with Legal. \n
- Working knowledge of cloud infrastructure and SaaS security controls across AWS, Azure, GCP, or similar environments. \n
- Experience supporting external audits and certification activities, including evidence collection, fieldwork coordination, and remediation tracking, and working directly with customers, vendors, and internal stakeholders. \n
- Strong written communication skills with the ability to develop clear, audit-ready documentation. \n
- Ability to operate independently, manage competing priorities, and drive execution in a fast-moving environment. \n
Preferred Qualifications
\n- \n
- CIPP/E, CIPP/US, CIPP/C, CIPP/A, CDPO, CIPM, CIPT, CISSP, CISA, CRISC, AIGP, ISO Working knowledge of ISO 27001 / ISO 27001 / ISO 42001 implementation , or similar certification - Lead Implementer or equivalent experience preferred. \n
- Experience with compliance automation platforms such as Vanta, Drata, or Secureframe. \n
- Experience implementing or supporting AI governance frameworks, including ISO 42001, the EU AI Act, or the NIST AI Risk Management Framework. \n
- Experience managing privacy and security compliance across multiple jurisdictions and legal entities. \n
- Experience supporting EU and Middle East operations. \n
- Experience responding to enterprise customer security and compliance reviews within a B2B, SaaS, technology, or platform business. \n
- Analytical or compliance-analysis background, with strong project coordination skills: able to run recurring compliance work across several teams and hold owners to deadlines. \n
- Experience directly supporting a designated Data Protection Officer (DPO) and Information Security leadership. \n
Success in This Role
\nSuccess in this role means supporting a privacy and security compliance program that is practical, scalable, and embedded into how Napster operates.
\n \nYou will strengthen visibility across Napster's privacy and security controls, support the certification and attestation efforts led by the program, enhance audit readiness,reduce compliance risk by surfacing gaps early, and execute the repeatable processes that allow the company to expand into new markets, and launch new products without unnecessary operational friction.
\n \nIn the first year, the priority is centralizing the day-to-day upkeep of documentation, and registers, that currently sit with multiple departments. Some parts of the year will involve assisting with review and audit cycles end to end within the program's calendar; others will be steady maintenance and record-keeping.
\n \nMost importantly, you will help scale the compliance needed to support Napster's continued growth.
\n \nWhy Join Napster?
\nThis is an opportunity to build, not simply maintain.
\n \nYou will have the ability to shape Napster’s global privacy and security compliance program from the ground up and work directly with teams across Napster.
\n \nAs Napster expands its global footprint and develops new technology and AI-enabled products, this role will play an important part in creating the governance, controls, and operational infrastructure necessary to support that growth.
\n \nIf you have wanted more hands-on exposure to AI than a traditional compliance function allows, this is that role. We are an AI-first company, and this work sits close to how our AI products are built, shipped, and governed.
\n \nBenefits
\n- \n
- Paid Time-Off: We offer flexible vacation time with 10 company holidays. \n
- Health Plans: We offer robust medical, dental, and vision plans for you and your dependents. Disability, life insurance, and FSA benefits are also available \n
- Wellness: Access to Teladoc and an EAP \n
- Parental Leave: Paid leave \n
- Retirement Savings: Contribute pretax earnings to our 401(k) Plan \n
Our Culture
\n- \n
- Impact: Play a crucial role in our growth journey. \n
- Culture: Join a vibrant team valuing creativity and collaboration. \n
- Growth: Thrive in a fast-paced, dynamic environment. \n
- Reward: Enjoy competitive compensation, equity opportunities, and comprehensive benefits. \n
- Ready to shape our future? Apply now and be part of something extraordinary! \n
We’re looking for more forward-thinking, collaborative people to be part of our innovation journey and mission to push the boundaries of technology. If you’re ready to help us achieve this vision, we’d love to hear from you! At Napster Corp , we're looking for people who are invigorated by our values and driven to change the world, not those who simply check off boxes.
\n \nNapster Corp embraces a diversity of backgrounds and experienc
$16.04 per hour
...focusing on the U.S. Departments of Homeland Security and Treasury. We strive to hire only... ...enrollment process. Data Security and Privacy: Handle sensitive personal information carefully... ...contractor, and federal employee files. Compliance and Training: Stay up to date with...SuggestedFull timeFor contractorsLocal areaFlexible hours$150k - $205k
...Team is seeking an experienced AI Application Developer to drive... ...needs into scalable, secure, and elegant technology solutions... ...alignment with enterprise security, compliance, and scalability requirements.... ...-based access control, data privacy, and performance at scale. \n...SuggestedWork at officeRemote work- ...One Federal Solution is seeking Credentialing Specialists to support a large federal identity credentialing... ...and customer support activities while ensuring compliance with established credentialing policies and security procedures. This position supports secure identity...SuggestedPermanent employmentFor contractorsWork experience placementWork at office
$10 - $20 per hour
...Job Description At TELUS Digital , we don't just build smart AI; we build intuitive AI . As a Human-AI Interaction (HAI) & UX Specialist , you are the architect of the user experience. You study the "friction" between human intent and machine response, refining...SuggestedHourly payFor contractorsLocal areaRemote workFlexible hours- ...Description Job Description Legal and Compliance Specialist FLSA Classification Non-Exempt... ...counsel and compliance officer, HIPAA privacy officer, and risk manager, the legal... ...’s privacy officer and HIPAA security officer. Maintain documentation related...SuggestedContract workWork at officeLocal area
- ...ensuring the safety, legality, and efficiency of the Mon EMS agency. Oversee non-clinical operations, including regulatory, privacy standards & compliance for organizational safety requirements, fleet, inventory & supply management and facilities maintenance in alignment...Work at officeLocal area
$60 - $70 per hour
...growing community of professionals advancing the next wave of AI. As an AI Trainer, you’ll play a hands-on role by analyzing... ...evaluating professional work preferred \n \n \n LinkedIn Data Security and Privacy Notice \n -Data-Privacy- Notice_LI_TalentCommunity.pdf...Hourly payFull timeContract workPart timeRemote work$100k - $115k
...partner; final legal opinions, contract language, and formal compliance determinations remain the responsibility of the Legal and... ...affecting 340B operations is a plus. \n Understanding of HIPAA privacy and security requirements and safe handling of protected health...Contract workTemporary workWork experience placementWork at officeRemote workWork from homeHome officeFlexible hours$18 - $50 per hour
...Overview: Siemens Digital Industries Software is seeking an AI & Engineering Data Intern to support emerging Artificial Intelligence... ...a strong and representative candidate pool. California Privacy Notice California residents have the right to receive additional...Remote jobHourly payFull timeInternshipLocal area$65 per hour
...other language professionals to work as project consultants in our AI Labor Marketplace. This is not a full-time employment position -... ..., AI training, content review, or quality assurance is a plus. \n \n \n LinkedIn Global Data Privacy Notice for Job Candidates...Hourly payFull timeContract workPart timeRemote work$74.1k - $148.3k
...designs and implements the structured cabling, security, AV, BMS/controls, and related systems... ..., and testing packages to ensure full compliance with OCI standards. Vendor Management... ...innovations to life-saving care. And with AI embedded across our products and services...Temporary workLive inLocal areaWorldwideRelocationRelocation packageFlexible hours- ...Job Description ImagineX is a tech company that deploys AI-assisted teams to build and secure mission-critical enterprise solutions with our clients –... ...). Enterprise Security: Understanding of RBAC, data privacy, and secure execution sandboxes for code-interpreter agents...Permanent employmentFull timeTemporary workRemote work
- ...exists between what the front line needs and what is delivered. Our AI-native platform, Air Enterprise Readiness, aligns development,... ...cutting-edge Artificial Intelligence solutions for our National Security clientele. This pivotal AI leadership role is instrumental in...Full timeWork at officeRemote work
$145k - $150k
...States \n \n The Forward Deployed AI Solutions Engineer role is responsible... ...operational pain points, data constraints, compliance boundaries, and user adoption barriers.... ...real systems and data while respecting security, privacy, HIPAA, PHI, and operational control...Permanent employmentFull timeRemote workMonday to Friday$50 per hour
...Job Description Domain Expert – AI Prompt Design & Evaluation \n \n Experience: Professional / Domain Expertise Required \n Job Type: Contractor \n Schedule: Flexible \n Compensation: $50 per approved task \n \n Role Overview \n We are looking...For contractorsFlexible hours$170k - $230k
...and equitable care. \n The Opportunity \n We’re hiring an AI Engineer with strong voice AI experience to help design and... ...engagement, or SDOH \n Familiarity with HIPAA and healthcare data and privacy considerations \n \n Compensation and Benefits \n \n ~...Remote work- ...Job Description Our global client is seeking a Product Regulatory Compliance Specialist to join their team! \n \n The Product Regulatory Compliance Specialist will manage regulatory compliance activities throughout the product lifecycle. This role will oversee...Work at office
- ...private investment firm seeking a Legal & Compliance Analyst to join its team. This is a broad... ...\n Support Marketing Rule, privacy and cybersecurity compliance initiatives... ...develop scalable processes and leverage AI and technology tools to improve workflows...Remote work
$40 per hour
...pay rates based on progression and performance. (No max hours; no min hours) \n Healthcare Operations experts evaluate and improve AI-generated responses on healthcare operations topics and author expert-level, source-grounded work product used to train AI. There is...Remote work- ...\n Tredence's BFSI Data & AI practice is scaling rapidly across... ...Data and AI Consulting Specialist to help lead this growth. This... ...ensure platforms are scalable, secure, and built for future growth.... ...entitlements, and regulatory and compliance considerations to every...
- ...PolyPhaze is a data intelligence platform that makes enterprise data AI-ready by unifying and governing information across systems. The... ...the governance envelope as an engineering requirement, not a compliance box: authority levels enforced architecturally, audit hooks live...Full timeContract workInterim roleFlexible hours
$23 per hour
...education, we deliver lasting solutions to today’s toughest workforce challenges. \n \n JOB SUMMARY \n The Temporary Compliance Onboarding Specialist position is within Prolink's Compliance department and partners with key stakeholders to complete onboarding...Temporary workLocal areaRemote workFlexible hoursShift work$86.4k
...and interoperability, NLP, and AI/ML algorithms. Includes... ...employees to do this job. Compliance Requirement : This job adheres... ...as described in the Notice of Privacy Practices and Privacy... ...Procedures as well as all data security guidelines established within...For contractorsWork at officeLocal area- ...Job Description Compliance & Quality Specialist \n Substance Use Disorder & Mental Health | Remote / Hybrid (Broward/Palm Beach) \n \n Banyan Treatment Centers is looking for a detail-oriented and motivated Compliance & Quality Specialist to support regulatory...Immediate startRemote work
- ...Job Description Lead AI Forward Deployed Engineer – Databricks \n \n ON Data Staffing is partnering with a leading Data... ...\n Partner with AI Engineering, Data Engineering, Analytics, Security, and Governance teams to deliver secure and scalable AI solutions...
- ...Description The role \n Early June is hiring a contract AI & Marketing Ops Automation Specialist to build our agency's operating "brain": connected... ..., and handle routine tasks. \n • Keep client data secure. Many clients are in healthcare, so you'll follow our rules...Full timeContract workPart timeImmediate startRemote work
$112.7k - $193.2k
...everyone. From advanced data analytics and AI to cybersecurity, we use innovative... ..., operations, and support while building secure, scalable, and resilient enterprise software... ...evaluation frameworks, security guardrails, and compliance standardsMentor teams on prompt...Minimum wageFull timeWork experience placementWork at officeLocal areaRemote work$150k - $250k
...Description Sticker Mule is building the most lucrative commerce platform on the Internet by combining software, manufacturing, and AI in one stack. \n \n We're hiring an engineer to build, run and manage a team of AI agents to help us innovate faster, improve...Remote workRelocation package$25 per hour
Prolific is seeking an AI Training Expert to help train and evaluate leading AI models. This position offers competitive pay up to $25 per hour for one-hour tasks, allowing you to work from home. Successful candidates will have strong AI training skills, attention to detail...Remote jobHourly payWork from homeFlexible hours- ...Job Description we are a technology company specializing in AI for Science and applying AI technologies to cutting-edge research and real-world applications in biopharmaceuticals, new materials, finance, and other fields. \n \n Directions You Will Be Involved...Remote workOverseas
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Privacy, Security, and AI Compliance Specialist. Be the first to apply!
- regulatory compliance remote West Virginia
- regulatory affairs assistant West Virginia
- customs compliance West Virginia
- compliance team leader West Virginia
- compliance technician West Virginia
- code compliance West Virginia
- compliance lead West Virginia
- regulatory compliance West Virginia
- regulatory affairs West Virginia
- privacy compliance West Virginia





