Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Data Privacy Manager

$118.5k - $152.5k

Lendistry

Lendistry is an Equal Opportunity/Affirmative Action Employer. We consider applicants without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, or membership in any other group protected by federal, state, or local law.

If you need assistance or accommodation due to a disability, you may contact us at View email address on click.appcast.io

Lendistry does not accept unsolicited resumes from recruiters, employment agencies, or staffing firms. To conduct business with Lendistry, a Master Services Agreement (MSA) must be executed and confirmed prior to submitting any information relating to a potential candidate. Without a signed MSA, Lendistry shall not be responsible to any individual or entity for any payment relating to any form of fee or compensation.

And, in the event that a resume or candidate is submitted by a recruiter, an employment agency, or a staffing firm without a fully executed MSA, Lendistry has the unrestricted right to pursue and hire any of those candidate(s) without any legal or financial responsibility to the recruiter, agency, and/or firm.


A Day in the Life

The Data Privacy Manager will lead the enterprise privacy program across Lendistry's and affiliated and subsidiary entities. Reporting to the VP, Enterprise Security, this role is the organization's technical data privacy subject matter expert, translating regulatory requirements into concrete technical controls and auditable processes.

You will own the governance, technical, and operational aspects of Lendistry's privacy program, spanning regulatory obligations under CCPA/CPRA, GLBA, SBA program requirements, state lending and consumer finance law, and evolving state privacy statutes, through day-to-day privacy operations, data subject rights handling, vendor privacy diligence, and privacy-by-design embedded in product development and AI/ML pipelines.

You will partner closely with Security, Legal, Compliance, Product, Engineering, and every business unit and process that collects, processes, or shares personal information, serving as the primary driver of technical implementation of compliance obligations across the organization.

Lendistry: Who We Are


We're proud to be the nation's largest minority-led, tech-savvy lender for small businesses and commercial real estate. As a certified Community Development Financial Institution (CDFI) and Community Development Entity (CDE), our mission is all about creating economic opportunities and fueling growth for small business owners and their communities. Join us as we pave the way with innovative financing and financial education!

What You'll Be Doing

Data Privacy & Protection
  • Serve as the Data Privacy subject matter expert for the organization.
  • Design, implement, and manage solutions to protect personal data, embedding "privacy by design" into the software development lifecycle, product architecture, and AI/ML privacy integration.
  • Act as a bridge between Compliance, Legal, and Engineering teams to translate privacy policy and regulatory requirements into (i) actionable requirements such as data minimization, encryption, tokenization, data masking, anonymization, and access controls, and (ii) clearly defined, auditable controls.
  • Maintain and continuously update enterprise data flow diagrams and data inventories to map the lifecycle of personal information from ingestion to deletion.
  • Lead and document annual privacy risk assessments, including Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Manage first-line-of-defense compliance with the technical requirements of applicable US state privacy laws (CCPA/CPRA, GLBA Safeguards Rule, and the growing patchwork of state statutes).
  • Support incident response activities related to data privacy, including breach assessment, documentation, and regulatory support, in partnership with the Security and Legal.
Privacy Strategy & Program Ownership
  • Own the governance, technical, and operational aspects of the enterprise privacy program across Lendistry and all subsidiary entities, working cross-departmentally with Legal, Compliance, and Engineering to set privacy strategy.
  • Serve as Lendistry's point of contact for Legal and Compliance on privacy matters involving regulators, banking partners, auditors, and consumers.
  • Set the privacy roadmap, including annual program priorities, investment requests, and measurable objectives tied to business and regulatory risk.
  • Report regularly to VP, Security and executive leadership on privacy posture, material risks, regulatory developments, incidents, and program maturity.
Privacy by Design & AI Privacy
  • Embed privacy by design in the product development lifecycle, reviewing new features, data flows, retention changes, and vendor integrations before they ship.
  • Partner with the AI team to set privacy guardrails on Lendistry's AI systems, including data minimization, PII redaction before inference, model training data governance, and consumer disclosure for automated decisioning.
  • Contribute to Lendistry's responsible AI posture alongside Legal, Compliance, Security, and the AI team, with attention to fair lending, consumer disclosures for AI-driven decisions, and alignment with the NIST AI Risk Management Framework.
Third-Party & Vendor Risk
  • Support third-party risk assessments with a focus on data handling, privacy, and regulatory exposure.
  • Review vendor security and privacy documentation (SOC reports, SIGs, DPAs).
  • Maintain and update the data inventory and data flow diagrams to reflect new tools or changes in the use case of existing tools, ensuring the vendor data map accurately tracks who receives Lendistry personal data, for what purpose, under what contractual protections, and with what track record.
  • Track controls and remediation items and ensure vendors meet contractual and regulatory obligations.
Training & Culture
  • Work with Compliance and Training and Development teams to administer privacy training, including role-based training for engineering, credit, servicing, marketing, and customer-facing teams, plus executive-level education.
  • Build a privacy-aware culture where data questions prompt conversation rather than workarounds.
  • Serve as a credible, accessible partner to every business unit that handles personal information.
Cross-Functional Collaboration
  • Work closely with Security, Engineering, Product, Legal, Compliance, and Operations teams.
  • Provide practical guidance that balances compliance, risk reduction, and business velocity.
  • Assist with regulator, auditor, and customer due-diligence inquiries.
AI Governance & Responsible Use

Lendistry expects its AI privacy team to be among the most thoughtful users of AI tools in the company. This role will collaborate with Legal, Compliance, AI and Engineering leadership to set AI use standards and strategy for privacy operations
  • Stay current on AI capabilities and limitations as they relate to privacy operations
  • Assist the Legal, Compliance and AI teams in shaping the policies, training, and controls that govern AI use across the organization
Your Areas of Knowledge and Expertise
Core Experience
  • 5+ years in privacy, data protection, or a closely adjacent field, with a clear pattern of growing program ownership and regulatory accountability.
  • Hands-on experience supporting regulatory and compliance programs, including SOC 2 and GLBA Safeguards Rule, along with familiarity with U.S. state privacy laws (CA, CO, VA, CT, UT, TX, OR, MT, NJ, TN, IA, IN, DE, NE, NH, MD, MN) and global frameworks such as GDPR, PIPEDA, LGPD, or DPDPA.
  • Demonstrated ability to perform privacy and security risk assessments - PIAs, DPIAs, and data security risk assessments - with strong documentation and evidence-management practices.
  • Hands-on experience developing and maintaining data inventories, data maps, and data flow diagrams to support privacy compliance and regulatory obligations.
  • Deep working knowledge of CCPA/CPRA, including consumer rights, sensitive personal information, service provider vs. third-party distinctions, opt-out signals, and CPPA enforcement expectations.
  • Deep working knowledge of GLBA (Privacy Rule and Safeguards Rule) and how GLBA interacts with state privacy laws for financial institutions.
Technical & Program Skills
  • Understanding of privacy engineering and secure system design, including familiarity with privacy-enhancing technologies such as differential privacy, federated learning, and secure multi-party computation (particularly in AI/ML pipelines).
  • Working knowledge of data mapping and automation tools used to manage data subject rights requests and privacy operations workflows (e.g., OneTrust, Archer, TrustArc, Transcend, Osano, or equivalent).
  • Experience embedding privacy into product development - reviewing features, data flows, and vendor integrations at the point of design rather than at launch.
  • Experience overseeing privacy for AI or automated decisioning systems - data minimization, training data governance, consumer disclosure, and fair lending intersections.
  • Strong analytical, organizational, and documentation skills, with the ability to manage multiple compliance initiatives independently and communicate effectively across technical and business stakeholders.
Required Certifications
  • CIPT or CDPSE required. CIPM and CISSP preferred.
Preferred Qualifications
  • CIPP/US, CIPP/E, CIPM, CIPT, or FIP privacy certifications.
  • Experience in SBA lending, CDFI operations, or other federally regulated financial institutions.
  • Experience with state lending examinations, CFPB matters, or other consumer-protection regulator engagement.
  • Experience with the NIST Privacy Framework and NIST AI Risk Management Framework.
  • Experience building privacy programs across multiple legal entities or operating subsidiaries.
  • Experience with cross-border operations.
Why You'll Love Working Here:
  • Comprehensive Medical, Dental, and Vision Insurance
  • Generous Paid Time Off
  • Birthday Day Off
  • 12 Paid Company Holidays
  • 401(k) Match
  • FSA and HSA
  • Paid Life Insurance

  • Paid Disability Insurance
  • Pet Insurance
  • Employee Assistance Program (EAP)
  • Professional Development Courses
  • In Office Provided Snacks and Drinks
  • Gym Facilities (LA & Tustin/CEC Offices)
  • In Office Engagement Activities


Compensation Range

The US base salary range for this full-time position is $118,500 - $152,500 annually.

Our salary ranges are determined by role, level, and location.

The range displayed on each job posting reflects the minimum and maximum base salary for new hires for the position across all US locations. Within the range, individual pay is determined by multiple factors like job-related skills, experience, and state of residence. Your recruiter can share more about the specific salary range during the interview process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include any variable compensation elements.

Physical Requirements

This is a stationary position that requires frequent sitting (approximately 95%), repetitive wrist motions, grasping, speaking, listening, close vision, and the ability to adjust focus. It also may require occasional standing, lifting, carrying of 20lbs or less, walking, kneeling, bending/stooping, twisting, pulling/pushing, and reaching above the shoulder. Employees in this position must be physically able to efficiently perform the essential functions of the position.

ACKNOWLEDGEMENT
B.S.D. Capital, Inc. dba Lendistry is an equal employment opportunity employer committed to providing its employees, applicants and other covered persons with equal opportunities without regard to race, color, age (40 or older), religious creed (including religious belief, practice or dress and grooming practices), national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender (including pregnancy, childbirth or medical condition related to pregnancy or childbirth), gender expression, gender identity, sexual orientation, military or veteran status (including past, current or prospective service), or any other characteristic protected under applicable federal, state or local law.
Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Data Privacy Manager in Los Angeles, CA vacancy
  • $145.52k - $180.29k

     ...reflects the rich diversity of Los Angeles County Integrated Data and Governance Officer $12,127 to $15,024 Monthly Insurance:...  ...administrative direction, plans, organizes, coordinates, and manages strategic processes for data governance; develops and leads a centralized... 
    Suggested
    Full time
    Contract work
    Work at office
    Remote work

    Los Angeles County Office of Education

    Downey, CA
    4 days ago
  • $71k - $81k

     ..., and IT operations. This role will be responsible for monitoring security systems, responding to incidents, supporting endpoint management, maintaining compliance standards, and assisting with IT projects including ERP implementation. The ideal candidate will... 
    Suggested
    Work at office
    Monday to Friday

    Pasona NA

    Los Angeles, CA
    1 day ago
  •  ...the kind of direct access and development opportunities that larger firms rarely offer at this level. Looking for 5-7+ years in data privacy and cybersecurity. Background in technology transactions, software licensing, fintech, or healthtech is a plus. Compensation is... 
    Suggested
    Work at office
    Flexible hours

    McClure Harrison, Inc.

    Los Angeles, CA
    2 days ago
  •  ...IT SECURITY INCIDENT RESPONSE MANAGER Downey, CA 5+ months Responsibilities:...  ...cause scenarios. d. Work directly with data asset owners and business response plan owners...  ...Manager (CISM), Certified Information Privacy Professional (CIPP), GIAC Certified Incident... 
    Suggested

    West Advanced Technologies

    Downey, CA
    18 hours ago
  • $125k - $175k

     ...assurance program against industry standards, requirements (contractual and regulatory), and organizational needs. Governance: Managing and spearheading governance of the classified cyber assurance program to interpret and drive implementation of industry standards,... 
    Suggested
    Permanent employment
    Temporary work
    Remote work
    Weekend work

    SpaceX

    Hawthorne, CA
    3 days ago
  • $113.4k - $162k

     ...professionals to join us in bringing smart money management and payment solutions to everyone's...  ...ISO 27001, CIS Benchmarks) for sensitive data protectio **Ability to work in the U.S....  ...meet your needs in a way that respects your privacy and ensures equal opportunity. Our goal... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Flexible hours
    3 days per week

    Green Dot

    Los Angeles, CA
    4 days ago
  •  ...Communications Security (COMSEC) Subject Matter Expert (SME) responsible for supporting the LAAFB COMSEC account and ensuring the secure management, control, distribution, and accountability of cryptographic materials and COMSEC equipment. This position requires strong... 
    Temporary work
    Local area

    Vision Information Technology

    Los Angeles, CA
    4 days ago
  •  ...including analysts, engineers, and project managers. This role is integral to identifying,...  ...Cloud Security Posture Management (CSPM), Data Loss Prevention (DLP), Microsoft Baseline...  ...please review Insight Global's Workforce Privacy Policy: Required Skills & Experience... 
    3 days per week

    Insight Global

    Los Angeles, CA
    4 days ago
  •  ...security control implementation, validation, and assessment activities. Perform and document system audits and risk analysis. Manage and execute Continuous Monitoring (ConMon) tasks to ensure compliance throughout the system lifecycle. Support configuration... 
    Full time
    Work experience placement
    Local area
    Immediate start
    Remote work
    Flexible hours

    Arete Associates

    Los Angeles, CA
    1 day ago
  • $110k - $190k

     ...secure development initiatives including code review, dependency management, secrets management, and vulnerability remediation...  ...ATO (Authority to Operate) Export control and regulated data handling requirements Assist with development of system security... 
    Contract work
    Work experience placement
    Casual work
    Relocation package

    CHAOS Industries

    Hawthorne, CA
    18 hours ago
  • $111.04k - $145k

     ...'re looking for an experienced Information Technology Security Manager to lead and evolve our enterprise Information Security Program...  ...organization to protect systems, networks, and sensitive member data. You'll work alongside executive leadership and play a key role... 
    Work experience placement
    Local area
    Monday to Friday
    Weekend work

    Northrop Grumman Federal Credit Union

    Gardena, CA
    2 days ago
  •  ...IT Security Compliance Manager Location: Downey, CA Duration: 6 Months The Consultant will perform the following tasks: 1....  ...Certified Information Security Manager (CISM) or Certified Information Privacy Professional (CIPP) 2. Bachelor’s degree from an accredited... 

    WATI

    Downey, CA
    1 day ago
  • $217.58k - $271.98k

     ...deliver technical cybersecurity consulting and advisory services across a broad spectrum of areas, including threat and vulnerability management, technical security testing, cybersecurity assessments, incident response readiness, and cybersecurity strategy activities.... 
    Internship
    Seasonal work
    Work at office
    Local area
    Flexible hours
    3 days per week

    Grant Thornton

    Los Angeles, CA
    3 days ago
  • $190k

     ...and business superior performance through data, technology and digital. BCG Platinion...  ...Software, Cybersecurity, and Technology Risk Management. Our Tech Advisory and Delivery Chapter...  ...Understanding data protection, data security, and privacy drivers that influence organizations... 
    Work at office

    Boston Consulting Group

    Los Angeles, CA
    4 days ago
  • $20k

     ...ranked Best and Brightest workplace! Impact is a leading national managed services provider, specializing in IT & Cloud, Cybersecurity,...  ...goals in areas such as line of business application optimization, data analytics, AI‑driven insights, and process redesign Own the... 

    Impact Networking

    Culver City, CA
    2 days ago
  • $150k

     ...Assessment (BTA) approach, then translate findings into a clear managed services program (fully managed or co‑managed) aligned to client...  ...direction of the Business Transformation Assessment (BTA): coordinate data collection, validate findings, and develop a prioritized... 

    Impact Networking, LLC.

    Culver City, CA
    18 hours ago
  •  ...Cyber Security Analyst to support mission operations at Los Angeles Air Force Base (LAAFB). You will be responsible for the secure management and accountability of cryptographic materials and COMSEC equipment, with strong knowledge of COMSEC policies and procedures... 

    Vision IT

    Los Angeles, CA
    3 days ago
  • $150k

     ...strategic advisors and technologists. The role involves leading discovery workshops, developing actionable roadmaps, and proposing managed services solutions aligned to client needs. With 7+ years of IT/cybersecurity experience required, candidates should have strong operational... 

    Impact Networking, LLC.

    Culver City, CA
    18 hours ago
  • Arete Associates in Northridge, CA is seeking a full-time Cyber Security Analyst/Information Systems Security Officer. The selected candidate must hold a Top Secret security clearance and will primarily work on classified networks. Responsibilities include performing security...
    Full time
    Flexible hours

    Arete Associates

    Los Angeles, CA
    2 days ago
  • Proofpoint is seeking a qualified candidate in Los Angeles to evaluate and support changes to our Threat Analysis environment. Responsibilities include analyzing needs and creating internal tools while collaborating on threat research. The ideal applicant will have experience...
    Flexible hours

    Proofpoint

    Los Angeles, CA
    3 days ago
  • $87.7k - $164k

     ...consultation and assessment on perceived security threats Maintain, manage, improve and update security incident process and protocol...  ...log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware... 
    Summer holiday
    Local area
    Flexible hours

    Ernst & Young Oman

    Los Angeles, CA
    1 day ago
  • Vision Information Technology Consultants LLC is seeking a Cyber Security Analyst to support Department of Defense operations at Los Angeles Air Force Base. The role involves monitoring, analyzing, and responding to cybersecurity threats while ensuring compliance with security...

    Vision Information Technology Consultants LLC

    Los Angeles, CA
    2 days ago
  •  ...threat vector feed and placing IP and domain blocks. Two (2) years of experience within the last three (3) years maintaining and managing an active directory environment. Two (2) years of experience within the last three (3) years deploying, fine tuning, responding... 

    WATI

    Downey, CA
    1 day ago
  •  ...career professionals to join our Cyber Security team as a Junior Cyber Security Consultant. This role focuses on Identity and Access Management (IAM), specifically federated identity solutions and PingFederate implementations. It offers an excellent opportunity for... 
    Full time
    Remote work
    Work from home

    Guru Schools

    Los Angeles, CA
    3 days ago
  •  ...role supports the protection of sensitive government systems and data in a fast-paced, mission-driven environment. (This Position...  ...integrity and professionalism. If you are passionate about IT asset management, logistics, and ensuring operational success in a DoD... 
    Full time
    Temporary work
    Local area

    Vision Information Technology

    Los Angeles, CA
    3 days ago
  • iQuasar is seeking a mission-driven and detail-oriented Cyber Threat Intelligence (CTI) Analyst to support operations for one of our clients. In this high-impact role, you will be the frontline of technical threat analysis, translating complex intelligence into actionable...

    iQuasar

    Los Angeles, CA
    18 hours ago
  •  ...based evaluations to identify threats such as model manipulation, data leakage, and adversarial attacks, and recommending practical...  ...implementing native cloud security controls, identity and access management, and secure configuration of cloud services. ~ Experience... 
    Work experience placement

    Disney France

    Burbank, CA
    2 days ago
  • $104k - $156k

     ...and reduce manual effort ~ Partner with IT on device management, deployment, and lifecycle security ~ Reduce enterprise...  ...understanding of computer science fundamentals, including algorithms and data structures ~ Experience securing andoperatingmanaged... 
    Remote work

    Relativity

    Los Angeles, CA
    1 day ago
  • $75 - $114.42 per hour

     ...Angeles, CA 90001 US (Primary) Category Information Technology Job Type Full-time Career Level Experienced (Non-Manager) Education Bachelor's Degree Salary Grade $75.00 - $114.42 ( $156,000 to $237,993 YR ) Travel Security Clearance Required... 
    Full time
    Local area

    Cornerstone Concilium Inc

    Los Angeles, CA
    3 days ago
  • $110k - $140k

     ...operational core of our cybersecurity organization, responsible for managing alert triage across our cybersecurity tool stack, coordinating...  ...as core compliance evidence Identify patterns in alert data and surface recurring issues to the InfoSec Engineer for remediation... 
    Permanent employment
    Immediate start

    Varda Space Industries

    El Segundo, CA
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Data Privacy Manager. Be the first to apply!