Privacy, Security, and AI Compliance Specialist
Napster Corp.
Privacy, Security, and AI Compliance Specialist
Napster
Location: Remote - Anywhere in US (CST, EST) or UK
About Napster
Napster is an AI-first platform company. We build and deploy AI agents across consumer, enterprise, and developer products, and we run hardware in public spaces. As the company continues to grow across global markets and expand its technology and product offerings, we are building scalable operational, security, privacy, AI governance, and compliance programs that support the business today and position us for future growth.
We are looking for a Privacy, Security and AI Compliance Specialist to help run and maintain Napster’s privacy, security, AI governance, and compliance framework across our global organization.
The Role
The Privacy, Security and AI Compliance Specialist will be responsible for assisting with implementing, operating, and maintaining Napster’s privacy fundamentals, security, PIMS procedures, incident handling, data mapping, vendor/privacy risk, and AI governance compliance programs across our global operations.
This is a hands-on role for someone who is comfortable taking day-to-day charge of the documentation, and registers behind several compliance programs at once. You will help support and maintain Napster’s Privacy Information Management System (PIMS), Information Security Management System (ISMS), and AI Management System (AIMS), and assist with compliance efforts across ISO 27001, ISO 27701, ISO 42001, SOC 2, and other applicable privacy and security frameworks.
Working under the Operations Department, you’ll work closely with other teams to translate regulatory, contractual, and certification requirements into practical processes that can scale with the company.
Responsibilities
Privacy & Compliance
- Support the operation and maintenance of Napster's Privacy Information Management System (PIMS) and supporting privacy compliance framework, as defined by the program.
- Maintain the documented scope of Napster's privacy and information security management systems across entities, systems, products, and business operations, and flag changes that require a scope decision.
- Maintain data maps, records of processing activities, retention requirements, and data subject request processes across applicable jurisdictions.
- Document and review controller and processor classifications for new and existing controllers and processors as relevant, and the appropriate privacy controls for Napster’s processing activities.
- Conduct privacy reviews and Data Protection Impact Assessments (DPIAs) for new products, features, vendors, and the record of processing activities (ROPA).
- Operate and refine the processes that align Napster's day-to-day operations with applicable privacy, security, regulatory, and contractual requirements.
- Maintain the documented process for the full personal data lifecycle, including collection, use, retention, transfer, return, and secure disposal, end-to-end.
- Assist with the data subject request process, including intake, identity verification, response within statutory deadlines, and auditable record-keeping.
- Maintain PIMS governance documentation, including defined roles and decision rights, documented PIMS objectives, and a tracker showing status against those objectives.
- Compile and report PIMS performance metrics defined by the program as requested.
Certifications & Audit Readiness
- Assist with Napster’s compliance certification and attestation programs, including ISO 27001, ISO 27701, ISO 42001, and SOC 2, along with compliance with data protection legislation.
- Assist with readiness and gap assessments.
- Assist with the maintenance of audit-ready policies, standards, procedures, controls, and supporting documentation.
Source of Truth & Ongoing Operation
- Maintain the register of approved vendors, sub-processors, and tools, including which are approved for which markets, whether a vendor has infrastructure in the required region, and under what data residency and transfer conditions.
- Act as the first point of contact for internal teams on whether a given vendor, tool, or processing activity is approved for a given market or use case, and give a clear answer with alternatives where they exist.
- Maintain the map of how personal data flows across our global operations, and keep it current as vendors and clients change.
AI Governance & Compliance
- Maintain the AI system inventory, covering purpose, data sources, model provenance, and deployment surface for each system.
- Maintain the record of Napster’s role for each AI system, as provider, deployer, or both, together with its risk classification.
- Coordinate AI impact assessments, including fundamental rights assessments where required, and keep the resulting records.
- Maintain the AI regulatory obligation tracker across the EU AI Act, US state AI and automated decision-making laws, and sector-specific AI rules, and translate obligations into requirements for the teams that own them.
- Support AI incident identification, escalation, and regulatory reporting procedures, and maintain the external channel for reporting adverse impacts.
- Maintain the record of approved AI vendors and model providers, including responsible-AI attestations, training-data restrictions, and market limitations.
- Support stakeholders on AI transparency obligations, including agent disclosure, synthetic content marking, and rights relating to automated decision-making.
This role does not cover AI model quality assurance. Testing model behavior, red-teaming, and evaluating model outputs sit with other teams. This role sets and maintains the governance record around those activities.
Privacy, Legal & Contractual Compliance
- Establish and document the lawful basis supporting applicable processing activities.
- Manage the privacy and security requirements associated with Data Processing Agreements (DPAs), Article 28 processor terms, Standard Contractual Clauses (SCCs), international data transfers, and security schedules.
- Partner closely with Legal on regulatory interpretation, contractual privacy and security requirements, breach notification obligations, and negotiated customer or partner agreements.
- Help ensure Napster’s privacy and security practices remain aligned with GDPR, UK GDPR, CCPA/CPRA, and other applicable global privacy requirements.
Risk, Incident & Third-Party
- Operate Napster’s third-party and vendor risk management program, including onboarding assessments, risk tiering, ongoing monitoring, and periodic reassessments.
- Support and maintain privacy and security incident response procedures and documentation.
- Track incident response procedures against applicable regulatory and contractual reporting and notification requirements.
- Oversee enterprise customer and partner security reviews, including security questionnaires, diligence requests, and supporting documentation.
- Identify emerging compliance risks and work with stakeholders to develop practical remediation plans.
What We’re Looking For
- 8+ years of experience in privacy, security compliance, IT audit, GRC, or a related field, including direct responsibility for building or managing a privacy or security compliance program.
- Strong knowledge of security and privacy frameworks, such as ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, NIST Cybersecurity Framework, NIST SP 800-53, and SOC 2 Trust Services Criteria.
- Strong understanding of ISO/IEC 27701 as a standalone Privacy Information Management System standard, and of how a PIMS aligns with an ISO/IEC 27001 ISMS.
- Strong understanding of ISO/IEC 42001 as a standalone AI Management System standard, and of how an AIMS aligns with an ISO/IEC 27001 ISMS.
- Practical, hands-on experience using AI tools, whether at work or independently, with the ability to explain how AI-assisted compliance or analytical work was independently validated against authoritative source material.
- Experience maintaining compliance registers, trackers, and evidence libraries across more than one framework at a time, with the analytical judgment to spot when a record no longer matches reality.
- Hands-on experience operating data subject request workflows and personal data lifecycle controls, including retention, transfer, secure disposal, and privacy program objectives and metrics.
- Working knowledge of global privacy regulations, including GDPR, UK GDPR, and CCPA/CPRA.
- Experience applying lawful basis, controller and processor classifications, international transfer requirements, and other privacy principles to real-world business operations.
- Demonstrated experience working with and scaling ISO, NIST, SOC 2, or similar compliance programs.
- Experience performing risk assessments, internal audits, privacy reviews, and DPIAs.
- Experience reviewing and operationalizing Data Processing Agreements, security schedules, and related privacy and security terms in partnership with Legal.
- Working knowledge of cloud infrastructure and SaaS security controls across AWS, Azure, GCP, or similar environments.
- Experience supporting external audits and certification activities, including evidence collection, fieldwork coordination, and remediation tracking, and working directly with customers, vendors, and internal stakeholders.
- Strong written communication skills with the ability to develop clear, audit-ready documentation.
- Ability to operate independently, manage competing priorities, and drive execution in a fast-moving environment.
Preferred Qualifications
- CIPP/E, CIPP/US, CIPP/C, CIPP/A, CDPO, CIPM, CIPT, CISSP, CISA, CRISC, AIGP, ISO Working knowledge of ISO 27001 / ISO 27001 / ISO 42001 implementation , or similar certification - Lead Implementer or equivalent experience preferred.
- Experience with compliance automation platforms such as Vanta, Drata, or Secureframe.
- Experience implementing or supporting AI governance frameworks, including ISO 42001, the EU AI Act, or the NIST AI Risk Management Framework.
- Experience managing privacy and security compliance across multiple jurisdictions and legal entities.
- Experience supporting EU and Middle East operations.
- Experience responding to enterprise customer security and compliance reviews within a B2B, SaaS, technology, or platform business.
- Analytical or compliance-analysis background, with strong project coordination skills: able to run recurring compliance work across several teams and hold owners to deadlines.
- Experience directly supporting a designated Data Protection Officer (DPO) and Information Security leadership.
Success in This Role
Success in this role means supporting a privacy and security compliance program that is practical, scalable, and embedded into how Napster operates.
You will strengthen visibility across Napster's privacy and security controls, support the certification and attestation efforts led by the program, enhance audit readiness,reduce compliance risk by surfacing gaps early, and execute the repeatable processes that allow the company to expand into new markets, and launch new products without unnecessary operational friction.
In the first year, the priority is centralizing the day-to-day upkeep of documentation, and registers, that currently sit with multiple departments. Some parts of the year will involve assisting with review and audit cycles end to end within the program's calendar; others will be steady maintenance and record-keeping.
Most importantly, you will help scale the compliance needed to support Napster's continued growth.
Why Join Napster?
This is an opportunity to build, not simply maintain.
You will have the ability to shape Napster’s global privacy and security compliance program from the ground up and work directly with teams across Napster.
As Napster expands its global footprint and develops new technology and AI-enabled products, this role will play an important part in creating the governance, controls, and operational infrastructure necessary to support that growth.
If you have wanted more hands-on exposure to AI than a traditional compliance function allows, this is that role. We are an AI-first company, and this work sits close to how our AI products are built, shipped, and governed.
Benefits
- Paid Time-Off: We offer flexible vacation time with 10 company holidays.
- Health Plans: We offer robust medical, dental, and vision plans for you and your dependents. Disability, life insurance, and FSA benefits are also available
- Wellness: Access to Teladoc and an EAP
- Parental Leave: Paid leave
- Retirement Savings: Contribute pretax earnings to our 401(k) Plan
Our Culture
- Impact: Play a crucial role in our growth journey.
- Culture: Join a vibrant team valuing creativity and collaboration.
- Growth: Thrive in a fast-paced, dynamic environment.
- Reward: Enjoy competitive compensation, equity opportunities, and comprehensive benefits.
- Ready to shape our future? Apply now and be part of something extraordinary!
We’re looking for more forward-thinking, collaborative people to be part of our innovation journey and mission to push the boundaries of technology. If you’re ready to help us achieve this vision, we’d love to hear from you! At Napster Corp , we're looking for people who are invigorated by our values and driven to change the world, not those who simply check off boxes.
Napster Corp embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees. We strive to build a company that reflects a global audience.
CCPA Notice for California Job Candidates: Please review our CCPA notice at
$100k - $120k
...people. Virta's Legal team seeks a Privacy & Compliance Specialist to own the day-to-day execution of privacy... ...with Legal, Engineering, Product, Security, and Commercial teams to maintain and... ...Demonstrates a proactive use of AI tools to improve individual output and...SuggestedCurrently hiringWork at officeRemote work- The Compliance Specialist reports to the Director Legal, Compliance, Privacy & Security (“Director”) and has a key role in supporting the Director in implementing the seven elements of an effective compliance and helping promote the Company's vision, mission, and culture...SuggestedContract work
- Sr. Privacy Compliance SpecialistEdible Brands® was launched in 2022 to bring together powerful... ...and geographies. The Privacy Compliance Specialist is a hands-on technical ownership role... ...bridges Legal, Information Security, Engineering, Marketing Operations, and...SuggestedContract workCasual workWork at officeWorldwideMonday to Friday
$62k - $141k
Cyber Compliance SpecialistThe Opportunity:Designs, implements, and manages... ...ensure database and software security. Applies specific functional... ...and procedures including Privacy, NIST, RMF, and FISMASecret... ...and prevent fraud.Candidate AI Usage PolicyAI is a part of our...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ...To support a growing practice, the full-time Privacy and Compliance Specialist will manage privacy operations, oversee compliance projects, and serve... ...privacy impact assessments and data subject request workflows Proactive use of AI tools to improve efficiency and output...SuggestedFull timeRemote work
- ...Supporting the Office of the Chief Privacy Officer, the full-time Senior Privacy Compliance Specialist will manage privacy projects, conduct risk assessments, and... ...provide expert guidance on information privacy and security compliance within the organization. Key...Full timeWork at officeRemote work
$800 per unit
...creative and technical talent with leading AI research labs. Headquartered in San... .... Position: Insurance Regulatory Compliance Specialist Type: Contract Compensation:... ...consumer notices, complaint handling, privacy, reporting, audits, and corrective action...Contract workSummer workImmediate startRemote work$105.4k - $207.8k
Position Summary AI Security Senior ConsultantOur Deloitte Cyber team understands the... ...maturity assessments in cybersecurity, privacy, or governance and developing strategy... ...platforms, governance, risk, and compliance tools, or model risk management systems...Local areaWorldwideVisa sponsorship- US Family Health Plan (PacMed Clinics DBA Pacific Medical Centers) seeks a Compliance Specialist to support the Compliance and Privacy Program, partnering with operational and clinical teams to identify risks, interpret regulations, monitor performance, and drive corrective...
- ...Obtain Public TrustWhat You Will Do:Our consultants on the AI and Data Defense and Security team help clients maximize the value of their data and... ...DevSecOps practices.Apply responsible AI principles, governance, privacy, security, and human-in-the-loop review throughout the AI...Full timeFlexible hours
$135k - $165k
...Ivo is an AI-powered contract review and legal technology company transforming how... ..., negotiate, and manage contracts. Security, privacy, and trust are foundational to our platform... ...a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo...Contract workFlexible hours- About Mistral Mistral provides full-stack AI solutions: from frontier models to... ...and team-spirited. Role summary As a Security Compliance Specialist, you will contribute to the development... ...location, please refer to our Benefits page. Privacy Policy Your privacy matters to us. You...Relocation package
$94.4k - $198.2k
Job Title: Data Scientist - AI/mL SpecialistJob Category: ScienceTime... ...the Department of Homeland Security's Cyber Crimes Center (C3) in... ...that meet rigorous federal compliance standards Contribute to... ...architects, and cybersecurity specialists on cross-functional projectsCommunicate...Contract workWork experience placementImmediate startFlexible hours- Holland & Knight is seeking a Privacy and Compliance Analyst to support firm-wide data protection and privacy initiatives. The role requires familiarity... ..., and third-party risk assessments, with exposure to AI privacy considerations. The position will contribute to risk...
$60 - $70 per hour
...supports the day to day execution of AI governance reviews-from intake and triage... ...coordinating closely with technology, security, data privacy, legal, and business stakeholders. The... ...experience in technology, governance, compliance, risk management, security, business...Hourly payContract workTemporary workFor contractorsWork experience placementWork at office$157.68k - $238.5k
...Samsara is building a brand-new role at the intersection of security engineering and applied AI. This person will be the most AI-forward technologist on... ...genuine candidates. Please see Samsara’s Candidate Privacy Notice for more information.Fraudulent Employment OffersSamsara...Full timeRemote workFlexible hours$100k - $200k
...passionate team dedicated to accomplishing hard things, together.AI Security Engineer (Agentic SOC)Location: McLean, VA | On-site (5 days/... ...a request for reasonable accommodation will be responded to from this email address.Appian's Applicant & Candidate Privacy NoticeWork experience placementLocal areaFlexible hours- ...that will delight our customers.Senior AI Security and Governance EngineerJob Summary:VIAVI... ...on three interconnected pillars: AI compliance and governance, AI security and secure... ...close partnership with Engineering, Legal, Privacy, Product, and Risk teams, and reports...Full timeWork from homeHome office
- ...its competitive advantage.What You’ll Do: We're looking for an AI Security Engineer to design, implement, manage, and support our... ...development from the start, not bolted on afterward.Support data privacy and governance efforts, including PII handling, data lineage,...Full timeLocal area
$117.5k - $234.5k
...on Carrier social media at @Carrier.The AI Security Engineer is responsible for building,... ...monitoring, data protection, governance, and compliance requirementsDevelop technical... ...Date: 25 September 2026Job Applicant's Privacy NoticePlease click on the link to review...Minimum wageFull timeTemporary workLocal areaRemote workVisa sponsorship$147k - $184.8k
...strengths of each geographic location.Position Summary:The AI Security Engineer will be a key member of the “Structure Brain”... ...adversarial attack mitigation.Secure data pipelines and ensure compliance with data privacy regulations (e.g., GDPR, HIPAA).Integrate security best...Contract workWork at officeRemote work- A leading provider of compliance solutions is seeking a Customer Success Representative to engage with clients and ensure the optimal use of AI-powered products. This role includes managing client projects, performing training sessions, and facilitating onboarding. Ideal...
- ...The Artificial Intelligence Security Engineer leads enterprise efforts... ...models, and generative AI deployments. This practitioner... ...implementation security, governance, and privacy evaluations for commercial... ...hosting criteria, and compliance attestations against frameworks...Full time
- ...apply now.We are currently seeking a AI Marketplace & Governance Specialist to join our team in Remote, Texas (... ...-technical users (legal, finance, compliance).About NTT DATANTT DATA is a $30... ...capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and...Work at officeLocal areaRemote workFlexible hours
$100k - $155k
...breaches, and we’ve redefined modern security with the world’s most advanced AI-native platform. We work on... ...The Senior Governance, Risk, and Compliance Specialist is tasked with providing... ...in the context of security, privacy and other enterprise-wide operational...Full timeWork experience placementWork at officeLocal areaRemote work$90 - $110 per hour
...Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors... ...D'Angelo , Larry Summers , and Jack Dorsey . Position: Compliance & Financial Crime Domain Intake — Shape Upcoming Compliance Engagements...Hourly payContract workFor contractorsSummer workRemote work$150k - $275k
...passionate team dedicated to accomplishing hard things, together.Lead AI Security Engineer (Agentic SOC)Location: McLean/Tysons, VA | On-site (5... ...a request for reasonable accommodation will be responded to from this email address.Appian's Applicant & Candidate Privacy NoticeWork experience placementLocal areaFlexible hours$190k - $237.5k
...the entire content lifecycle, secure critical content, and transform... ...workflows with enterprise AI. We help companies thrive in the... ...Infrastructure, Incident Response, Legal, Privacy, and the business functions... .... In accordance with OFCCP compliance, here is the Pay Transparency...Live inWork at officeLocal areaShift work3 days per week$172.78k - $225.72k
...Job:We are seeking a visionary Sr Staff AI Security Engineer to serve as the primary... ...training, fine-tuning, and inference.Azure AI Specialist: Lead the security configuration for... ...policies for responsible AI usage, data privacy, and model risk management.Identity & Data...Full timeFor contractorsWork at officeLocal areaRemote work$170k - $225k
...redefine the intersection of networking and security. At Fortinet, our mission is to safeguard... ...an experienced and innovative Principal AI Security Engineer to join our Corporate... ...role in ensuring the security, safety, and privacy of our AI-driven applications while...Full timeWork experience placementRemote workWorldwide
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Privacy, Security, and AI Compliance Specialist. Be the first to apply!
- global security specialist United States
- sr industrial security specialist United States
- senior security consultant United States
- security clearance specialist United States
- security analyst intern United States
- security specialist United States
- physical security consultant United States
- cloud security consultant United States
- security analyst United States
- security consultant United States




