Director, Privacy Exam and Audit
What you'll need to apply
What this employer's standard application typically asks
About this role
Employer-provided description, formatted for easier reading.
The global privacy regulatory landscape is not static, and the product and technical landscape at Meta changes multiple times daily to continue to meet and exceed the needs of the billions of people on our platforms. The Director of the Privacy Exam and Audit team works at the center of privacy regulation, legal, business, product, and engineering to put our users' privacy at the center of everything we do.
The Privacy Exam and Audit program is part of Meta's Regulatory Compliance Programs organization and establishes, diagnoses, improves, and manages compliance for better user outcomes and operational effectiveness — while providing visibility into the state of compliance at every step along the way.
The team is responsible for creating, maintaining, and improving Meta's company-wide privacy compliance and audit operations to improve the reliability and maturity of our privacy practices.
We are looking for a seasoned leader who brings operational scale and deep privacy compliance and audit expertise to lead and develop an industry-leading privacy program. Someone who shares our passion for tackling privacy complexities head-on, to help design and build continuous operational compliance practices at massive scale while representing our users and their privacy at the forefront of everything we do.
In this role, you will create and improve company-wide operational processes to establish, measure, and improve privacy practices and compliance measures, execute testing, and report on the state of compliance.
This role is a trusted partner to product, business, legal, and engineering teams across the company, developing deep insights and driving improvements into the mechanics of how teams incorporate compliance and privacy-by-design into their operations and product life cycles.
This role is also Meta's face to the outside: the Director owns the day-to-day relationship with our external auditors, independent assessors, and regulators — managing their requests, defending our compliance position, and building the credibility that makes that position stick.
Success is defined as much by influence as by ownership: the Director translates engineering and product reality into a defensible compliance position, and must be equally credible in front of a regulator, an external assessor, a Board committee, and an engineering leader whose roadmap they are trying to shape.
Responsibilities
- Define, refine, and scale company-wide privacy compliance operating processes (i.e.
- privacy control testing, issue management, change management, certification).
- Design, implement, and maintain scalable compliance operations with a well-documented roadmap, goals, and objectives.
- Develop and improve testing procedures to measure and improve the effectiveness of privacy controls and safeguards.
- Develop and manage KPIs to drive continuous improvement to the compliance operating model.
- Develop long-term objectives for how we will evolve the privacy program operating model while delivering on immediate priorities.
- Build, lead, and develop a high-performing team, including managers, senior individual contributors, and contingent workforce.
- Provide guidance to product, business, and engineering teams on complying with the Privacy Program and its day-to-day objectives.
- Become a trusted partner, working and influencing cross-functionally with leadership, engineering, product, and business teams — building a deep understanding of how their teams work, their needs, and how privacy compliance can be operationalized into their teams.
- Evaluate, evolve, and create program controls and protocols working with legal and privacy product teams.
- Own accountability for regulated deliverables with fixed external deadlines, and represent the state of privacy compliance to executive leadership and Board committees.
- Own and manage the relationship with external auditors, independent assessors, and regulators — serving as the primary point of contact, negotiating scope and timelines, and ensuring Meta responds accurately, consistently, and on time.
- Prepare and defend Meta's privacy compliance position in external examinations and assessments, including responding to findings and observations, agreeing remediation commitments, and tracking them through to closure.
- Coordinate internally ahead of external engagement — aligning Legal, product, and engineering stakeholders on messaging, preparing witnesses and subject matter experts, and ensuring a single coherent narrative reaches the auditor or regulator.
- Anticipate bottlenecks, provide escalation management, and ensure user privacy is not compromised.
- Drive the strategy for automation and AI that scales testing and monitoring throughput without compromising defensibility.
Qualifications
- 15+ years of product operations, program management, compliance, or IT experience
- 15+ years of experience delivering technical programs or products from inception to delivery across organizations
- Experience managing and developing teams, including managing managers or senior individual contributors
- Demonstrated experience managing relationships with external auditors, independent assessors, or regulators, including owning information requests and presenting directly to external parties
- Bachelor's or Master's degree in a related discipline or equivalent practical experience Experience designing, implementing, and maintaining scalable compliance operations
- Experience influencing stakeholders and engineers
- Proven track record of delivering organizational transformational change
- Design-thinking process improvement experience, leveraging creativity and structure to solve complex problems while putting the user first
- Experience working in a technical environment
- Cross-group collaboration experience
- Experience in end-to-end lifecycle creation and management
- Familiarity with various privacy and data protection legislation
- Experience delivering assessments, evidence, or reporting against an external regulatory order, assessor, or certification regime
- Experience operating under a consent order, regulatory settlement, or similar sustained external oversight regime
- Experience managing a formal regulatory examination or independent third-party assessment cycle end-to-end
- Prior experience in an external audit, assessment, or regulatory role (e.g. Big 4, supervisory authority)
- Experience building compliance or risk assessment capability for AI systems
- Relevant certifications (CIPP, CIPM, CIPT, CRISC, CISA)