Vice President, Global Privacy Officer at Sirius XM | NY, US | Rezi

Vice President, Global Privacy Officer at Sirius XM

Vice President, Global Privacy Officer

Sirius XM · NY, US

3 weeks ago

Vice President, Global Privacy Officer

Sirius XM · NY, US

23 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

This dual strategic and legal leadership role seeks a motivated attorney to join the SiriusXM legal department, focusing on cutting-edge privacy issues. The position will define and execute SiriusXM’s global privacy vision across its companies, acting as the senior subject matter expert in privacy and overseeing how personal data is handled by business stakeholders and external parties.

Responsibilities

  • Define, execute and scale the Company’s overarching global privacy vision, governance architecture and privacy risk assessment framework.
  • Lead the Company's Privacy function within the Legal department in the design and execution of the Company’s privacy program, reviews of vendor and partner agreements, privacy impact and risk assessments, and consumer data rights management.
  • Work collaboratively with other members of the legal department, privacy operations consultants and Company personnel to devise, manage and implement privacy program priorities and operational standards for compliance with regulatory and contractual requirements while maximizing business goals and objectives.
  • Set legal and operational policies and standards for the collection, use, sharing, retention, and monetization of consumer personal data.
  • Prepare reports for the Chief Legal Officer, C-suite leaders and Company’s Board of Directors, as applicable, on the status of the Company’s privacy posture, emerging privacy trends in regulation and enforcement and related business impacts, and compliance metrics.
  • Lead the legal response to data security incidents and privacy breaches, serving as the privacy lead on the Incident Response Team and handling regulatory disclosures where required.
  • Develop, publish and maintain corporate transparency through privacy notices, cookie policies, consumer-facing disclosures and consumer rights submission flows.
  • Partner closely with engineering, product and marketing operations stakeholders and leads to embed Privacy by Design methodologies into product development lifecycles and data practices.
  • Provide advice and guidance to data science and analytics teams on privacy-compliant training and deployment of machine and large language learning models, personalization engines and other listener telemetry.
  • Guide marketing and lifecycle teams on compliant practices for personalization, direct marketing, paid marketing and first- and third-party data strategies.
  • Oversee privacy regulatory and contractual compliance in ad sales, direct and programmatic advertising, identity resolution, data clean rooms, and third-party data and ad tech integrations.
  • Lead team members in drafting and negotiations for data processing agreements, partner and vendor data sharing and licensing terms, and privacy audits for vendors, measurement partners, ad networks, data providers and other third-party data sources.
  • Support business stakeholders in ongoing monitoring for compliance with regard to third party agreements.
  • Define and oversee privacy frameworks for collection, use and protection of employee, contractor and candidate personal data worldwide, including in employee operations, cross-border transfers, use of AI in employment decisions, and workplace monitoring.
  • Maintain current knowledge of applicable federal, state and foreign privacy laws and frameworks (e.g., CCPA, CA Delete Act, PIPEDA, GDPR, LGPD), maintain lawful cross-border transfer mechanisms, and monitor advancements in information privacy technologies to ensure organizational adaptation and compliance.
  • Serve as the primary point of contact for data protection authorities, regulatory inquiries, and industry coalitions.
  • Oversee privacy training, information sessions and other communications to increase employee understanding of company privacy policies, data handling practices and procedures and legal obligations.
  • Work with business teams and senior management to ensure awareness of best practices on privacy issues.
  • Develop and assist in the implementation of procedures for vetting and auditing vendors for compliance with the Company's privacy policies and contractual requirements.
  • Represent the Privacy function in senior leadership discussions, vendor/customer meetings, and cross-functional forums where privacy requirements, tradeoffs, and risks must be resolved.
  • Drive measurable improvements in privacy program maturity, incident readiness, vendor governance, compliant product launches, and privacy risk reduction.
  • Manage privacy program resourcing, vendor support, and outside counsel engagement for privacy matters, as applicable.
  • Lead, coach, and develop high-performing teams to foster career growth and professional development.
  • Provide constructive feedback, conduct performance reviews, and guide team members in setting and achieving goals.
  • Build and maintain an inclusive, collaborative team culture that encourages innovation and accountability.
  • Provide hands-on guidance to directors, senior managers, attorneys, paralegals, and privacy professionals to ensure the function operates efficiently and aligns with business goals.

Requirements

  • Must be licensed and in good standing to practice law in New York.
  • A Juris Doctorate from a nationally recognized law school is required.
  • 15 years of legal experience, with 8-10 years of direct privacy law experience, including an depth knowledge of global privacy laws and experience with building, implementing, and maintaining a global privacy program.
  • In-house experience preferred.
  • 8-10 years of people leadership, with a track record of building, coaching, and scaling high-performing teams.
  • Expert knowledge of US, Canadian, European and UK privacy laws and practices.
  • Certified Information Privacy Professional-US (CIPP-US) certification required.
  • CIPP-EU, other certifications strongly preferred.
  • Significant experience managing a team of attorneys, paralegals, privacy professionals, vendors, and outside counsel in support of a corporate privacy function.
  • Excellent analytical and judgement skills.
  • Excellent written and verbal communications skills with the ability to translate complex legal and privacy concepts into actionable requirements for all levels of the organization.
  • Ability to act as a highly effective communicator regarding Company privacy requirements and data practices with vendors, partners, and regulators.
  • Excellent time management skills with the ability to prioritize and multitask and work under shifting deadlines in a fast-paced environment.
  • Ability to work independently and in a team environment.
  • Ability to maintain strong working relationships with demanding internal clients.
  • Ability to remain confident, mature and calm under fire, and to make decisions and pivot quickly and fluidly, thinking practically and be solution-oriented.
  • Experience advising on privacy and data security law and compliance efforts, including the organization and coordination of privacy assessments, corporate policies and processes.
  • Demonstrated knowledge and experience drafting and negotiating complex agreements relating to in-bound and out-bound agreements.
  • In-depth knowledge of cutting edge IT, web, mobile and ad-tech ecosystems and their privacy implications required.
  • Knowledge of automotive technology systems or smart and connected devices strongly preferred.
  • Direct experience advising internal stakeholders on privacy matters related to direct to consumer marketing and advertising as supply, demand, programmatic marketplace and ad tech intermediary.
  • Must have legal right to work in the U.S.

Skills

  • Privacy law
  • Global privacy vision
  • Privacy risk assessment
  • Privacy program design and execution
  • Vendor and partner agreement review
  • Privacy impact assessments
  • Consumer data rights management
  • Regulatory compliance
  • Contractual compliance
  • Data handling policies
  • Data retention policies
  • Data monetization
  • Data security incident response
  • Privacy breach response
  • Regulatory disclosures
  • Privacy notices
  • Cookie policies
  • Consumer-facing disclosures
  • Consumer rights submission flows
  • Privacy by Design methodologies
  • Machine learning privacy
  • Large language model privacy
  • Personalization engines
  • Listener telemetry privacy
  • Direct marketing compliance
  • Paid marketing compliance
  • First-party data strategies
  • Third-party data strategies
  • Ad sales privacy
  • Programmatic advertising privacy
  • Identity resolution privacy
  • Data clean rooms privacy
  • Third-party data integrations
  • Ad tech integrations
  • Data processing agreements
  • Data sharing agreements
  • Data licensing agreements
  • Vendor privacy audits
  • Measurement partner privacy audits
  • Ad network privacy audits
  • Data provider privacy audits
  • Employee data privacy
  • Contractor data privacy
  • Candidate data privacy
  • Cross-border data transfers
  • AI in employment decisions
  • Workplace monitoring privacy
  • CCPA
  • CA Delete Act
  • PIPEDA
  • GDPR
  • LGPD
  • Cross-border transfer mechanisms
  • Information privacy technologies
  • Data protection authority liaison
  • Regulatory inquiry response
  • Industry coalition participation
  • Privacy training development
  • Vendor vetting
  • Vendor auditing
  • Leadership
  • Coaching
  • Team development
  • Performance reviews
  • Goal setting
  • Inclusive team culture
  • Collaborative team culture
  • Innovation
  • Accountability
  • Drafting complex agreements
  • Negotiating complex agreements
  • IT ecosystem privacy
  • Web ecosystem privacy
  • Mobile ecosystem privacy
  • Ad-tech ecosystem privacy
  • Automotive technology systems privacy
  • Smart connected devices privacy
  • Direct to consumer marketing privacy
  • Advertising supply privacy
  • Advertising demand privacy
  • Programmatic marketplace privacy
  • Ad tech intermediary privacy

Location

  • New York City

Work Type

  • Full-time

Experience Level

  • 15 years of legal experience
  • 8-10 years of direct privacy law experience
  • 8-10 years of people leadership

Education Level

  • Juris Doctorate from a nationally recognized law school
  • Licensed and in good standing to practice law in New York
  • Certified Information Privacy Professional-US (CIPP-US)
  • CIPP-EU certification preferred

Salary/Compensations

  • $254,000 to $310,000

Benefits

  • Discretionary short-term incentives
  • Discretionary long-term incentives

About the Company

  • SiriusXM and its brands (Pandora, SiriusXM Media, AdsWizz, Simplecast, and SiriusXM Connect) are leading a new era of audio entertainment and services by delivering the most compelling subscription and ad-supported audio entertainment experience for listeners -- in the car, at home, and anywhere on the go with connected devices.
  • Our vision is to shape the future of audio, where everyone can be effortlessly connected to the voices, stories and music they love wherever they are.
  • This is the place where a diverse group of emerging talent and legends alike come to share authentic and purposeful songs, stories, sounds and insights through some of the best programming and technology in the world.
  • Our critically-acclaimed, industry-leading audio entertainment encompasses music, sports, comedy, news, talk, live events, and podcasting.
  • No matter their individual role, each of our employees plays a vital part in bringing SiriusXM’s vision to life every day.
  • SiriusXM is the leading audio entertainment company in North America, and the premier programmer and platform for subscription and digital advertising-supported audio products.
  • SiriusXM's platforms collectively reach approximately 150 million listeners, the largest digital audio audience across paid and free tiers in North America, and deliver music, sports, talk, news, comedy, entertainment and podcasts.
  • Pandora, a subsidiary of SiriusXM, is the largest ad-supported audio entertainment streaming service in the U.S.
  • SiriusXM's subsidiaries Simplecast and AdsWizz make it a leader in podcast hosting, production, distribution, analytics and monetization.
  • The Company’s advertising sales organization, which operates as SiriusXM Media, leverages its scale, cross-platform sales organization and ad tech capabilities to deliver results for audio creators and advertisers.
  • SiriusXM, through SiriusXM Canada Holdings, Inc., also offers satellite radio and audio entertainment in Canada.
  • In addition to its audio entertainment businesses, SiriusXM offers connected vehicle services to automakers.

Equal Opportunity

  • SiriusXM is an equal opportunity employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, national origin, ancestry, alienage or citizenship status, age, disability or handicap, sex, gender identity, marital status, familial status, veteran status, sexual orientation or any other characteristic protected by applicable federal, state or local laws.