Privacy Operations Lead
AI in this role
Deepgram is the leading platform underpinning the emerging trillion-dollar Voice AI economy, providing real-time APIs for speech-to-text (STT), text-to-speech (TTS), and building production-grade voice agents at scale. More than 200,000 developers and 1,300+ organizations build voice offerings that are ‘Powered by Deepgram’, including Twilio, Cloudflare, Sierra, Decagon, Vapi, Daily, Cresta, Granola, and Jack in the Box. Deepgram’s voice-native foundation models are accessed through cloud APIs or as self-hosted and on-premises software, with unmatched accuracy, low latency, and cost efficiency. Backed by a recent Series C led by leading global investors and strategic partners, Deepgram has processed over 50,000 years of audio and transcribed more than 1 trillion words. There is no organization in the world that understands voice better than Deepgram.
Company Operating RhythmAt Deepgram, we expect an AI-first mindset—AI use and comfort aren’t optional, they’re core to how we operate, innovate, and measure performance.
Every team member who works at Deepgram is expected to actively use and experiment with advanced AI tools, and even build your own into your everyday work. We measure how effectively AI is applied to deliver results, and consistent, creative use of the latest AI capabilities is key to success here. Candidates should be comfortable adopting new models and modes quickly, integrating AI into their workflows, and continuously pushing the boundaries of what these technologies can do.
Additionally, we move at the pace of AI. Change is rapid, and you can expect your day-to-day work to evolve just as quickly. This may not be the right role if you’re not excited to experiment, adapt, think on your feet, and learn constantly, or if you’re seeking something highly prescriptive with a traditional 9-to-5.
The Opportunity
Deepgram is looking for a Privacy Operations Lead to own the operational backbone of our privacy program. Deepgram processes audio — often some of the most sensitive data our customers hold — across several deployment models: hosted with model-improvement opted in, hosted with model-improvement opted out (effectively zero data retention), single-tenant Deepgram Dedicated deployments with regional data residency, and fully self-hosted deployments running in the customer's own environment. Our hosted services run primarily on our own bare-metal infrastructure in colocation datacenters, with AWS used for overflow capacity and a small set of services — so knowing where data actually lives means knowing our datacenters, not just a cloud console.
You will be the person who knows, in operational detail, how data moves through each of those models — and who turns that knowledge into durable artifacts: data flow maps, records of processing, assessment templates, playbooks, and self-service guidance that Legal, Engineering, and Sales Engineering can use without re-deriving the answer every time. You will also be the technical voice in enterprise customer privacy reviews.
This is not a policy-writing job. Roughly half the work is assessment and advisory; the other half is designing and operating the processes and tooling that make our privacy claims repeatable and verifiable. Where verification requires reading code or inspecting infrastructure, you will define what needs to be proven and partner with Security and Engineering to prove it — you are not expected to do that engineering work yourself.
This role reports to the Director of Information Security and works closely with Legal, Engineering, and Solutions/Sales Engineering.
We are open on level. This is a senior individual-contributor role, and we will calibrate title, scope, and compensation to demonstrated experience.
About Deepgram
Deepgram builds foundational voice AI — speech-to-text, text-to-speech, and voice agent infrastructure — used by enterprises and developers to build production voice applications at scale. Our models are trained and served on our own infrastructure, and we offer hosted, dedicated single-tenant, and self-hosted deployment options so customers can meet their own data residency and retention requirements. Learn more at deepgram.com.
Responsibilities
Own customer and prospect privacy risk assessments, DPIAs, and transfer impact assessments end to end. Be the technical voice in customer privacy reviews and vendor due diligence calls.
Build and maintain accurate data flow maps and records of processing across hosted, dedicated, and self-hosted deployments — including which datacenter, region, or cloud each flow touches — and own the process that keeps them accurate as the product changes.
Translate GDPR, UK GDPR, CCPA/CPRA and other US state privacy laws, and emerging AI regulation (EU AI Act, state AI and automated decision-making rules) into concrete requirements that engineering and GTM teams can act on, rather than memos.
Define the privacy requirements for product and infrastructure changes — retention, logging and telemetry, third-party subprocessors, training-data lineage — and drive them to implementation with the owning teams.
Own the operating model for our privacy controls: retention and deletion enforcement, DSAR and deletion workflows, consent and opt-out handling, de-identification and redaction. You specify, instrument, test, and audit; Engineering builds.
Design and run operational auditing and remediation workflows, so drift between what we claim and what we do is caught by process rather than by a customer.
Own the subprocessor and vendor privacy review process — including colocation and infrastructure providers — and the artifacts that support our DPAs and trust center.
Own privacy enablement: playbooks, self-service guidance, and training for Engineering, Support, and Sales Engineering — including what Sales Engineering is and is not allowed to promise.
Partner with Legal on DPAs, SCCs, transfer mechanisms, and the residency commitments we make for dedicated deployments.
Partner with Security so that privacy evidence and security evidence (SOC 2, ISO 27001, PCI DSS) are produced once and reused.
Skills Needed
Substantial experience in privacy operations, legal operations, or technical privacy and compliance — enough that you have run assessments end to end and owned the outcome.
Demonstrated ownership of privacy operational systems at scale: data maps, DSAR workflows, consent management, retention processes, or the tooling behind them.
Technically fluent and unintimidated: you can read an architecture diagram, follow a data flow through datacenter and cloud infrastructure, understand what a log line or a retention setting actually implies, and ask the questions that expose a gap — without needing someone to translate for you.
Practical, applied experience with GDPR and CCPA/CPRA, and a current view of where AI regulation is heading.
Able to hold your own with a Fortune 500 privacy team or DPO without escalating every question.
Clear writer. A large share of this job is producing documents that customers, auditors, and engineers rely on.
Strong bias toward automating and documenting your own work rather than becoming the bottleneck for it.
Comfortable with ambiguity and with making a defensible call when the law is unsettled.
Nice to Have
CIPM, CIPT, CIPP/E, or equivalent certification.
Comfort reading code (Python, Go, Rust, or TypeScript), writing SQL, or scripting your own tooling.
Familiarity with on-premise or colocation infrastructure, containerized (Docker) workloads, and how data residency works outside a single cloud provider; AWS familiarity a plus.
Experience with ML/AI data pipelines and training-data governance.
Privacy work in a hybrid model — multi-tenant SaaS alongside self-hosted or on-premise deployments.
Exposure to formal audits: SOC 2, ISO 27001, HIPAA, PCI DSS.
Notice: We're aware of individuals impersonating Deepgram recruiters. All legitimate Deepgram recruiting communication comes from an @deepgram.com email address. If you've received a message claiming to be Deepgram, please forward it to careers@deepgram.com.
How we rate this
Privacy Operations Lead at Deepgram rates 43 out of 100 for how much of the daily work is AI. That makes it Uses AI (AI Level 2 of 4). The level is about AI in the job, not seniority.
Uses AI. An ordinary role that requires AI tools.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- What have you built with speech recognition or text-to-speech, and where did it break?
- Walk me through how you've used Sierra in your day-to-day work.
- What are the limits of Decagon that you've run into, and how did you work around them?
- This role expects you to use AI tools as part of the job. Which ones have you used, and for what?
- Tell me about a time an AI tool got something wrong. How did you catch it?
Adapt your resume
- List these exact terms on your resume: Speech, Sierra, and Decagon. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Put the AI tool in a bullet point about what you did, not just in a skills list — this role treats it as a required part of the job.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote AI jobs (Uses AI ●●○○ or higher) by email
One email a week with the new remote AI jobs (Uses AI ●●○○ or higher), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Operations roles that use AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step