Privacy Analyst- HQ
Agora · Santa Clara, CA · Posted 2026-08-06
Job description
## What You'll Do ### Privacy Reviews & Compliance - Conduct Privacy Reviews, Data Protection Impact Assessments (DPIAs), and Transfer Impact Assessments (TIAs) for new products, features, internal tools, and AI services. - Evaluate data flows across SDKs, cloud infrastructure, and real-time communications systems, including cross-border data transfers, encryption, and regional processing requirements. ### Customer & Regulatory Support - Manage customer privacy requests, including DPA negotiations, GDPR inquiries, sub-processor reviews, and security/privacy questionnaires. - Own the end-to-end Data Subject Request (DSR) process, ensuring timely and compliant responses. - Support privacy reviews for regulated industries, including HIPAA and COPPA. ### Privacy Operations - Maintain Agora's Record of Processing Activities (RoPA), privacy notices, DPA templates, SCCs, and sub-processor documentation. - Administer and optimize our privacy platform (Ketch), including consent management, cookie compliance, data mapping, DSR workflows, and assessment automation. - Support privacy audits and certifications, including SOC 2 Type II, HIPAA, ISO 27001/27701, ISO/IEC 42001, and regional privacy programs. ### AI Governance - Perform AI compliance reviews covering training data governance, consent mechanisms, model transparency, and regulatory requirements. - Partner with Security and AI Governance teams to evaluate internal AI tools and third-party AI vendors. ### Program Enablement - Monitor evolving global privacy and AI regulations, including GDPR, CCPA/CPRA, LGPD, PIPL, COPPA, the EU AI Act, and emerging U.S. AI regulations. - Develop guidance, training, playbooks, and repeatable processes that improve privacy compliance across the organization. - Track privacy metrics, DSR SLAs, review throughput, and program performance for executive reporting. * * * # Qualifications ### Required - Bachelor's degree or equivalent experience. - 5+ years of experience in privacy, compliance, legal operations, or risk management within a SaaS, cloud, or technology company. - Strong knowledge of GDPR, CCPA/CPRA, LGPD, and modern privacy operations. - Hands-on experience with DPIAs, RoPA, DSRs, DPAs, and vendor privacy assessments. - Ability to understand technical concepts such as data flows, cloud architecture, SDKs, and encryption while effectively partnering with both engineering and legal teams. - Ability to be in the office 3x per week ### Preferred - IAPP certification (CIPP/E, CIPP/US, CIPM, CIPT, or AIGP). - Experience supporting SOC 2 Type II, ISO 27001/27701, ISO/IEC 42001, HIPAA, or similar compliance frameworks. - Experience with AI governance, AI/ML compliance, and emerging AI regulations. - Hands-on experience administering ****Ketch**** (preferred) or comparable platforms such as OneTrust, Securiti, or TrustArc. - Experience supporting global engineering organizations and distributed teams. - Experience with privacy considerations for real-time communications, video, telephony, or media streaming technologies. ****Work Authorization:**** Applicants must be legally authorized to work in the United States at the time of hire. This position is not eligible for current or future employment visa sponsorship.