Senior Privacy and Data Governance Risk Program Manager
- linkCopy link
- emailEmail a friend
- Health, dental, vision, life, disability insurance
- Retirement Benefits: 401(k) with company match
- Paid Time Off: 20 days of vacation per year, accruing at a rate of 6.15 hours per pay period for the first five years of employment
- Sick Time: 40 hours/year (increased to 69 hours/year for Seattle) including 5 discretionary sick days per instance
- Maternity Leave (Short-Term Disability + Baby Bonding): 28-30 weeks
- Baby Bonding Leave: 18 weeks
- Holidays: 13 paid days per year
Minimum qualifications:
- Bachelor's degree in a technical field, or equivalent practical experience.
- 8 years of experience in program management.
Preferred qualifications:
- 4 years of experience in Data Privacy, Data Governance, Enterprise Risk Management, or regulatory compliance within the technology sector.
- Proven experience synthesizing complex technical and regulatory data into actionable communications (written and verbal) tailored for executive and board-level audiences.
- Experience with advanced risk assessment methodologies and utilizing enterprise risk management software.
- Deep experience operating within a federated compliance model at a global scale.
- Strong technical depth in data pipelines and data classification with demonstrated AI fluency in streamlining programmatic functions.
About the job
To meet the company’s federated privacy operating model, the Office of Privacy Resilience (OPR), within Core’s Privacy, Safety, and Security (PSS) team, was established to shape and demonstrate privacy at Google. We do this by setting a high bar for privacy and collaborating with Product Areas and partner teams to achieve it. Product Areas look to OPR to design internal standards and controls that embed privacy into products, define clear implementation paths, measure control efficacy, and build accountability for privacy outcomes across the company.
As the Lead Privacy Program and Data Governance Risk Program Manager, you will own and drive the strategic goal, execution, and continuous evolution of the team’s overall Privacy and Data Governance Risk program. In this mission-critical role, you will serve as the central orchestration point for high-stakes initiatives. These responsibilities include managing the annual Privacy and Data Governance Risk Assessment (PDGRA), delivering executive and Board-level risk reporting, and maturing our privacy risk metrics.
Furthermore, you will lead the scaling of the Enterprise Privacy and Data Governance framework across the entire organization. Success in this role requires navigating highly ambiguous environments and partnering deeply with cross-functional leaders in Engineering, Legal, Regulatory Affairs, and Enterprise Risk Management. Through these strategic partnerships, you will proactively identify, communicate, and manage top privacy and data risks.
The Core team builds the technical foundation behind Google’s flagship products. We are owners and advocates for the underlying design elements, developer platforms, product components, and infrastructure at Google. These are the essential building blocks for excellent, safe, and coherent experiences for our users and drive the pace of innovation for every developer. We look across Google’s products to build central solutions, break down technical barriers and strengthen existing systems. As the Core team, we have a mandate and a unique opportunity to impact important technical decisions across the company.
Individual pay is determined by factors including job-related skills, experience, and relevant education or training.US: $192000 - $278000 (USD) + 20% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Direct end-to-end Privacy and Data Governance Risk Assessments (PDGRA) aligned with Google’s Risk Taxonomy and Rating scales. Use AI technologies to automate and streamline these audit-ready, actionable workflows.
- Lead the synthesis, preparation, and delivery of high-quality narrative and metrics-based risk reporting packets for the Board and executive committees.
- Scale the Enterprise Privacy and Data Governance Framework. Translate regulatory policies into governable standards and actionable product and engineering roadmaps.
- Develop robust privacy risk frameworks measuring inherent and residual risks. Partner with Analytics and Engineering to transition from manual registers to automated, telemetry-driven dashboards.
- Serve as the primary liaison across lines of defense to identify process breakdowns, drive consensus, and influence prioritization of risk remediations.
Information collected and processed as part of your Google Careers profile, and any job applications you choose to submit is subject to Google's Applicant and Candidate Privacy Policy.
Google is proud to be an equal opportunity and affirmative action employer. We are committed to building a workforce that is representative of the users we serve, creating a culture of belonging, and providing an equal employment opportunity regardless of race, creed, color, religion, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition (including breastfeeding), expecting or parents-to-be, criminal histories consistent with legal requirements, or any other basis protected by law. See also Google's EEO Policy, Know your rights: workplace discrimination is illegal, Belonging at Google, and How we hire.
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.
Google is a global company and, in order to facilitate efficient collaboration and communication globally, English proficiency is a requirement for all roles unless stated otherwise in the job posting.
To all recruitment agencies: Google does not accept agency resumes. Please do not forward resumes to our jobs alias, Google employees, or any other organization location. Google is not responsible for any fees related to unsolicited resumes.
Equity is granted exclusively and discretionarily by Alphabet Inc. on the basis of an agreement concluded between you and Alphabet Inc. Alphabet Inc. is your sole contractual partner with respect to equity grants. GSU grants are not guaranteed, are discretionary, are subject to approval by the Alphabet Inc. board of directors or its delegate, the terms of the relevant Alphabet Inc. stock plan, and your grant agreement. They have no impact on statutory payments. Current or past grants do not confer an acquired right.