Director, Compliance - Deputy Privacy Officer
MSCCN - Indianapolis, IN
Apply NowJob Description
When you join Sallie Mae, you become a champion for all students. Weu2019re on a mission to power confidence as students begin their unique journey. To help them plan their higher education, successfully finish, and prepare for life after school. To help them Start smart. Learn big. Students need guidance navigating this important time in their life. They need someone who acknowledges that their education path is unique. They need a partner willing to evolve and not only meet but surpass their expectations. Weu2019re changing. Because students need a better way. Weu2019re looking for people who are excited to drive this transformation. To break barriers and think of new ways to adapt, help, and create better experiences for studentsu2014and for each other. This is where diverse backgrounds, beliefs, and perspectives matter. Itu2019s where youu2019re empowered to bring your authentic self to work. Feeling your best allows you to do your best. Our benefits take care of the whole youu2014from physical and mental to financial and professional. Youu2019ll get opportunities to further your education and career, support for you and your family (including your pets), paid time off to volunteer for the things that matter to you, and more. Weu2019re obsessed with impact and making a real difference. For us, that means putting relationships first, asking u201cwhy not?u201d when tackling challenges, and continuously learning new skills. Come do more than join something, change something. For students, for future generations, for the future of education. What You'll Contribute This position will report to the Vice President, Privacy Officer and Fair & Responsible Banking Officer. The Director, Privacy Compliance, operates in a deputy privacy officer capacity, supporting all aspects of the Privacy Program and requires the Director to not only fulfill oversight of the program but perform detailed daily tasks to monitor the health of the program. The Privacy Director will lead enterprise privacy risk management across products, marketing/ad-tech, operations, and third parties. This role designs and executes the privacy program; oversees compliance with evolving state consumer privacy laws; ensures adherence to federal financial privacy obligations (e.g., GLBA/Reg P, FCRA); and orchestrates privacy incident response in partnership with Corporate Security and Legal. The Director will establish policy, perform risk assessments, advise on business initiatives (including digital marketing technologies), and deliver reporting to senior leadership and governance committees. What You'll Do Ad-Tech Governance & Marketing Privacy + Set enterprise standards for cookies, pixels, SDKs, tag managers, advertising IDs, consent banners, and cross-site tracking; implement controls to limit profiling/targeting of minors and sensitive categories. + Evaluate ad-tech stacks (e.g., CDP/DMP, clean rooms, measurement partners) for lawful bases, consent preferences (opt-in/opt-out), and data minimization; drive vendor due diligence and contractual controls (DPA, SCCs/appropriate safeguards). + Partner with Marketing, Digital, Data, and Engineering to design consent management, accurate preference signaling, and compliant audience creation/activation; lead periodic audits of trackers and SDKs. State and Federal Privacy Law Compliance + Build and maintain a multi-state compliance program covering consumer rights (access, deletion, correction, portability), opt-out rights (sale/share/targeted advertising), and risk assessments (DPIAs) as applicable. + Monitor legislative changes; translate new requirements into policies, standards, and implementation roadmaps for business teams. + Own program controls for GLBA/Reg P, Interagency Security Guidelines, and FCRA touchpoints (e.g., permissible purpose, adverse action data handling); align notices with model form requirements and internal policy governance. + Partner with Product, Servicing, and Vendor Management to ensure appropriate use and sharing of NPI/PII, including affiliate sharing boundaries and marketing limits. Policy, Training, Testing & Monitoring + Develop and maintain privacy policies, procedures, and standards; implement training and awareness programs tailored to various business teams. + Design testing/monitoring plans and dashboards; prepare metrics for executives and governance committees (e.g., DSAR SLAs, opt-out rates, ad-tech audit findings, incident trends). Risk & Advisory for Products and Change Management + Embed privacy by design in product lifecycle (requirements, design reviews); provide business requirements for projects that involve consumer data. + Conduct DPIAs/PIAs and vendor assessments; advise on data retention, minimization, and de-identification. _The above information is intended to describe the general nature and level of work performed by employees assigned to this job; it is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications required of employees in this role._ What you have Minimum: Indicate minimum education, skills and experience required. + 7+ years of privacy experience in financial services, with hands-on GLBA/Reg P program responsibility and demonstrated familiarity with FCRA. + Deep expertise in ad-tech privacy (cookies/pixels/SDKs, consent frameworks, audience targeting, clean rooms) and practical implementation of consent and opt-out controls. + Proven leadership of privacy incident response, including cross-functional coordination with SOC and Legal, regulatory notifications, and customer communications. + Strong working knowledge of U.S. state privacy laws (e.g., CCPA/CPRA and other comprehensive state laws) and experience operationalizing consumer rights. + Ability to translate law/regulation into technical and process requirements; experience guiding engineering and marketing teams through compliant implementations. + Excellent communication, stakeholder management, and governance reporting skills; experience preparing materials for senior leadership/committees. Preferred education, skills, and experience. + Experience with privacy tooling (consent management platforms, DSAR orchestration, tag governance, data mapping/records of processing). + Background in financial-sector controls (FFIEC/Interagency security guidelines) and privacy testing/monitoring programs. + Industry certifications (e.g., CIPP/US, CIPM, CIPT) and familiarity with advertising standards and trust frameworks. The Americans with Disabilities Act _The Americans with Disabilities Act of 1990 (ADA) prohibits discrimination by employers, in compensation and employment opportunities, against qualified individuals with disabilities who, with or without reasonable accommodation, can perform the u201cessential functionsu201d of a job. A function may be essential for any of several reasons, including: the job exists to perform that function, the employee holding the job was hired for his/her expertise in performing the function, or only a limited number of employees are available to perform that function._ Feeling your best helps you do your best: Our benefits take care of the whole youu2014so you can build your work around your life (not the other way around). + Competitive base salaries + Bonus incentives + Generous PTO, Floating Holidays and 12 Federal Holidays observed + Support for financial-well-being and retirement 401k with employer match + Comprehensive medical, dental, vision, hospital indemnity, critical illness, pet insurance and more + Employer paid short-term/long-term disability and basic life insurance + Flexible hybrid working arrangements. + Paid parental leave and adoption reimbursement programs + Free access to on-site staffed fitness centers (in Delaware) and gym subsidy (for locations outside Delaware) + Confidential counseling support (EAP), Health Advocacy services and Wellness program with financial incentives + Tuition Reimbursement and Family Scholarship Programs + Career development and training opportunities Not the right fit? Let us know you're interested in a future opportunity by clicking _Introduce Yourself_ in the top-right corner of the page or create an account to set up email alerts as new job postings become available that meet your interest Sallie Mae is proud to be an equal opportunity (EEO) employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, sexual orientation, national origin, age, genetic information, gender identity, disability, Veteran status or any other characteristic protected by federal, state or local law. Click here ( to view the U.S. Pay Transparency Policy, here ( for federal job applicant notices, and here ( to view the California Employee Privacy Notice. Reasonable accommodations are available for applicants with disabilities in all phases of the application and employment process. To request an accommodation please call (855) 756-2007 and choose option 9. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.Sallie Mae is proud to be an equal opportunity (EEO) employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender, sexual orientation, national origin, age, genetic information, gender identity, disability, Veteran status or any other characteristic protected by federal, state or local law. If you'd like more information about your EEO rights as an applicant, please click Click to view the U.S. Pay Transparency Policy.
Created: 2026-03-02