Hippo70
Data Privacy, Cybersecurity & AI Compliance Manager
Austin, Texas, United States · Dallas, Texas, United States · Morristown, New Jersey, United States
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.7M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- US
- Work mode
- On-site / unstated
- First seen by hirly
- 5 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Title : Data Privacy, Cybersecurity & AI Compliance Manager
Location : Austin, TX / Dallas, TX / Morristown, NJ (Hybrid)
Reporting to : Sr. Enterprise Compliance Director
About Hippo:
Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us. We use technology and data to help our customers stay ahead of problems and protect what matters most.
Today, that same tech-native approach powers our work beyond homeowners. Hippo operates as a diversified carrier platform, partnering with MGAs to deliver tailored program solutions that help them grow and deliver better customer experiences. Behind that work is a team that values ownership, curiosity, collaboration, and continuous improvement.
If you're energized by building what's next, we'd love to meet you.
About You:
You are a compliance professional who lives at the intersection of data privacy, cybersecurity, and AI governance. You're not necessarily an attorney, but you know how to translate complex regulatory requirements into practical, operational compliance programs, and you know when an issue needs to go to Legal for interpretation or sign-off. You've built or matured compliance programs against frameworks like the CCPA/CPRA and other state privacy laws, the TCPA and related marketing rules, the NYDFS Cybersecurity Regulation (23 NYCRR 500), the NAIC Insurance Data Security Model Law, and emerging AI regulations (e.g., Colorado AI Act, EU AI Act, NAIC AI model bulletins). You're as comfortable running day-to-day privacy operations, working a live security incident alongside InfoSec, or writing a quarterly report for a board committee as you are designing the program those activities live in. Insurance industry experience is a strong plus, since you understand the regulatory overlay carriers and producers face beyond standard corporate compliance. You're detail-oriented, comfortable managing multiple regulatory threads at once, and skilled at partnering across Legal, Security, Engineering, Marketing, and the business to keep Hippo ahead of a fast-moving regulatory landscape.
What You'll Do:
Privacy Program Build & Ownership: Design, build, and run Hippo's enterprise data privacy compliance program, maturing it from today's operational footing into a documented, auditable program: governance and accountability structure, data inventory and records of processing, privacy impact assessment process, policy framework, program metrics, and a regulatory change management process covering CCPA/CPRA, other state privacy laws, and insurance-specific privacy requirements (e.g., GLBA and state insurance privacy laws)
Privacy Operations & Consumer Rights: Own Hippo's privacy mailbox and consumer rights request process end to end: intake, verification, tracking, and timely response to access, deletion, correction, and opt-out requests, with documentation sufficient to withstand regulatory scrutiny
Marketing & Advertising Compliance: Own compliance for marketing and outreach channels, including TCPA/telemarketing and SMS consent requirements (CTIA messaging standards, consent capture and logging, opt-out handling), CAN-SPAM, and website tracking technologies (cookies, pixels, session replay) and consent management; partner with Marketing and Growth teams on campaign and disclosure review
Cybersecurity Regulatory Compliance: Support compliance with insurance-specific cybersecurity regulations (NYDFS 23 NYCRR 500, NAIC Insurance Data Security Model Law and state adoptions) and general frameworks (e.g., NIST); support annual certifications, risk assessments, and regulatory exams and audits, and maintain required documentation
Cyber Event Handling: Partner with Information Security on the triage, investigation, containment, and resolution of cyber events; own the compliance workstream for each event, including documentation, materiality and notification analysis support (state breach statutes, NYDFS 72-hour reporting), and remediation tracking, escalating legal determinations to counsel
AI Governance & Compliance: Build and maintain Hippo's AI compliance framework, including use case intake, risk assessment, inventory, and monitoring for AI/ML systems across the business; track state, federal, and international AI regulation relevant to insurance (algorithmic accountability, AI in underwriting, claims, and pricing, model governance requirements)
Vendor & Third-Party Risk: Conduct privacy and data-protection reviews of vendors and third-party service providers, support the data processing agreement process with Legal, and partner with InfoSec on third-party security diligence, including NYDFS Section 500.11 TPSP requirements
Policies, Standards & Training: Draft, maintain, and operationalize internal policies, standards, and procedures for data privacy, cybersecurity, and AI use, and develop and deliver company-wide training and awareness on those policies, in coordination with the Sr. Enterprise Compliance Director and Legal
Regulatory Liaison Support: Serve as a day-to-day point of contact for regulatory inquiries, exams, and audits touching privacy, cyber, and AI, coordinating responses and escalating legal interpretation questions to attorney oversight
Cross-Functional Partnership: Work closely with Legal, Information Security, Engineering, Marketing, and business units to embed privacy, security, and AI compliance requirements into products, processes, and vendor relationships
Must Haves:
5+ years of experience in data privacy, cybersecurity, and/or AI governance compliance within a regulated industry, including hands-on operational experience (consumer rights requests, incident response, marketing compliance), not just policy work
Bachelor's degree; one or more relevant certifications strongly preferred: CIPP/US, CIPM, or CIPT (IAPP privacy certifications), AIGP (IAPP Artificial Intelligence Governance Professional), CISSP, CISM, CRISC, or CDPSE
Demonstrated experience building or significantly maturing a privacy or compliance program, not solely running an established one
Working knowledge of key privacy, marketing, and cybersecurity regulatory frameworks (CCPA/CPRA and other state privacy laws, TCPA, GLBA, NYDFS 23 NYCRR 500, NAIC Insurance Data Security Model Law)
Familiarity with the emerging AI regulatory landscape and how it applies to insurance use cases (underwriting, claims, pricing, customer service)
Experience supporting security incident response and breach notification analysis in partnership with information security and legal teams
Strong written communication skills, including experience preparing reporting for senior management, board, or committee audiences
Experienced working in close partnership with legal counsel and knows when to escalate for legal interpretation
Strong program and project management skills; able to manage multiple regulatory workstreams simultaneously
Insurance industry experience strongly preferred (P&C a plus)
Technical aptitude and the ability to quickly learn new technologies and platforms (privacy management, consent management, and GRC tooling a plus)
Nice to Haves:
Insurance industry experience strongly preferred (P&C a plus)
Benefits and Perks:
Hippo treats its team members with the same level of dedication and care as we do our customers, which is why we’re fortunate to provide all of our Hippos with:
Healthy Hippos Benefits - Multiple medical plans to choose from and 100% employer covered dental & vision plans for our team members and their families. We also offer a 401(k)-retirement plan, short & long-term disability, employer-paid life insurance, Flexible Spending Accounts (FSA) for health and dependent care, and an Employee Assistance Program (EAP)
Equity - This position is eligible for equity compensation
Training and Career Growth - Training and internal career growth oppor
Listed on hirly, a job board. hirly is not the employer: Hippo70 is hiring for this role.
Similar jobs
- Data Privacy & Governance ManagerHormel Foods Family of Companies · Austin, MN, United StatesFirst seen 9d ago
- Data Privacy LeadEquifax · USA - Georgia - Alpharetta - 30005First seen 2d ago
- Lead Data Privacy EngineerCvshealth · Work At Home-IllinoisFirst seen 4d ago
- GRC, Data Privacy & Technical Cybersecurity SME - Senior ManagerCfgi · United StatesFirst seen 6d ago
- Data Privacy Delivery LeadThehartford · 4 LocationsFirst seen 9d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job