- Location
- AT - Vienna, Austria
- Type
- Full-time
- Department
- Administration
- Seniority
- Director
- Experience
- 10+ years
- Source
- Workday
Description
Why This Role Exists
Privacy, data protection, and responsible data governance are critical to customer trust, business growth, and responsible innovation. As Director, Privacy, you will lead Tricentis' global privacy program, serve as the company’s Data Protection Officer, and translate complex privacy and data protection obligations into practical operating models.
This role reports to the Chief Legal Officer. This is an operational legal leadership role. You will not only interpret requirements; you will ensure the right governance, follow-through, controls, and accountability are in place across the business. You will partner closely with Legal, Security, Product, Engineering, GRC and the CIO organization as Tricentis strengthens privacy governance, AI governance, and enterprise risk management.
What You'll Own
- Lead Tricentis' global privacy program as an operational legal leader who turns privacy requirements into practical privacy governance frameworks, processes, operating procedures and controls.
- Serve as Data Protection Officer for Europe-based privacy obligations, including GDPR, regulatory engagement, privacy risk oversight, and cross-border data protection requirements.
- Monitor and interpret evolving global privacy, data protection, and AI laws and regulations (e.g., GDPR, e-Privacy Directive, CCPA/CPRA, PIPEDA, PDPA, the Australian Privacy Act, and the EU AI Act and other emerging AI regulatory frameworks), ensure timely operationalization of privacy and data protection requirements across the business.
- Advise senior leadership on privacy risks, mitigation strategies, and regulatory obligations, and lead privacy participation in cross-functional risk governance forums across Legal, Security, Product, Engineering, GRC, and executive stakeholders.
- Support the organization’s ISO/IEC 27701 privacy management program, including supporting GRC on audit and certification activities, and driving privacy-related remediation efforts and ongoing improvements.
- Develop and maintain data protection provisions, addendums and standards for global contract templates, playbooks, compliance documents and training and enablement resources for consistent, scalable global contracting.
- Advise the commercial contracting team on privacy and data protection provisions in customer and partner agreements, balancing legal and regulatory requirements with commercial objectives.
- Advise Sales, Professional Services, Marketing, and Go-to-Market teams on designing and executing commercial activities and service delivery in compliance with applicable privacy and data protection laws.
- Partner with Legal, Security, Product, Engineering, Procurement, Go-to-Market teams, GRC, and the CIO organization to embed privacy into product, commercial, operational, and AI governance decisions.
- Partner with the IP & Product Counsel to integrate privacy-by-design into product development and address cross-border regulatory challenges.
- Partner with the GRC on AI governance program to advise on and support operationalization of AI regulatory requirements.
- Serve as the Privacy representative on the Technology Oversight Board and partner with Procurement to ensure purchases include appropriate data protection terms and are reviewed for privacy risk.
- Partner with Product Security and Security teams on incident response activities and ensure compliance with global breach notification requirements across jurisdictions.
- Establish and deliver privacy training and awareness programs that build privacy accountability and a strong privacy culture across the organization.
- Develop and lead a high-performing global privacy team while increasing privacy awareness and accountability across the organization.
Challenges You'll Help Solve
- Keeping pace with evolving global privacy regulations while maintaining business agility and operational efficiency.
- Supporting AI adoption with practical privacy guidance, clear legal interpretation, defensible controls, and partnership with the AI governance function.
- Creating consistent privacy practices across multiple regions, business functions, and technology environments.
- Reducing privacy and regulatory risk while enabling customer, partner, and employee trust.
- Moving privacy from advisory intent to operational reality, where decisions are documented, owners are clear, controls work, and follow-through happens.
- Clarifying how privacy, AI governance, GRC, Legal, Security, Product, and Engineering work together when emerging risks affect customers, products, data use, or regulatory commitments.
Skills for Success
Required Skills
- Operational Privacy Leadership: Demonstrated ability to design, implement, and improve enterprise privacy programs where policies, controls, owners, workflows, evidence, and follow-through are clear.
- Privacy Regulatory Expertise: Deep knowledge of global privacy frameworks, including GDPR, e-Privacy requirements, CCPA/CPRA, PIPEDA, PDPA, the Australian Privacy Act, UK GDPR, and AI-related privacy obligations, with the ability to apply them in practical business environments.
- Privacy Governance and Compliance Programs: Experience supporting ISO/IEC 27701 or comparable privacy management frameworks, including audits, certification, controls, remediation efforts, and continuous improvement initiatives.
- Data Protection Officer Capability: Experience serving as a DPO or performing equivalent responsibilities involving European privacy requirements, regulatory engagement, compliance oversight, and privacy risk management.
- Commercial Contracting and Data Protection: Ability to advise on DPAs, privacy provisions, customer commitments, and commercial agreements while balancing legal requirements with business goals.
- Cross-Functional Influence: Demonstrated success partnering with business, product, security, procurement, and go-to-market teams to drive enterprise-wide outcomes.
- AI Governance Partnership: Ability to advise on privacy implications of AI systems, data use, agent governance, technical controls, and escalation paths while partnering with GRC and other AI governance stakeholders.
- Privacy Operations and Technology: Experience using OneTrust or comparable privacy management platforms to manage operational privacy processes.
- Leadership and Communication: Ability to explain complex privacy concepts to diverse audiences, influence senior stakeholders, and lead teams through change.
Preferred Skills
- Experience supporting AI governance, AI agent governance, responsible data use, technical control review, or emerging technology risk programs.
- Experience partnering with product organizations on privacy-by-design initiatives.
- Knowledge of cross-border data transfer requirements, European privacy expectations, and global data governance practices.
- Background as a privacy attorney or operational privacy leader who has worked closely with technical, engineering, security, or data governance teams.
- Experience supporting incident response programs and regulatory breach notification requirements.
- Relevant privacy certifications or credentials.
Qualifications
- Qualified to practice law in EU member state.
- IAPP certification (e.g., CIPP/E, CIPP/US, CIPM).
- 10+ years of experience in privacy, data protection, and compliance, with 5+ years in-house at a global software company.
Success in Your First Year
First 90 Days
- Build relationships with key stakeholders across Legal, Security, Product, Engineering, GRC, Procurement, and Go-to-Market functions.
- Assess the current privacy program, AI governance touchpoints, DPO obligations, OneTrust workflows, DSAR processes, and priority risk areas.
- Establish a roadmap for privacy governance, risk committee participation, compliance initiatives, operational improvements, and cross-functional decision accountability.
Six Months
- Advance key privacy initiatives, including governance improvements, DPO operating model clarity, privacy program maturity, and AI governance partnership routines.
- Strengthen cross-functional privacy processes related to contracting, procurement, product development, engineering, privacy operations, and risk escalation.
- Improve visibility of privacy risks, metrics, and program performance for leadership stakeholders.
Twelve Months
- Demonstrate measurable progress in privacy program maturity, governance effectiveness, and operational performance.
- Successfully support ISO/IEC 27701 objectives and continuous improvement efforts.
- Establish a scalable privacy function that enables business growth, regulatory compliance, responsible AI adoption, and stronger customer trust.
Why Join
- Lead a strategically important function with enterprise-wide visibility and impact.
- Step into a role where operational execution matters as much as legal expertise.
- Influence business decisions, product innovation, customer trust, and responsible data practices.
- Partner with senior leaders across Legal, Product, Security, and commercial functions.
- Help shape how privacy, AI governance, GRC, and responsible technology adoption work together in a global enterprise software company.
- Build and grow a global privacy capability that supports a rapidly evolving business environment.
We are under a legal obligation in Austria to indicate the minimum salary, which is 84 826 EUR gross per year for this position, according to the IT collective agreement. However, our attractive compensation packages follow current market salaries and can therefore be significantly above the indicated minimum salary.
Wir sind in Österreich gesetzlich verpflichtet, das Mindestgehalt anzugeben, welches laut IT-Kollektivvertrag für diese Position 84 826 EUR brutto pro Jahr beträgt. Unsere attraktiven Vergütungspakete orientieren sich an den aktuellen Marktgehältern und können daher deutlich über dem angegebenen Mindestgehalt liegen.
Tricentis is proud to be an equal opportunity workplace. Qualified applicants will receive consideration for employment without regard to race, color, ethnicity, gender, religious affiliation, age, sexual orientation, socioeconomic status, or physical and mental disability and other statuses protected by law.
Global Sanctions Compliance
We comply with all applicable global sanctions and export control laws. Candidates must not be listed on any government restricted party lists (including OFAC SDN List and U.S. Commerce Department restricted lists) and must certify that their employment would not violate any sanctions or export control regulations. Candidates must notify us of any changes to their status during the application process or subsequent employment.