Data Privacy, Cybersecurity & AI Compliance Manager

Posted 2 Days Ago
Be an Early Applicant
3 Locations
In-Office
120K-180K Annually
Senior level
Insurance
Hippo is an insurtech (Unicorn!) start-up based in San Jose with operations in Austin, Texas.
The Role
Build and manage enterprise privacy, cybersecurity, and AI compliance programs in a regulated insurance environment. Responsibilities include consumer rights operations, marketing and consent compliance, cyber incident compliance support, AI governance, vendor risk reviews, policies, training, regulatory exams, audits, and board reporting. The role partners closely with Legal, Information Security, Engineering, Marketing, and business teams while managing multiple regulatory workstreams.
Summary Generated by Built In

Title:  Data Privacy, Cybersecurity & AI Compliance Manager

Location: Austin, TX / Dallas, TX / Morristown, NJ (Hybrid) 

Reporting to: Sr. Enterprise Compliance Director  

About Hippo: 

Hippo was built on a promise: make homeownership effortless. Nearly a decade later, that mission still drives us. We use technology and data to help our customers stay ahead of problems and protect what matters most.   

Today, that same tech-native approach powers our work beyond homeowners. Hippo operates as a diversified carrier platform, partnering with MGAs to deliver tailored program solutions that help them grow and deliver better customer experiences. Behind that work is a team that values ownership, curiosity, collaboration, and continuous improvement.  

If you're energized by building what's next, we'd love to meet you.  

About You: 

You are a compliance professional who lives at the intersection of data privacy, cybersecurity, and AI governance. You're not necessarily an attorney, but you know how to translate complex regulatory requirements into practical, operational compliance programs, and you know when an issue needs to go to Legal for interpretation or sign-off. You've built or matured compliance programs against frameworks like the CCPA/CPRA and other state privacy laws, the TCPA and related marketing rules, the NYDFS Cybersecurity Regulation (23 NYCRR 500), the NAIC Insurance Data Security Model Law, and emerging AI regulations (e.g., Colorado AI Act, EU AI Act, NAIC AI model bulletins). You're as comfortable running day-to-day privacy operations, working a live security incident alongside InfoSec, or writing a quarterly report for a board committee as you are designing the program those activities live in. Insurance industry experience is a strong plus, since you understand the regulatory overlay carriers and producers face beyond standard corporate compliance. You're detail-oriented, comfortable managing multiple regulatory threads at once, and skilled at partnering across Legal, Security, Engineering, Marketing, and the business to keep Hippo ahead of a fast-moving regulatory landscape. 

What You'll Do: 

  • Privacy Program Build & Ownership: Design, build, and run Hippo's enterprise data privacy compliance program, maturing it from today's operational footing into a documented, auditable program: governance and accountability structure, data inventory and records of processing, privacy impact assessment process, policy framework, program metrics, and a regulatory change management process covering CCPA/CPRA, other state privacy laws, and insurance-specific privacy requirements (e.g., GLBA and state insurance privacy laws) 
  • Privacy Operations & Consumer Rights: Own Hippo's privacy mailbox and consumer rights request process end to end: intake, verification, tracking, and timely response to access, deletion, correction, and opt-out requests, with documentation sufficient to withstand regulatory scrutiny 
  • Marketing & Advertising Compliance: Own compliance for marketing and outreach channels, including TCPA/telemarketing and SMS consent requirements (CTIA messaging standards, consent capture and logging, opt-out handling), CAN-SPAM, and website tracking technologies (cookies, pixels, session replay) and consent management; partner with Marketing and Growth teams on campaign and disclosure review 
  • Cybersecurity Regulatory Compliance: Support compliance with insurance-specific cybersecurity regulations (NYDFS 23 NYCRR 500, NAIC Insurance Data Security Model Law and state adoptions) and general frameworks (e.g., NIST); support annual certifications, risk assessments, and regulatory exams and audits, and maintain required documentation 
  • Cyber Event Handling: Partner with Information Security on the triage, investigation, containment, and resolution of cyber events; own the compliance workstream for each event, including documentation, materiality and notification analysis support (state breach statutes, NYDFS 72-hour reporting), and remediation tracking, escalating legal determinations to counsel 
  • AI Governance & Compliance: Build and maintain Hippo's AI compliance framework, including use case intake, risk assessment, inventory, and monitoring for AI/ML systems across the business; track state, federal, and international AI regulation relevant to insurance (algorithmic accountability, AI in underwriting, claims, and pricing, model governance requirements) 
  • Vendor & Third-Party Risk: Conduct privacy and data-protection reviews of vendors and third-party service providers, support the data processing agreement process with Legal, and partner with InfoSec on third-party security diligence, including NYDFS Section 500.11 TPSP requirements 
  • Policies, Standards & Training: Draft, maintain, and operationalize internal policies, standards, and procedures for data privacy, cybersecurity, and AI use, and develop and deliver company-wide training and awareness on those policies, in coordination with the Sr. Enterprise Compliance Director and Legal 
  • Regulatory Liaison Support: Serve as a day-to-day point of contact for regulatory inquiries, exams, and audits touching privacy, cyber, and AI, coordinating responses and escalating legal interpretation questions to attorney oversight 
  • Cross-Functional Partnership: Work closely with Legal, Information Security, Engineering, Marketing, and business units to embed privacy, security, and AI compliance requirements into products, processes, and vendor relationships 

Must Haves: 

  • 5+ years of experience in data privacy, cybersecurity, and/or AI governance compliance within a regulated industry, including hands-on operational experience (consumer rights requests, incident response, marketing compliance), not just policy work
  • Bachelor's degree; one or more relevant certifications strongly preferred: CIPP/US, CIPM, or CIPT (IAPP privacy certifications), AIGP (IAPP Artificial Intelligence Governance Professional), CISSP, CISM, CRISC, or CDPSE
  • Demonstrated experience building or significantly maturing a privacy or compliance program, not solely running an established one
  • Working knowledge of key privacy, marketing, and cybersecurity regulatory frameworks (CCPA/CPRA and other state privacy laws, TCPA, GLBA, NYDFS 23 NYCRR 500, NAIC Insurance Data Security Model Law)
  • Familiarity with the emerging AI regulatory landscape and how it applies to insurance use cases (underwriting, claims, pricing, customer service)
  • Experience supporting security incident response and breach notification analysis in partnership with information security and legal teams
  • Strong written communication skills, including experience preparing reporting for senior management, board, or committee audiences
  • Experienced working in close partnership with legal counsel and knows when to escalate for legal interpretation
  • Strong program and project management skills; able to manage multiple regulatory workstreams simultaneously
  • Technical aptitude and the ability to quickly learn new technologies and platforms (privacy management, consent management, and GRC tooling a plus) 

Nice to Haves: 

  • Insurance industry experience strongly preferred (P&C a plus) 

Benefits and Perks:

Hippo treats its team members with the same level of dedication and care as we do our customers, which is why we’re fortunate to provide all of our Hippos with: 

  • Healthy Hippos Benefits - Multiple medical plans to choose from and 100% employer covered dental & vision plans for our team members and their families. We also offer a 401(k)-retirement plan, short & long-term disability, employer-paid life insurance, Flexible Spending Accounts (FSA) for health and dependent care, and an Employee Assistance Program (EAP) 
  • Equity - This position is eligible for equity compensation  
  • Training and Career Growth - Training and internal career growth opportunities 
  • Flexible Time Off - You know when and how you should recharge 
  • Little Hippos Program - We offer 12 weeks of parental leave for primary and secondary caregivers 
  • Hippo Habitat - Snacks and drinks available and catered lunches for onsite employees

The Morristown, NJ base pay range for this role is $120,000 - $179,500. Exact compensation may vary based on several job-related factors that are unique to each candidate, including but not limited to: skill set, experience, education/training, location, business needs and market demands.

Hippo is an equal opportunity employer, and we are committed to building a team culture that celebrates diversity and inclusion. Hippo’s applicants are considered solely based on their qualifications, without regard to an applicant’s disability or need for accommodation. Any Hippo applicant who requires reasonable accommodations during the application process should contact the Hippo’s People Team to make the need for an accommodation known. 

Applicant & Employee Privacy Notice (CCPA/CPRA)

Skills Required

  • 5+ years of experience in data privacy, cybersecurity, and/or AI governance compliance within a regulated industry
  • Hands-on experience with consumer rights requests, incident response, and marketing compliance
  • Bachelor's degree
  • Experience building or significantly maturing a privacy or compliance program
  • Working knowledge of CCPA/CPRA, other state privacy laws, TCPA, GLBA, NYDFS 23 NYCRR 500, and the NAIC Insurance Data Security Model Law
  • Familiarity with emerging AI regulations and insurance use cases including underwriting, claims, pricing, and customer service
  • Experience supporting security incident response and breach notification analysis with information security and legal teams
  • Strong written communication skills and experience preparing reports for senior management, boards, or committees
  • Experience partnering closely with legal counsel and escalating matters requiring legal interpretation
  • Strong program and project management skills with the ability to manage multiple regulatory workstreams
  • Insurance industry experience, preferably property and casualty
  • Technical aptitude and ability to learn privacy management, consent management, and GRC platforms
  • Relevant certification such as CIPP/US, CIPM, CIPT, AIGP, CISSP, CISM, CRISC, or CDPSE

Hippo Insurance Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Hippo Insurance and has not been reviewed or approved by Hippo Insurance.

  • Healthcare Strength — Health coverage is described as comprehensive, with multiple medical plans plus employer-paid dental and vision for employees and families. Feedback suggests wellness rewards and EAP add to the overall value.
  • Leave & Time Off Breadth — Flexible or unlimited PTO and paid parental leave are highlighted as core parts of the package. Observations indicate these policies are intended to support work-life balance, though usage can depend on team workloads.
  • Equity Value & Accessibility — Equity or stock options are included for many corporate and tech roles. This component is presented as a meaningful part of total compensation in certain positions.

Hippo Insurance Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
500 Employees
Year Founded: 2015

What We Do

Hippo’s more than just a home insurance company, its reimagined home protection, helping our customers identify and resolve issues in their homes before they become major headaches. Hippo offers complimentary smart home devices with smart home discounts, home care services that include home wellness checkups and layers in advanced technology that’s focused on preserving our customers’ properties and their pocketbooks. In just over three years, we’ve grown to protect hundreds of thousands of homeowners in 31 states, reaching over 70 percent of the US homeowners population, and aim to reach 95 percent of homeowners by 2021. Hippo has raised $359 million in total funding with a recorded $1.5 billion valuation. Most recently, the company announced a $150 million Series E funding round led by venture capital firm FinTLV.

Gallery

Gallery

Similar Jobs

Enverus Logo Enverus

Account Executive

Big Data • Information Technology • Software • Analytics • Energy
In-Office
3 Locations
1800 Employees
80K-180K Annually
Hybrid
Austin, TX, USA
205000 Employees
Hybrid
Bellaire, TX, USA
205000 Employees
Hybrid
Sachse, TX, USA
205000 Employees

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account