About Tunnl
Tunnl is building a future where artificial intelligence enables organizations to connect meaningfully with the people who matter most. We help organizations conduct research at scale, define the right audiences, surface real-time insights, identify optimal communication channels, and measure changing attitudes over time.
Tunnl serves brands, agencies, and advocacy groups alike - organizations navigating complex communications, reputational, and regulatory landscapes. These teams need smarter, faster ways to make audience-informed decisions that stand up to scrutiny and resonate across stakeholder groups. Whether you're building a brand, shaping public opinion, managing risk, or launching a new initiative, Tunnl empowers you to move from insight to impact with clarity & confidence.
About the Role
Tunnl is looking for a Senior Privacy & Compliance Manager to help build and operate the privacy program supporting our data, audience intelligence, advertising, research, and AI-enabled products.
This is a hands-on privacy operations role for someone who understands how consumer data moves through complex data and advertising ecosystems. We are looking for a privacy professional who has personally built and operated privacy processes—not someone whose experience has been primarily providing legal advice or interpreting policy.
Reporting directly to Tunnl’s CTO and Data Privacy Officer (DPO), you’ll serve as the company’s day-to-day privacy and compliance lead. You’ll work closely with legal counsel and partner directly with Product, Engineering, Data, Security, Sales, and Marketing to turn regulatory requirements into practical processes, controls, and product requirements—and take ownership of getting them implemented.
What You'll Do
Own consumer privacy operations, including access, deletion, correction, and opt-out requests and the processes required to propagate those requests across Tunnl’s systems, vendors, and data partners.
Lead U.S. state privacy and data-broker compliance, including registrations, regulatory requirements, operational controls, and implementation of new state privacy obligations.
Build and maintain Tunnl’s data inventory and data-flow maps, developing a practical understanding of how consumer and audience data is collected, combined, used, shared, retained, and deleted.
Lead privacy reviews for products and data, including privacy impact assessments for new products, features, datasets, data partnerships, and uses of consumer data.
Evaluate vendors and data partners for privacy risk and help establish appropriate controls and requirements.
Partner directly with Product, Engineering, and Data teams to embed privacy requirements into products and systems without unnecessarily slowing the business.
Build and continuously improve Tunnl’s privacy compliance program, including policies, procedures, controls, and supporting documentation.
Plan and execute privacy and compliance audits, test the effectiveness of controls, identify gaps, and drive remediation through completion.
Work with legal counsel and leadership to assess emerging privacy requirements and risks and translate them into actionable implementation plans.
What We're Looking For
Required:
7–10 years of privacy, data protection, or related compliance experience, with substantial hands-on responsibility for operating privacy programs.
Meaningful experience with consumer data and data-driven products, ideally in one or more of these areas:
ad tech, digital advertising, audience targeting, or measurement;
identity resolution, consumer data, or data brokerage;
political, advocacy, or voter data;
retail media or large-scale advertising platforms; or
survey research, consumer panels, or market research.
Direct experience managing consumer opt-out, deletion, or access-request workflows.
Strong working knowledge of U.S. state privacy laws, particularly CCPA/CPRA and the evolving state privacy landscape.
Experience building or maintaining data inventories and data-flow maps.
Experience conducting privacy impact assessments, product privacy reviews, vendor assessments, and compliance audits.
Demonstrated ability to translate regulatory requirements into practical business and technical processes.
Ability to operate independently and work directly with Product, Engineering, Data, Sales, Marketing, and other business teams.
Preferred:
Direct experience with state data-broker registrations and compliance requirements.
Experience with audience activation, identity resolution, advertising technology, measurement, or data licensing.
Experience building privacy processes in a smaller or fast-growing organization after working within a mature privacy program.
Experience implementing or operating privacy technology such as Fides, OneTrust, or similar platforms.
CIPP/US, CIPM, or another relevant privacy certification.
Why You Should Apply:
Join a team driven by curiosity, teamwork, integrity, and a shared passion for solving big challenges.
A friendly, welcoming, and supportive culture with regular social and team events.
Comprehensive benefits with excellent medical, vision, and dental coverage.
Health Savings Account (HSA) and Flexible Spending Account (FSA) options.
Employer-paid life insurance & short-term & long-term disability, with other voluntary additional coverage available (accident, critical illness, hospital indemnity).
Flexible hybrid work policy.
Flexible paid vacation plus 80 hours of paid sick leave.
10 paid company holidays per year.
401(k) plan with 100% match up to 3%, plus 50% match up to 5% (subject to IRS limits).
Cell phone reimbursement stipend.
Monthly parking or commuter stipend for VA-based employees.
Skills Required
- 7-10 years of progressive privacy and compliance experience, ideally in data, adtech, market research, or information services
- Required privacy certification: CIPP/US, CIPM, AIGP, or equivalent
- Hands-on experience managing consumer privacy request operations (opt-outs, deletions, access requests) at scale
- Experience building and maintaining data inventories and data flow maps
- Working knowledge of U.S. state data privacy laws (CCPA/CPRA and other state laws), data broker regulatory landscape, TCPA, and CAN-SPAM
- Experience conducting privacy risk assessments, PIAs/DPIAs, and vendor privacy reviews
- Experience supporting privacy and/or cybersecurity incident response, including breach notification obligations
- Experience drafting and maintaining privacy policies, procedures, and standards
- Strong project management skills; ability to manage and prioritize multiple concurrent initiatives independently
- Excellent written and verbal communication; translate regulatory language into plain-English guidance
- Proficiency in common business tools (Excel, PowerPoint) and privacy management or GRC platforms
- OneTrust experience
- Familiarity with survey research regulations and market research industry standards (ESOMAR, MRA)
- Experience with AI governance frameworks and privacy considerations for automated decision-making systems
- Bachelor's degree in law, information management, business, or a related field
What We Do
Tunnl is leveraging AI to erase the boundaries between insights, audiences, and outcomes to ensure every piece of intelligence can be acted on. We combine the judgment of seasoned data experts with the power of artificial intelligence to help organizations find and connect with the people who matter most. With years of experience embedded in our platform, we enable research at scale, define the right audiences, surface powerful insights, identify optimal communication channels, and measure changing attitudes over time—all in one experience built to eliminate data silos.








