Privacy & AI Governance Analyst

Vasion, Inc.

Lehi (UT)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

401k with company match
Company-contributed HSA
On-site gym
Flexible paid time off
Vacation bonus
Paid parental leave

Job summary

Vasion, Inc. in Lehi, Utah seeks a Privacy & AI Governance Analyst to own the privacy program and AI governance framework from day one, reporting to the General Counsel & Chief Compliance Officer.

You will work cross-functionally with Product, Engineering, Security, Sales, Marketing, HR, and Legal to embed compliance into how Vasion builds and operates. You will also support Vasion’s HIPAA obligations as a group health plan sponsor, and help drive FedRAMP authorization, ISO 42001 certification,

Qualifications

  • 3–5 years in privacy, compliance, or legal operations at a tech/SaaS company
  • Working knowledge of GDPR and CCPA and practical privacy program execution
  • Experience reviewing, redlining, and negotiating DPAs
  • Exposure to ISO 42001 or EU AI Act compliance is a plus
  • Strong written communication; able to draft policy and training
  • Ability to manage multiple workstreams with deadlines
  • CIPP/US, CIPP/E, or CIPM preferred
  • Experience with privacy GRC or consent tools (OneTrust, MineOS, Osano) is a plus
  • HIPAA familiarity is a plus but not required

Responsibilities

  • Own end-to-end DPA review, redline, and execution
  • Manage DSR intake and responses for GDPR/CCPA
  • Conduct Privacy Impact Assessments for new features and data processing
  • Maintain subprocessor register and vendor notification compliance
  • Own privacy policy updates and publication
  • Manage EU-US Data Privacy Framework obligations
  • Support privacy obligations for Germany, UK, and Australia entities
  • Lead data mapping and privacy GRC tool deployment
  • Deliver GDPR and privacy training to internal teams
  • Maintain AI model inventory, bias testing, audit trails
  • Draft Responsible AI Use Policy and guidance
  • Support ISO 42001 certification maintenance
  • Monitor EU AI Act and US state AI legislation
  • Coordinate with AI Governance Committee
  • Conduct AI vendor risk assessments
  • Own compliance policy library and publishing
  • Design privacy and governance training programs
  • Develop plain-language guidance for Eng/Marketing/Sales/HR
  • Support Sales with privacy questionnaire responses
  • Support HIPAA obligations as group health plan sponsor
  • BAA management and breach notification procedures
  • Maintain HIPAA Policies & Procedures with Security
  • Maintain on-site perks and benefits communications

Skills

Privacy program management
GDPR & CCPA knowledge
DPA review & negotiation
AI governance familiarity
Cross-functional collaboration
Policy writing
Ambiguity tolerance
CIPP/US or CIPM in progress
Privacy GRC tools (OneTrust/Osano/Mine
HIPAA familiarity

Tools

OneTrust
MineOS
Osano

Job description

For more than a decade, Vasion has been helping companies simplify their print infrastructure, automate business processes, and integrate their technology in a more secure environment. Our mission, to make digital transformation attainable for everyone, drives a culture of innovation and exploration. We have one simple goal: help organizations simplify processes through automation and integration.

So we created simple, cost-effective, and easy-to-implement digital tools that work together, removing bottlenecks and improving efficiency. And we’re always on the lookout for new people who can help us innovate, grow, and reach our goal.

About the role

As Privacy & AI Governance Analyst at Vasion, you will own the execution of our privacy program and AI governance framework, two of the company's highest-externally-visible compliance domains. This is a hands-on builder role, not a coordinator role. You will inherit programs in motion and be expected to run them independently from day one. You will report directly to the General Counsel & Chief Compliance Officer and serve as the company's subject matter expert on all things privacy and AI governance. You will work cross-functionally with Product, Engineering, Security, Sales, Marketing, HR, and Legal to embed compliance into how Vasion builds and operates. You will also support Vasion's obligations as a group health plan sponsor as the company transitions toward a self-funded insurance model. This role is an opportunity to build privacy and AI governance infrastructure at a company in a genuine market moment, where FedRAMP authorization, ISO 42001 certification, and a growing federal customer base make compliance a strategic differentiator, not a back-office function.

What you'll do
  • Own the end-to-end DPA review, redline, and execution process — with authority to approve standard customer DPAs without escalation
  • Manage data subject rights (DSR) intake, response, and tracking across GDPR, CCPA, and applicable US state privacy laws
  • Conduct Privacy Impact Assessments (PIAs) for new product features, integrations, and data processing activities
  • Maintain and update the subprocessor register and manage vendor subprocessor compliance notifications
  • Own privacy policy maintenance, including coordinating updates with Marketing and ensuring accurate web publication
  • Manage Vasion's EU-US Data Privacy Framework compliance obligations
  • Support international privacy obligations across Vasion's Germany, UK, and Australia entities
  • Lead data mapping and privacy GRC tool deployment (active evaluation in progress)
  • Deliver GDPR and privacy training to internal teams
AI Governance Program Execution
  • Maintain Vasion's AI model inventory, bias testing documentation, and audit trail records
  • Draft and maintain the Responsible AI Use Policy and supporting internal guidance
  • Support ongoing ISO 42001 certification maintenance and internal audit readiness
  • Monitor EU AI Act and US state-level AI legislation and assess applicability to Vasion's product and operations
  • Provide operational support to the AI Governance Committee, coordinating with the CIO and cross-functional members
  • Conduct AI vendor risk assessments in partnership with Security and Procurement
Policy Development & Training
  • Own the compliance policy library — drafting, maintaining, versioning, and publishing policies across domains
  • Design and deliver privacy and AI governance training programs for internal teams
  • Develop plain-language compliance guidance for Engineering, Marketing, Sales, and HR
  • Support Sales with privacy and AI compliance questionnaire responses and Trust Center content
  • Support Vasion's HIPAA obligations as a group health plan sponsor through the transition from level-funded to self-funded coverage
  • Assist with Business Associate Agreement (BAA) management, workforce training coordination, and breach notification procedures
  • Maintain HIPAA Privacy and Security Policies & Procedures in coordination with the CCO as Security Official
Qualifications
  • 3–5 years of experience in a privacy, compliance, or legal operations role — ideally at a technology or SaaS company
  • Working knowledge of GDPR and CCPA and the practical mechanics of running a privacy program (not just regulatory familiarity)
  • Experience reviewing, redlining, and negotiating Data Processing Agreements (DPAs)
  • Exposure to AI governance frameworks, ISO 42001, or EU AI Act compliance is a meaningful plus
  • Demonstrated ability to execute across multiple compliance workstreams simultaneously without losing detail or deadline discipline
  • Strong written communication — you can write a policy people actually read and a training people actually learn from
  • Comfort building in ambiguity — many of the processes you will own are in progress or not yet formalized
  • CIPP/US, CIPP/E, or CIPM certification held or actively in progress preferred
  • Experience with privacy GRC or consent management tools (OneTrust, MineOS, Osano, or similar) is a plus
  • Familiarity with HIPAA group health plan compliance is a plus but not required
  • Flexible work environment
  • Vacation Bonus
  • Flexible paid time off
  • Paid parental leave
  • Competitive pay
  • A full suite of traditional benefits
  • 401k with company match and immediate vesting
  • Financial wellness education
  • Company-contributed HSA
  • On-site perks include gym, pickleball, snacks & drinks, arcade, theater room, etc.
Our Core Values

Vasion looks for people who will exemplify its four core values and are driven to become:

  • Disruptive Visionaries: Our customers are the heroes, and our role is to be a guide on their journey, truly listening and identifying the needs and wants of our customers.
  • Relationship Builders: We treat people as people, building strong relationships through empathy, compassion, and honest communication.
  • Candor Seekers: Candid conversations are critical to achieving objectives, and we nurture a culture of caring personally and challenging directly.
  • Action Owners: Every employee takes ownership of any failures and develops a plan to win, no matter their tenure or circumstance.
More about Vasion

Visithttps://www.vasion.comto learn more about Vasion.

Additional Information

Vasion is an equal opportunity employer. We evaluate qualified applicants without regard to race, age, color, religion, sex, national origin, disability, veteran status, gender identity, sexual orientation and other legally protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Privacy & AI Governance Analyst
Privacy & AI Governance Analyst

Vasion • Lehi (UT)

On-site
USD 110,000 - 160,000
Vacation Bonus
Flexible paid time off
Paid parental leave
+1
Privacy and AI Governance Analyst
Privacy and AI Governance Analyst

PrinterLogic • Lehi (UT)

On-site
USD 120,000 - 160,000
Global Privacy & Information Governance Manager
Global Privacy & Information Governance Manager

Vontier • United States

Remote
GBP 90,000 - 120,000
Privacy & AI Governance Specialist
Privacy & AI Governance Specialist

Vasion • Lehi (UT)

On-site
USD 110,000 - 160,000
Vacation Bonus
Flexible paid time off
Paid parental leave
+1
Senior Privacy Counsel
Senior Privacy Counsel

Abnormal • United States

On-site
USD 180,000 - 240,000
Senior Privacy Counsel
Senior Privacy Counsel

Socket.dev • United States

On-site
USD 200,000 - 235,000
Privacy Analyst- HQ
Privacy Analyst- HQ

Agora • Santa Clara (CA)

On-site
USD 120,000 - 150,000
Senior Privacy Counsel
Senior Privacy Counsel

Abnormal AI • United States

On-site
USD 200,000 - 235,000
Equity
Competitive salary
Benefits package
Lead Privacy & AI Governance
Lead Privacy & AI Governance

PrinterLogic • Lehi (UT)

On-site
USD 120,000 - 160,000
Privacy & AI Governance Lead
Privacy & AI Governance Lead

Vasion, Inc. • Lehi (UT)

On-site
USD 90,000 - 130,000
401k with company match
Company-contributed HSA
On-site gym
+3