New

Senior Manager, Privacy Operations (Legal)

Redwood City, California, United States

Corcept is leading the way in the research and development of cortisol modulators, molecules that regulate cortisol activity at the glucocorticoid receptor (GR). To date, we have discovered more than 1,000 selective proprietary cortisol modulators.

In 2012, we received FDA approval of Korlym® (mifepristone), the first approved treatment for hypercortisolism (Cushing’s syndrome).

Today, our team and collaborators continue to unlock the possibilities of cortisol modulation as a way to treat serious diseases. With more than 30 ongoing studies across a wide range of disease areas, including endocrinology, oncology, metabolism, and neurology, we remain dedicated to advancing the possibilities of cortisol modulation.

What began as a ripple of scientific truth is now poised to unleash a sea change of discovery representing a fundamental shift in the way we understand and treat disease.

The Senior Manager, Privacy Operations will be responsible for implementing, operationalizing, and continuously improving Corcept’s global privacy program. This role will translate legal and regulatory privacy requirements into practical, scalable, and auditable operational processes across the organization.

The role requires close collaboration with IT, HR, Clinical, Commercial, Drug Safety, and Quality functions to ensure that privacy requirements are embedded into day‑to‑day business activities, systems, and vendor relationships. The ideal candidate combines strong privacy program management experience with the ability to work hands‑on in a regulated pharmaceutical environment. The role also offers the opportunity to support broader compliance topics.

This is a hybrid position typically requiring on-site presence 3 days per week.

This role reports to the Sr. Director, Legal & Privacy.

Responsibilities:

Privacy Program Operations

  • Implement and maintain the Corcept’s privacy program, including policies, guidelines, and work instructions
  • Operationalize privacy requirements under applicable data protection laws (e.g., GDPR, UK GDPR, CCPA, U.S. state privacy laws, and other global regulations)
  • Maintain records of processing activities (RoPA), data inventories, and supporting documentation
  • Support privacy‑by‑design principles in business processes and systems

Data Subject Rights & Incident Management

  • Own and manage the intake, tracking, and fulfillment of data subject rights requests (DSARs), including access, deletion, correction, and objection requests
  • Support privacy incident and breach response activities, including intake, triage, investigation support, documentation, and remediation tracking
  • Coordinate with internal stakeholders to ensure timely, accurate, and well documented responses within statutory deadlines

Privacy Risk Management

  • Coordinate and perform privacy impact assessments / data protection impact assessments (PIAs/DPIAs) in collaboration with IT and business teams
  • Identify operational privacy risks and recommend mitigation strategies
  • Support internal audits, inspections, and regulatory inquiries related to privacy

Vendor Privacy Support

  • Support vendor privacy due diligence and onboarding processes, including privacy questionnaires and risk assessments
  • Assist with the operational implementation of data processing agreements and privacy‑related contractual requirements
  • Track and monitor privacy obligations applicable to vendors

Training, Awareness & Enablement

  • Develop and deliver role‑based privacy training and awareness materials
  • Act as a point of contact for business teams on operational privacy questions
  • Promote a culture of privacy, accountability, and data protection across the organization

Reporting & Continuous Improvement

  • Track and report on privacy metrics and key performance indicators (KPIs)
  • Identify opportunities to streamline and automate privacy processes and workflows
  • Monitor regulatory developments and recommend operational enhancements as needed

Preferred Skills, Qualifications and Technical Proficiencies:

  • Hands‑on experience operationalizing privacy programs in a regulated environment, preferably pharmaceuticals, biotech, or life sciences
  • Strong working knowledge of global privacy frameworks, including GDPR, CCPA and U.S. privacy laws
  • Demonstrated experience managing DSARs, PIAs/DPIAs, and privacy incident workflows
  • Familiarity with Privacy management and workflow tools (e.g., OneTrust or similar platforms), Data mapping, RoPA, and DSAR management tools
  • Familiarity with information security and IT concepts (e.g., access controls, encryption, data lifecycle management)
  • Proficiency with Microsoft 365 tools (Excel, Word, PowerPoint, Teams) for documentation and reporting
  • Ability to translate legal requirements into clear, practical operational processes
  • Strong project management, organizational, and documentation skills
  • Excellent communication skills with the ability to work effectively across legal, technical, and business teams

Preferred Education and Experience:

  • 7+ years of experience in privacy and data protection, preferably in the pharmaceutical/biotech/life sciences industry
  • Bachelor’s degree required
  • Relevant privacy or compliance certifications preferred, such as:
    • Certified Information Privacy Manager (CIPM)
    • Certified Information Privacy Professional (CIPP/US, CIPP/E, or equivalent)

The pay range that the Company reasonably expects to pay for this headquarters-based position is $193,770 – $227,880; the pay ultimately offered may vary based on legitimate considerations, including geographic location, job-related knowledge, skills, experience, and education.

 Applicants must be currently authorized to work in the United States on a full-time basis.

For information on how Corcept collects, uses, discloses, protects, and otherwise processes personal information and an explanation of the rights and choices available to you with respect to your personal information, please refer to our Privacy Notice link

Corcept appreciates the commitment and hard work of all our team members as we strive to discover and develop novel treatments for patients with serious unmet medical needs.

 Please visit our website at: https://www.corcept.com/

Corcept is an Equal Opportunity Employer

Corcept will not conduct interviews via text message or messaging platforms and will not ask you to download anything as part of your interview.  Though we use third-party tools to help with advertising our jobs, please be vigilant in checking that the communication is in fact coming from Corcept.

 

Create a Job Alert

Interested in building your career at Corcept Therapeutics? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...
Select...
Select...

Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Corcept Therapeutics’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.