Senior Staff Data Security Privacy Engineer

Canada; United States

About Coursera

Coursera was founded in 2012 by Stanford professors Andrew Ng and Daphne Koller to make world-class learning accessible to everyone, everywhere. Today, over 190 million learners and 375+ university and industry partners use our platform to gain skills in fields like AI, data science, technology, and business. As a Delaware public benefit corporation and Certified B Corp, we’re driven by the belief that learning can transform lives through learning.

Why Join Us

At Coursera, we’re looking for inventors, innovators, and lifelong learners ready to shape the future of education. You’ll help build global programs and tools that power online learning for millions turning bold ideas into real impact. People who thrive here are customer-first builders who move fast, simplify ruthlessly, and iterate relentlessly on the metrics that matter. 

We’re a globally distributed team and let you choose the best way you work, whether it's from home, a Coursera hub, or a co-working space near you. Our virtual hiring and onboarding make it easy to join us and start making an impact from anywhere. If you’re ready to make a global impact, scale unique products exclusive to Coursera, and expand your career horizons, apply below.

At Coursera, we’re looking for inventors, innovators, and lifelong learners ready to shape the future of education. You’ll help build global programs and tools that power online learning for millions turning bold ideas into real impact. People who thrive here are customer-first builders who move fast, simplify ruthlessly, and iterate relentlessly on the metrics that matter. 

We’re a globally distributed team and let you choose the best way you work, whether it's from home, a Coursera hub, or a co-working space near you. Our virtual hiring and onboarding make it easy to join us and start making an impact from anywhere. If you’re ready to make a global impact, scale unique products exclusive to Coursera, and expand your career horizons, apply below.

Job Overview:

As a Sr. Staff Engineer, Data Security and Privacy, you will play a critical role in designing, building, and scaling the systems, processes, and controls that protect the company and our users’ data and ensure trust in our products. Working as part of the Information Security team, you will partner closely with Engineering,  Legal, and cross-functional stakeholders to embed privacy-by-design principles into our infrastructure and translate regulatory requirements into scalable technical solutions.

This is a hands-on role for a senior individual contributor who thrives at the intersection of security, privacy, and data infrastructure. You will shape how we discover, classify, and protect information, lead privacy risk mitigation efforts, and help evolve our data security capabilities as the company grows.

Responsibilities:

Privacy by Design and Technical Enablement

  • Partner with Engineering, Legal, Product, IT, and other cross-functional stakeholders (Stakeholders) to design and embed privacy and data protection principles across the entire organization, from product development to operations.
  • Partner with Stakeholders to translate legal and regulatory obligations into actionable technical requirements, policies, and controls.
  • Develop privacy-enhancing capabilities such as data minimisation, anonymisation, and access-control frameworks that scale with our infrastructure.

Data Discovery, Classification, and Mapping

  • Design and implement data classification and handling frameworks to provide appropriate protection throughout the data lifecycle.
  • Build and maintain comprehensive data inventories and data flow maps, identifying where data resides and how it is processed across systems.
  • Collaborate with Engineering teams to apply appropriate controls at every point in the data pipeline.

Risk Assessment, Monitoring, and Compliance Execution

  • Conduct technical risk assessments of internal and third party systems and applications to identify, evaluate, and mitigate privacy and data security risks, including vulnerabilities, misuse, and compliance gaps.
  • Contribute to Data Protection Impact Assessments (DPIAs) by assessing the technical and security implications of new processing activities.
  • Partner with Legal to transform evolving regulatory frameworks (e.g., GDPR, CCPA, NIST, ISO) into secure, scalable engineering solutions that drive compliance and build user trust.

Incident Response and Breach Management

  • Lead and coordinate the company’s technical response to data breaches or security incidents, including those impacting personal information (Incidents), enabling timely investigation, effective mitigation, and root-cause analysis.
  • Design and implement processes and tooling to detect, investigate, and remediate, Incidents in compliance with applicable laws.

Privacy Automation and Process Enablement

  • Partner with Stakeholders to design and implement automated workflows and tools to streamline privacy operations, including data subject rights requests and data deletion workflows.
  • Deploy and manage data loss prevention (DLP) capabilities across endpoints, applications, and infrastructure to prevent unauthorised disclosure of sensitive data.
  • Implement continuous auditing, monitoring, and alerting to track compliance posture and surface security and operational privacy risks proactively.

Cross-Functional Collaboration and Enablement

  • Act as a trusted advisor to Stakeholders on the technical implementation of privacy and security controls.
  • Provide strategic input on product design decisions and architectural choices to enable alignment with privacy and security best practices.
  • Partner with cross functional teams to develop and execute  vendor risk assessments, establishing processes that address technical, security and privacy requirements across the entire vendor lifecycle.

Additional Responsibilities

  • Collaborate with Legal on technical aspects of contractual reviews with enterprise customers,partners, vendors, and other third parties.
  • Contribute to the development of internal policies, standards, and procedures based on technical best practices.

Skills and Qualifications

  • 10+ years of hands-on experience in information security, privacy engineering, or related roles.
  • Strong understanding of global data protection laws and regulations (e.g. GDPR, CCPA) and their technical implications.
  • Proven experience in incident response, data protection engineering, and risk assessments.
  • Familiarity with data classification, mapping, and governance methodologies.
  • Experience with DLP technologies and implementing privacy workflows and automation.
  • Familiarity with workflow automation tools and ticketing systems (e.g. Jira, ServiceNow).
  • Experience in using third party privacy automation tooling is a plus.
  • Strong analytical, problem-solving, and communication skills, with the ability to work effectively across cross-functional teams.
  • Industry certifications (e.g. CISSP, CISA, CISM) are a plus.

Compensation 

This role is available in the following US Pay Zones:

Zone 1: $250,200 - $271,320

Zone 2: 220-000 - $259,200

Zone 3: $210,000 - $240,635

Zone 4: $200,000- $224,080

At Coursera, we offer competitive, zone-based pay aligned to your location, experience, and role level across four U.S. pay zones. Our total rewards package goes beyond salary, with comprehensive health and wellness benefits, bonus and RSU equity programs, and global perks designed to help you grow and thrive wherever you are.

US Pay Zones:

  • US-Z1: Bay Area
  • US-Z2: NYC and Seattle Metro
  • US-Z3: CA, WA, NY, NJ, CO, CT, DC, GA, IL, MA, MD, OR, RI, TX, VA
  • US-Z4: AK, AZ, DE, FL, HI, ID, IN, IA, KS, KY, MI, MN, MO, MT, NC, NV, NH, OH, OK, PA, SC, TN, UT, VT, WI

If this opportunity interests you, you might like these courses on Coursera:

 

Coursera is an Equal Opportunity Employer committed to building a welcoming and inclusive workplace. We consider all qualified applicants without regard to legally protected characteristics and provide reasonable accommodations upon request at accommodations@coursera.org. Learn more in our CCPA Applicant Notice and GDPR Recruitment Notice.

Create a Job Alert

Interested in building your career at Coursera? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
COURSERA IS A U.S. GOVERNMENT CONTRACTOR AND WE ARE REQUIRED TO INQUIRE ABOUT CONFLICTS BEFORE WE CAN RECRUIT CURRENT OR FORMER GOVERNMENT EMPLOYEES. IF THIS APPLIES TO YOU, WE REQUEST A LETTER FROM YOUR SUPERVISOR THAT THEY HAVE BEEN INFORMED ABOUT YOUR CONTACT WITH COURSERA (OR AS A FORMER EMPLOYEE, A LETTER STATING AN ETHICS OPINION WHICH IDENTIFIES ANY LIMITATIONS WHICH APPLY TO YOUR WORK IN THE PRIVATE SECTOR). THE LETTER SHOULD IDENTIFY ANY CONFLICTS OR POTENTIAL CONFLICTS, IF ANY EXIST.

Accepted file types: pdf, doc, docx, txt, rtf

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Coursera’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.