Jason Wilson

Jason Wilson

Head of Privacy & AI Governance | Privacy Engineering, Policy-as-Code, Security Compliance

20 yrs experience · Seattle, WA · <10 hrs/week

About

Governance, privacy, and security engineering leader who builds controls “as code” and embeds privacy/security requirements into SDLC and CI/CD pipelines. Experienced across SOC 2, ISO 27001, FedRAMP, and enterprise privacy/AI governance, including policy-as-code, DPIAs, model risk management, and automated evidence collection to support audit and authorization outcomes. Comfortable partnering with CTO/engineering/SRE as well as CISO-level briefings and customer trust inquiries.

Skills

AWSCI/CDDockerGitKubernetesLinuxNetworkingPythonSQLShellTerraform

Experience

  • Head of Privacy and AI Governance · Real Inc.09-01-2024 – 09-01-2025

    • Automated evidence collection and control testing for SOC 2 and ISO 27001 audits across a publicly traded real estate platform supporting $1.8B in annual transaction volume, leading enterprise privacy, data protection, and AI governance while managing customer-facing trust inquiries across brokerage, mortgage, title, and fintech lines of business. • Architected AI governance frameworks for generative AI products in production, including policy-as-code controls for biometric data processing, training data governance pipelines, and model risk management for mortgage decisioning under Fair Lending Act and ECOA. • Embedded privacy and AI governance requirements directly into the SDLC and CI/CD pipeline alongside CTO, engineering, and data science, owning the engineering guidelines, policy documentation, data governance architecture, and data protection impact assessments (DPIAs) rather than handing requirements over the wall.

  • Head of Security and Privacy · SciNote09-01-2023 – 09-01-2024

    • Sole security and compliance leader for a 75-person life sciences SaaS platform, architecting and executing FedRAMP Moderate authorization in 8 months and unlocking approximately $70M in federal contracts with FDA and HHS, building the technical evidence pipelines that fed 3PAO and registrar assessments. • Built the unified control framework from scratch using a GRC-as-Code approach, mapping controls across FedRAMP, ISO 27001, and SOC 2, authoring all compliance documentation including SSP, POA&M, and Rules of Behavior, and wiring continuous compliance monitoring into every stage of the SDLC through automated evidence collection from cloud infrastructure. • Designed and implemented third-party risk management workflows and vendor security assessment tooling, partnering with procurement to manage vendor security reviews and harden supply chain assurance across a global customer base.

  • Director of Privacy Engineering · Twilio09-01-2021 – 09-01-2023

    • Built, hired, and led the privacy engineering team from the ground up across distributed product groups, architecting automated data discovery and classification tooling to track data flows across a containerized microservices environment on AWS. • Integrated anonymization and encryption controls directly into core development workflows, embedding policy-as-code gates into the CI/CD pipeline across 8 business units and partnering with product security and engineering teams on security reviews. • Engineered OneTrust-based compliance automation that unified policy management, product launch assessment, and internal audit readiness for SOC 2 and ISO 27001 into a single operational system, replacing manual audit preparation cycles with repeatable, automated workflows.

  • Senior Manager, Security and Privacy · Microsoft09-01-2015 – 09-01-2021

    • Spent the first two years embedded as technical product manager for Azure Purview, working directly with engineering teams across Redmond and Israel to define and ship the data governance platform, writing technical specs for cloud-native infrastructure on Azure and building the data classification and lineage capabilities that fed downstream compliance controls. • Managed and mentored a security and privacy engineering team across Microsoft 365, Azure, and Dynamics, working with 70 global engineering teams to implement NIST 800-53, FedRAMP, ISO 27001, and SOC 2 controls directly into cloud services and building the technical compliance architecture for Azure Government certifications. • Translated NIST 800-53 and ISO 27001 control requirements into technical solutions at the product level, engineering automated remediation tracking integrated with vulnerability management tooling to push fixes upstream into early-stage development and streamline annual SOC 2 evidence delivery. • Reviewed and redlined contracts and DPAs for technical accuracy, working across legal, sales, and engineering to unblock enterprise deals, balancing customer requirements against organizational risk, and when exceptions landed, engineering the architectural changes to make them real rather than just accepted on paper.

  • Senior Data Privacy & Security Compliance Manager · MITRE03-01-2013 – 09-01-2015

    • Contributed directly to the development of NIST 800-53 security controls, producing implementation guidance that shaped how federal agencies and contractors interpreted and applied the framework. • Designed and implemented data security policies for HIPAA-aligned electronic health records systems under ACA requirements, working at the intersection of policy and technical implementation. • Dug into DFARS compliance assessments at the technical level, translating federal data protection requirements into concrete changes to acquisition processes before most organizations knew DFARS was coming for them.

  • Senior Technology Advisor · Bloomberg12-01-2011 – 03-01-2013

    • Contributed to the full development lifecycle of the Bloomberg Government IT Contracts platform, working across product, engineering, and UX to ship a tool with advanced analytics and data visualization for federal IT procurement intelligence. • Synthesized federal contracting datasets and cybersecurity market signals into actionable guidance for Fortune 500 clients navigating regulated government technology markets.

  • Lead Compliance Manager · Department of Defense11-01-2005 – 06-01-2011

    • Built cloud risk management frameworks grounded in NIST 800-53, FISMA, and RMF at a time when most of the federal government was still figuring out what cloud meant. • Contributed to the foundational control requirements that preceded FedRAMP, doing the POA&M and authorization groundwork before the program had a name. • Led deployment of a software analytics tool across government environments, working directly with development and security teams to get it across the line.

Education

  • Georgetown UniversityM.A., Technology Policy
  • University of Illinois at Urbana-ChampaignB.A., Political Science

Similar talent on Pangea

Hire Jason through Pangea

Describe your project to the Pangea agent — see if Jason is a fit, with transparent pricing and interviews booked straight onto your calendar. No contact details change hands until you hire.

See if Jason is a fit