About the role
As Senior Staff Engineer on the Privacy Engineering team, you'll define the technical strategy for how Shopify handles privacy at scale. This isn't a role where you execute someone else's roadmap โ you identify which problems Shopify needs to solve next, design the systems to solve them, and drive execution across teams and organizational boundaries.
You'll operate across multiple problem spaces simultaneously. You can be parachuted into an unfamiliar area, ramp up on the problem space quickly, and drive results. You don't just champion one project โ you shape the technical direction of the entire privacy engineering domain, influencing how other teams across Shopify think about and interact with privacy infrastructure.
The regulatory landscape is changing fast. California's Opt Me Out Act, evolving GPC standards, new data subject request types, and Shopify's expansion into new markets all create problems that don't have established solutions. You'll be the person who sees around corners and builds the infrastructure to handle what's coming โ not just what's here today.
About the team
Privacy Engineering is the team that makes privacy work at scale โ not as a policy checkbox, but as real infrastructure. We build and own the systems that let Shopify reliably handle millions of data subject requests across every surface of the platform: DSAR orchestration, PII redaction, compliance tooling, and the event pipelines that enforce privacy by default.
When a merchant, or their customer requests their data be deleted, when someone opts out of data sale, or when a regulatory deadline hits โ our systems are what make it happen. The problems are genuinely hard, the consequences are real, and the work has direct visibility into Shopify's company priorities.
We sit at the intersection of engineering, data, and compliance, coordinating across Identity, Data Platform, Data Governance, Streaming Platform, and Legal. This is a team that ships. We bias toward action, iterate quickly, and trust each other to own outcomes.
We use AI tools extensively โ Claude Code and Pi are part of our daily workflow for code generation, context gathering, PR reviews, and system investigation.
What you'll do
Define technical strategy across the privacy domain โ Identify the highest-leverage problems, prioritize across competing demands, and set multi-quarter technical direction. Influence the privacy roadmap in partnership with Legal, Compliance, and Data leadership.
Solve multiple high-value problems in parallel โ Ramp up on new problem spaces extremely quickly and drive results. You're comfortable switching between redesigning a petabyte-scale redaction pipeline and designing a new consent management architecture in the same week.
Drive cross-functional, cross-discipline coordination โ Privacy enforcement requires alignment across Engineering, Legal, Compliance, Product, and Data. You build the relationships, drive the conversations, and ensure Shopify's technical approach serves regulatory and business needs. You don't wait for alignment โ you create it.
Pull projects out of local maxima โ When a team is stuck in an approach that works but doesn't scale, you see the better architecture and drive the transition. You challenge orthodox approaches when they're suboptimal, and you have the credibility and evidence to bring people along.
Author foundational technical designs โ Your designs define the system boundaries, data models, and architectural patterns that the team builds on for years. They're clear enough for junior engineers to implement and rigorous enough for other senior staff to critique.
Improve the long-term health of privacy infrastructure โ Reduce systemic complexity, eliminate operational toil, and build systems that are cheaper, faster, and more reliable over time. You think in terms of total cost of ownership, not just feature delivery.
Set the standard for technical excellence โ Your code, reviews, designs, and operational practices are the benchmark. You raise the ceiling for every engineer who interacts with your work.
Prototype and experiment to solve problems several moves ahead โ When legislation is coming in 12 months, you've already built the proof of concept. When a new BigQuery feature could reshape how we do redaction, you've already tested it. You stay ahead of the curve.
What we're looking for
Sees the big picture and the details. You can zoom in from "how should Shopify handle privacy in 2028?" to "this BigQuery partition filter is generating the wrong timestamp type" in the same conversation. You're equally comfortable in a strategy meeting with Legal and debugging a production query timeout.
Is self-reliant and does it yourself first. You don't delegate understanding. You read the code, run the queries, and build the prototype. When you ask others to do something, you've already validated the approach yourself.
Operates with extreme ownership at organizational scale. You don't just own your projects โ you own the outcome for privacy at Shopify. When something falls through the cracks between teams, you catch it. When a compliance deadline is at risk, you escalate before it's too late.
Inspires the team and the area. People want to work on your projects because the problems are interesting, the approach is clear, and the impact is real. You attract talent through the quality of your thinking and the ambition of your work.
Requirements
Strong software engineering fundamentals โ you write production-grade code, hold a high bar for system design, and can go deep on implementation when needed.
Proven, hands-on expertise building and optimizing large-scale data processing systems, with measurable performance and cost improvements to show for it.
Demonstrated experience architecting and scaling high-throughput, real-time data systems handling millions of requests per day.
Fluency with AI coding tools as part of your daily engineering workflow โ not familiarity, actual integration.
Track record of cross-functional influence and impact: working across engineering, legal, compliance, and data platform teams to deliver outcomes that cut across organizational lines.
Track record of driving multi-quarter technical strategy across teams.
Track record of mentoring engineers and raising the reliability bar across a team.
Experience and genuine passion, or strong interest, for building systems in the privacy domain โ this isn't just a job to you, it's a problem space you want to go deep on.
Nice to haves
Experience with BigQuery, BigTable, Kafka, Flink
Experience with system redesigns that fundamentally changed how a domain operates
Familiarity with privacy and compliance regulations (GDPR, CCPA) and how they translate into technical requirements.
Experience building in regulated domains where correctness has legal consequences