Associate General Counsel, Privacy – Remote (USA)

Unlock Employer

Posted Oct 1, 2026

Remote · US Full Time
$260K – $295K/yr

Overview

This role involves serving as Associate General Counsel, Privacy within the legal function. Reporting to the General Counsel, you will own the organization’s global privacy legal function and act as the principal legal advisor on domestic and international privacy and data protection matters. You will also partner closely with Security and the GRC/Compliance functions to support privacy, security commitments, audits, and incident response.

This is a build-and-scale position: you will take a growing set of privacy obligations, customer commitments, and regulatory exposures and turn them into a coherent, well-documented privacy program that scales with the business. You will operate as an individual contributor with the expectation that you build a team as the program matures. Technical depth is important—you will review data flow diagrams, ask precise engineering questions about data storage and access, and provide guidance that product teams can implement.

Responsibilities

Own the global privacy program

  • Advise on domestic and international privacy and data protection laws and regulations, including GDPR, HIPAA, CCPA/CPRA, other U.S. state and international privacy laws, and international data transfer requirements.
  • Own the data subject request process end to end, including the privacy elements of vendor and subprocessor diligence.
  • Track regulatory and enforcement developments across jurisdictions and translate them into concrete changes to product, contracts, and internal practices.
  • Conduct and oversee privacy risk assessments, including data protection impact assessments (DPIAs), transfer impact assessments, and related documentation.

Manage and build out the function

  • Enhance and mature the privacy program to continue meeting evolving regulatory requirements.
  • Scale core privacy program components related to data subject rights requests, privacy notices, consent management, impact assessments, and policy management.
  • Maintain program operating machinery, including records of processing, data inventories and mapping, retention schedules, DPIAs and transfer impact assessments, and privacy policies and notices.
  • Deliver privacy and security training that improves internal awareness across engineering, sales, marketing, partner relationships, and support.
  • Manage outside counsel and privacy vendors against a budget.
  • Serve as, or manage the relationship with, EU representative and data protection officer arrangements as required.
  • Advise Marketing on adtech, cookies, and tracking technologies, and electronic marketing compliance.
  • Report to leadership on privacy and security risk and support Board and audit reporting on the program.

Counsel product and engineering

  • Embed with product and engineering teams during feature design to provide privacy-by-design guidance early enough to shape architecture rather than block launches.
  • Advise on data residency and localization, telemetry and usage data, encryption and key management, access controls, logging, anonymization and pseudonymization, and retention and deletion mechanics.
  • Advise on AI and machine learning features, including training data provenance, customer data use restrictions, model and vendor terms, and emerging AI regulatory requirements.

Support commercial contracting

  • Own the DPA and its negotiation strategy, including standard contractual clauses, the UK IDTA and Addendum, and other transfer mechanisms.
  • Negotiate privacy and security terms in customer and vendor agreements.
  • Serve as an escalation point for Legal and Deal Desk on privacy and security terms.
  • Build playbooks, fallback positions, and self-service guidance to help the team resolve most issues without you.
  • Support enterprise, public sector, and regulated-industry deals with sector-specific requirements, including HIPAA business associate agreements and financial services and payments obligations.

Partner with Security and GRC

  • Serve as legal counsel to the Security organization on security commitments, control frameworks, and audit and certification programs (SOC 2, ISO 27001, HIPAA, PCI DSS, and additional frameworks as needed).
  • Lead the legal workstream in security incident response, including assessing breach notification obligations across jurisdictions and contracts, managing regulator and customer notification, directing outside counsel and forensics under privilege, and running tabletop exercises with Security.
  • Advise on law enforcement and government data requests, preservation obligations, and policies governing responses.
  • Support GRC/Compliance on customer security questionnaires, trust center content, and the accuracy of public privacy and security representations.

Requirements

  • Strong academic credentials and membership in good standing with at least one U.S. state bar.
  • 7-10+ years of relevant legal experience, with strong training at a top-rated national or international law firm.
  • Experience in law firm and in-house roles at a high-growth B2B SaaS company, preferably in the data infrastructure sector.
  • Significant experience advising on domestic and international privacy and data protection matters.
  • Deep knowledge of global privacy laws and regulatory frameworks, including GDPR, HIPAA, CCPA/CPRA, other U.S. state and international privacy laws, cross-border data transfer requirements, and evolving privacy and data governance regulations.
  • Experience advising business and technical teams on privacy issues across the product lifecycle, including AI, machine learning, and emerging technologies (strongly preferred).
  • Experience supporting security matters, including customer-facing security commitments, security incident support, and related regulatory requirements (preferred).
  • Excellent judgment and strong business orientation, with the ability to translate complex legal issues into practical advice.
  • Strong interpersonal and communication skills, with the ability to work effectively with executives and cross-functional stakeholders.
  • Exceptional attention to detail, strong organizational skills, and the ability to manage multiple priorities in a fast-moving, high-growth environment.

Preferred Qualifications

  • Experience advising business and technical teams on privacy issues across the product lifecycle, including AI, machine learning, and emerging technologies.
  • Experience supporting security matters, including customer-facing security commitments, security incident support, and related regulatory requirements.

Compensation & Benefits

  • Targeted base salary range: $260,000 - $295,000, plus equity and a generous benefits package.
  • Actual compensation is determined based on factors including qualifications, number of years of directly relevant experience, and location.

Location

  • Location is not specified in the posting.

Don't miss out on remote legal roles