Overview
A leading organization in family history and personal DNA testing is seeking a Senior Counsel, Data Security & Governance. This role provides practical, business-focused legal guidance across data protection, information security, third-party risk, AI governance, and incident response. The position involves close collaboration with Security, Privacy, Product, Engineering, Data Science, Procurement, and Compliance teams to support a risk-based governance program that protects users and enables responsible growth.
Responsibilities
- Advise on global data protection, data governance, and cybersecurity requirements applicable to products, services, and internal operations
- Partner with Information Security to support governance of security programs and frameworks aligned with industry standards such as ISO, NIST, and SOC 2
- Provide legal oversight for third-party risk management, including vendor privacy and security reviews, risk assessments, and contractual protections
- Support product, engineering, and data science teams with privacy-by-design and security-by-design guidance throughout the product lifecycle
- Advise on legal, governance, and risk considerations related to AI and machine learning, including responsible use and impact assessments
- Serve as legal counsel for security incidents and data breaches, including assessment, escalation, notification obligations, and remediation support
- Review, assess, and respond to law enforcement, government, and regulatory requests for access to data
- Draft, review, and maintain data security, governance, and related policies, standards, and guidance
- Collaborate with cross-functional partners to operationalize governance requirements and drive consistent practices across the organization
- Monitor and interpret evolving privacy, cybersecurity, data governance, and AI-related laws, regulatory guidance, and enforcement trends
- Travel occasionally as needed
Requirements
- Juris Doctor (JD) or equivalent law degree from an accredited institution
- Active bar membership in at least one U.S. jurisdiction
- Minimum of 5 years of relevant legal experience advising on privacy, data protection, cybersecurity, or technology matters
- Experience counseling cross-functional teams in fast-paced, technology-driven environments
- Strong judgment and communication skills with the ability to deliver practical guidance under ambiguity
- Experience working with highly sensitive personal data
- Familiarity with information security and governance frameworks such as ISO, NIST, and SOC 2
- Experience supporting incident response, regulatory engagement, or AI governance initiatives
Compensation & Benefits
- Base salary range: $164,000 - $205,000, varying by geographic region and job experience
- Eligibility for bonus and equity
- Comprehensive benefits including health, dental, and vision coverage
Location & Work Arrangement
- Flexible work approach allowing choice of nearest office, remote work, or hybrid arrangements (subject to location restrictions and role requirements)
- Occasional travel as needed
Equal Opportunity
This employer is an Equal Opportunity Employer and makes employment decisions without regard to race, color, religious creed, national origin, ancestry, sex, pregnancy, sexual orientation, gender, gender identity, gender expression, age, mental or physical disability, medical condition, military or veteran status, citizenship, marital status, genetic information, or any other characteristic protected by applicable law. Reasonable accommodations are provided for qualified individuals with disabilities.
Additional Information
- Employment offers are contingent on background checks compliant with applicable law
- For candidates in San Francisco, CA, qualified applicants with arrest and conviction records will be considered in accordance with local ordinances
- The organization does not accept unsolicited assistance from search firms for this position; resumes submitted without a valid agreement will be considered the organization's property with no fee obligation