Sr Counsel, Data Governance

Unlock Employer

Posted Sep 16, 2026

Remote · US · ask about Worldwide Full Time
$204K – $226K/yr

Overview

This role is responsible for the legal and regulatory strategy for data use, with a focus on data governance and AI governance. You will negotiate and operationalize how data is collected, used, shared, retained, reused, and applied to AI—ensuring agreements provide the rights needed to operate and innovate while meeting regulatory and contractual obligations.

You will report to the Chief Compliance and Privacy Officer and partner closely with senior leaders across Sales, Technology, Product, Security, and other functions on high-impact business decisions. This is an owner-operator role: you will not only advise, but also negotiate, build, implement, maintain, run, monitor, audit, and remediate privacy, data governance, and AI governance programs and controls.

Responsibilities

  • Lead negotiations on data rights across new and existing client and partner agreements, including BAAs, DPAs, data use agreements, data sharing agreements, and other agreements governing data rights and obligations.
    • Cover data use, sharing, ownership, secondary use and reuse, AI use and training, system outputs, and data-related intellectual property rights.
    • Manage retention, de-identification, deletion, disclosure, and downstream use.
    • Proactively identify and renegotiate existing agreements to secure appropriate rights and manage regulatory and contractual risk.
  • Lead day-to-day operation of the organization’s Privacy Program, including:
    • HIPAA and state privacy and consumer health data requirements
    • Privacy notices and consents
    • Consumer rights
    • Privacy incidents and breach determinations
    • Required notifications
    • Regulator inquiries
    • Ongoing compliance
  • Lead day-to-day operation and administration of the organization’s AI governance program, including:
    • Interpretation and implementation of federal and state AI laws and regulatory requirements
    • AI Governance Committee processes
    • Governance framework, policies, procedures, and approval processes
    • AI system and use-case inventory
    • Risk assessments and responsible AI controls
    • Governance records
    • Regulatory change management
  • Interpret and implement the legal and regulatory framework for data governance, including requirements for:
    • Data collection, use, sharing, secondary use and reuse, and AI use
    • Retention, de-identification, deletion, disclosure
    • Residency and cross-border transfers
    • Translate changing requirements into practical policies, controls, procedures, and implementation plans
  • Build and maintain systems and controls that operationalize data governance, including:
    • Data maps and records of processing
    • Data classification and handling standards
    • Contractual obligation repositories and processes for translating contractual obligations into operational controls
    • Accountable owners, implementation requirements, and evidence of compliance
    • Retention and disposal requirements
    • Vendor and third-party privacy and data reviews and data-use controls
  • Partner with Product, Engineering, Security, AI, Commercial, User Support, and other teams to implement privacy, data, and AI requirements, including:
    • Privacy by design
    • Permissible data and AI uses
    • Product notices and consents
    • Technical and operational controls
    • Processes for addressing consumer and user questions
    • Serve as the day-to-day escalation point for privacy, data rights, permissible data use, and AI governance questions
    • Escalate material risks to the Chief Compliance and Privacy Officer
  • Lead day-to-day privacy, data, and AI risk and incident management, including:
    • Conducting assessments
    • Leading privacy, data, and AI aspects of incident response and breach analysis
    • Escalating material risks
    • Coordinating required notifications and corrective actions
    • Driving remediation through completion
  • Lead privacy, data, and AI compliance monitoring and assurance, including:
    • Audits
    • Client audits
    • Regulatory inquiries and investigations
    • Certifications, attestations, client trust and assurance requests
    • Review of representations regarding privacy, data, and AI practices
    • Monitor compliance and drive remediation when gaps are identified
  • Build and maintain policies, playbooks, training, and reporting for privacy, data governance, AI governance, responsible AI, and data rights, including training for Product, Engineering, Commercial, User Support, and executive reporting on program performance, risk, findings, and remediation.

Qualifications

  • 8+ years of legal experience with substantial healthcare regulatory, privacy, and compliance experience in a HIPAA-regulated organization. Healthcare experience is required.
  • Significant experience negotiating complex data rights with sophisticated enterprise clients and partners, including large health plans and healthcare organizations.
    • Must be able to independently lead difficult negotiations involving data use, ownership, AI rights, secondary use, retention, deletion, de-identification, and related restrictions.
  • Experience operating healthcare privacy and compliance programs, including regulatory interpretation, incident and breach response, risk assessment, monitoring, auditing, corrective actions, and remediation.
  • Strong compliance judgment and an owner-operator mindset, with the ability to move from legal interpretation to practical implementation and drive issues through resolution.
  • Advanced AI fluency and automation capability, including using AI extensively in substantive legal and compliance work.
    • Comfortable building and using AI agents to increase speed, quality, consistency, and leverage in a lean team.
  • Experience with AI governance, including emerging AI laws, risk assessments, approval workflows, inventories, responsible AI controls, and monitoring.
  • Exceptional judgment, executive presence, and communication skills.
    • Ability to represent the organization in high-stakes negotiations, defend well-reasoned positions, and challenge sophisticated internal and external stakeholders when necessary.
  • Active license to practice law and membership in good standing with a U.S. state bar.

Preferred Qualifications

  • Experience with international privacy and data protection requirements, including cross-border data transfers.
  • Privacy or AI governance certifications such as CIPP/US, CIPM, or AIGP.
  • Experience building privacy or AI governance programs at a growth-stage or high-growth company.
  • Experience managing client trust, security questionnaires, certifications, attestations, or enterprise customer assurance programs.

Compensation & Benefits

  • US base salary range (full-time): $204,000.00 to $226,000.00.
  • Salary ranges are determined by role and level. Compensation is determined by additional factors, including job-related skills, experience, and relevant education or training.
  • Compensation details listed in US role postings reflect the salary only and do not include equity or benefits.

Location

  • United States (US role posting salary range provided).

Don't miss out on remote legal roles