Overview
The organization is hiring a second attorney to provide hands-on legal support across day-to-day matters. This role works directly with the CLO and covers a broad mix of commercial contracting and data privacy work. Expect to move between topics such as data licensing agreements, HIPAA de-identification questions, NDAs, vendor BAAs, and cross-border data transfer analysis—often within the same week.
The role focuses primarily on:
- Commercial contracts: drafting, redlining, and negotiation for data licensing, SOWs, NDAs, BAAs, DPAs, and vendor agreements.
- Data & privacy: HIPAA/CCPA/GDPR, de-identification strategy, business associate posture, privacy policies, cross-border data transfers, and emerging AI regulation.
The business will look to this attorney as a first point of contact for legal guidance. Work is handled through modern legal tooling and collaboration systems (including chat-based intake, documentation/tracking, template libraries, and AI-assisted triage and drafting). Requests arrive quickly and priorities shift.
Responsibilities
- Draft, negotiate, and close commercial agreements across data supply and demand sides, including data licensing agreements, SOWs, NDAs, BAAs, DPAs, and novel arrangements without existing templates.
- Counsel internal teams across the organization on data privacy matters, including HIPAA, de-identification, consent, provenance, GDPR/CCPA, and AI-specific regulation as it develops.
- Triage and manage a high-volume legal queue with dozens of active matters, determining what requires deep work, what needs fast answers, and what should be referred to outside counsel.
- Partner with technical teams and technical counterparties to communicate legal risk and requirements clearly in practical terms.
- Manage and coordinate outside counsel on specialist matters, keeping work moving, tightly scoped, and cost-conscious.
- Help build legal infrastructure over time, including templates, playbooks, intake processes, and AI-assisted workflows to improve throughput.
Requirements
- Negotiated and closed complex technology or data transactions end-to-end, ideally including data licensing and work opposite technical counterparties.
- Owned meaningful parts of a privacy program while understanding how the full set of requirements fit together, including HIPAA and de-identification decisions and GDPR/CCPA compliance, as well as DPAs and BAAs (not just reviewing others’ work).
- Kept pace with emerging regulations and understands not only what key requirements are, but why.
- Managed a high-volume legal queue with personal accountability for turnaround time; can triage effectively and know when 80% today beats 100% next week.
- Comfortable operating in ambiguity and proactive about finding information needed to make informed decisions.
- Experience in fast-moving environments where priorities change and legal structure is built as you go.
- Fluency with modern tools used for day-to-day legal work, including chat-based intake, documentation/tracking systems, and AI systems for triage and drafting.
- Strong communication and relationship skills, including the ability to advise colleagues under deadline pressure and negotiate across cultures and company sizes with practical, calm, solution-focused guidance.
- JD and active bar membership in at least one U.S. jurisdiction.
Preferred Qualifications
- In-house experience at a technology company shipping products with novel legal risk, ideally involving AI, training data, or health data.
- Experience negotiating data licensing agreements or other data-centric commercial deals.
- Familiarity with de-identification standards (Expert Determination, Safe Harbor) and the healthcare data ecosystem.
- Experience serving as an early or solo in-house lawyer, building intake, templates, and outside counsel relationships from scratch.
Compensation & Benefits
Compensation and benefits are not specified in the provided description.
Location
Location is not specified in the provided description.