Overview
The organization is seeking a Senior Counsel, Privacy & Security. This position is remote-friendly.
This role serves as a primary legal advisor on privacy, data protection, information security, and AI matters, with a principal focus on leading complex customer and vendor negotiations involving these requirements. The ideal candidate is an independent, self-starter who can operate with significant autonomy in a fast-paced, results-oriented environment and is comfortable using AI tools as part of daily legal responsibilities.
Responsibilities
Customer Contract Negotiations
- Lead negotiations and escalations involving privacy, data protection, information security, AI, HIPAA, and other specialized legal and regulatory requirements.
- Develop practical positions that address legal risk while supporting customer relationships and timely deal closure.
- Communicate complex legal and regulatory concepts clearly to internal audiences and effectively convey the organization’s positions to customers, their counsel, and their privacy and security teams.
- Anticipate objections and recurring points of friction, resolving independently or in collaboration with peers and senior staff.
Vendor Contract Negotiations
- Review and negotiate vendor terms involving privacy, security, AI, HIPAA, data use, and other specialized requirements.
- Coordinate with Procurement, Information Security, business owners, and other Legal teams to assess risk, establish appropriate safeguards, and resolve escalated issues.
Contract Templates and Legal Standards
- Create and maintain standardized agreements and supporting materials, including:
- Customer DPA
- Vendor DPA
- Customer Information Security Program Description
- Vendor Security Standards
- HIPAA Business Associate Agreement
- Customer AI terms
- Vendor AI terms
- Update templates to address regulatory developments, negotiation experience, and changes in products and operations.
Public-Facing Privacy and Trust Documentation
- Develop and maintain customer-facing privacy, data-use, security, and compliance materials.
Policies, Playbooks, and Legal Enablement
- Develop and maintain internal policies, negotiation playbooks, and practical guidance.
- Translate legal requirements and approved risk positions into repeatable processes that enable consistent decision-making across Legal and the business.
Requirements
- A qualified attorney admitted to practice in one or more states in the United States and a member of one or more state Bar(s) in good standing, with a license to practice law within the state employed.
- Seven-plus years of experience as in-house counsel (law firm experience helpful but not required).
- Substantial experience negotiating privacy, data protection, and information security terms in enterprise software transactions, on both the customer and vendor side.
- Deep working knowledge of global privacy and data protection law (including GDPR, U.S. state privacy laws, and international transfer mechanisms), information security requirements and frameworks, HIPAA, and emerging AI regulation.
- Successful completion of one or more IAPP certifications (CIPP, CIPM, AIGP) preferred.
- Demonstrated experience drafting and maintaining contract templates, playbooks, policies, and public-facing privacy documentation.
- Demonstrated knowledge of best-practice internal controls, procedures, risk surveillance, and escalation.
- Excellent oral and written communication, presentation, and interpersonal skills.
- Excellent negotiation skills.
- Demonstrated ability to communicate complex legal issues and solutions clearly and succinctly, and to develop credibility at all levels of the business organization.
- Proven analytical, time management, and problem-solving skills.
Preferred Qualifications
- IAPP certifications (CIPP, CIPM, AIGP).
Compensation & Benefits
Salary
- United States salary range: $180,000 - $200,000
- Final compensation will be determined by relevant work experience, education, certifications, skills, and geographic location.
Additional compensation and benefits
- You may be eligible for additional compensation, such as a bonus.
- Benefits may include medical, retirement, financial, wellness, time off, employee discounts, and others.
Location
Remote-friendly.
For roles in San Francisco and Los Angeles, the organization will consider for employment qualified applicants with arrest and conviction records pursuant to the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring.
This position involves access to software/technology subject to U.S. export controls. Any job offer made will be contingent upon the applicant’s capacity to serve in compliance with U.S. export controls.