Overview
This role supports the organization’s legal and privacy/data protection programs through strategic counsel and vendor contract management. The position is focused on enterprise third-party risk management and data governance, including privacy and cybersecurity-related compliance initiatives.
Hybrid/remote work is supported, with onsite locations in Sioux Falls, SD, Phoenix, AZ, Louisville, KY, Troy, MI, Franklin, TN, and Easton, PA.
Responsibilities
- Provide legal support for data privacy, data protection, and cybersecurity programs, including development and maintenance of procedures, training, and guidance.
- Monitor and assess the effectiveness of internal data protection policies and procedures, including assistance with data subject access requests and security incidents; recommend amendments as applicable.
- Advise business partners on data protection and privacy laws, compliance, and best practices related to information technology and information security.
- Support regulatory change management in financial services by providing updates and guidance on the impact of new and changing laws.
- Lead support for vendor contract review, including preparing, adapting, and negotiating data protection contractual clauses and processes for client relationships, third-party vendor agreements, and sub-processor agreements. Ensure appropriate language when acting as a data controller and/or data processor, and provide guidance on risk mitigation and compliance with company policies and legal regulations.
- Collaborate with key business stakeholders across lines of business, including IT, Information Security, People & Culture, Treasury, and others as appropriate.
- Perform other legal support duties and responsibilities as required, assigned, or requested by the Deputy General Counsel and Chief Privacy Officer.
Requirements
- Juris Doctor degree required, with an active membership to practice in at least one U.S. state.
- 7+ years of legal experience as a practicing attorney in big law firms, governmental agencies, and/or in-house legal/compliance departments.
- Strong preference for demonstrated knowledge and experience in the financial services industry and with publicly traded companies.
- Extensive experience analyzing, interpreting, and applying state and federal regulations to vendor contracts and privacy programs.
- Working knowledge of privacy-related regulations associated with financial institutions. Experience with GDPR and CCPA a plus.
- Experience drafting complex technology and BaaS agreements.
- Proficient with technology, including Microsoft Office 365 (Word, PowerPoint, Excel, Outlook, Teams).
- Exemplary written and verbal communication skills.
Preferred Qualifications
- Prior in-house experience at a bank, fintech company, or financial services organization, particularly in privacy or vendor management functions.
Role-Specific Competencies
- Privacy & Data Awareness: Ability to apply privacy and data protection principles practically across commercial relationships and product offerings.
- Vendor & Third-Party Risk Management: Ability to assess and manage legal risk in third-party relationships, including evaluating vendor contracts and supporting enterprise risk management objectives.
- Stakeholder Management: Strong executive presence and ability to build relationships and influence stakeholders across business lines.
- Self-Direction: Intellectually curious and self-motivated, able to work independently.
- Adaptability: Willingness and flexibility to respond to evolving privacy regulations, vendor risk requirements, and organizational needs.
Compensation & Benefits
- Salary range: $104,000– $174,000
- Eligibility for an annual performance-based incentive opportunity.
- Comprehensive benefits package (for eligible employees) including health insurance, 401(k) retirement benefits, life insurance, disability benefits, paid time off, and more.
Location
Hybrid/remote with onsite locations in Sioux Falls, SD; Phoenix, AZ; Louisville, KY; Troy, MI; Franklin, TN; and Easton, PA.