
Associate General Counsel, Privacy
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in United States.
β’ Oversee the global privacy legal function of the company and act as the primary legal advisor on both domestic and international privacy and data protection issues.
β’ Collaborate with the Security Team and business units to create practical, business-focused solutions for complex privacy challenges.
β’ Develop a scalable and thoroughly documented privacy program that addresses privacy obligations, customer commitments, and regulatory risks.
β’ Provide guidance on GDPR, HIPAA, CCPA/CPRA, U.S. state privacy laws, international privacy legislation, and data transfer regulations.
β’ Manage the data subject request procedure and the privacy aspects of vendor and subprocessor due diligence.
β’ Monitor regulatory developments and enforcement actions, and adapt product, contract, and internal practices accordingly.
β’ Conduct and supervise Data Protection Impact Assessments (DPIAs), transfer impact assessments, and associated privacy risk documentation.
β’ Enhance program elements such as data subject rights, privacy notices, consent management, impact assessments, and policy governance.
β’ Maintain comprehensive records of processing activities, data inventories and mappings, retention timelines, assessments, policies, and notices.
β’ Provide privacy and security training to staff and promote internal awareness.
β’ Oversee external legal counsel and privacy vendors within budget constraints.
β’ Act as or manage the relationship with the EU representative and the data protection officer.
β’ Advise the Marketing team on adtech, cookies, tracking technologies, and compliance with electronic marketing regulations.
β’ Report privacy and security risks to leadership and assist with Board and audit reporting.
β’ Collaborate with product and engineering teams to embed privacy-by-design principles.
β’ Provide guidance on data residency, localization, telemetry, encryption, key management, access controls, logging, anonymization, pseudonymization, retention, and deletion practices.
β’ Counsel on AI and machine learning functionalities, including training data provenance, customer data limitations, model and vendor agreements, and forthcoming AI regulations.
β’ Develop negotiation strategies for Data Processing Agreements (DPAs) and negotiate privacy and security clauses in customer and vendor contracts.
β’ Support enterprise, public sector, and regulated industry transactions, including HIPAA business associate agreements and financial services obligations.
β’ Serve as legal counsel to the Security team regarding security commitments, control frameworks, and audit and certification processes.
β’ Lead the legal aspects of security incident response, including breach notifications, communications with regulators and customers, coordination with external counsel and forensics, and conducting tabletop exercises.
β’ Provide counsel on law enforcement and governmental data requests, preservation responsibilities, and response policies.
β’ Assist Governance, Risk, and Compliance (GRC) and Compliance teams with security questionnaires, trust center information, and public representations of privacy and security.
β’ Strong academic credentials.
β’ Active membership in good standing with at least one U.S. state bar.
β’ 7-10+ years of pertinent legal experience.
β’ Comprehensive training from a highly regarded national or international law firm.
β’ Experience in both law firm and in-house settings, particularly within a rapidly growing B2B SaaS company, ideally in the data infrastructure sector.
β’ Extensive experience advising on privacy and data protection matters on both domestic and international levels.
β’ In-depth understanding of global privacy laws and regulatory frameworks, including GDPR, HIPAA, CCPA/CPRA, other U.S. state and international laws, and cross-border data transfer regulations, along with evolving privacy and data governance standards.
β’ Preferred experience in advising business and technical teams on privacy considerations throughout the product lifecycle, particularly in relation to AI, machine learning, and emerging technologies.
β’ Preferred experience in supporting security-related matters, including commitments to customers regarding security, incident response, and related regulatory obligations.
β’ Excellent judgment, a strong business focus, and the ability to translate complex legal challenges into practical guidance.
β’ Strong interpersonal and communication skills, with the capability to work effectively with executives and cross-functional teams.
β’ Exceptional attention to detail, robust organizational abilities, and the capacity to manage multiple priorities in a dynamic, high-growth environment.
β’ Equity.
β’ Comprehensive benefits package.
The Federal Appeals Firm
Instacart
Instacart
Instacart
Get handpicked remote jobs straight to your inbox weekly.