
Director, Legal
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in United States.
• Oversee the daily operations of the global privacy program.
• Stay updated on new laws and regulatory guidance to ensure compliance before effective dates.
• Draft, update, and enhance privacy policies, notices, standards, records of processing, data maps, retention schedules, and internal guidance documents.
• Perform and document data protection impact assessments, transfer impact assessments, and privacy evaluations.
• Collaborate with product counsel, Product, and Engineering teams to integrate privacy by design into product development.
• Provide guidance on data minimization, purpose limitation, transparency, access, sharing, retention, technical specifications, and data flows.
• Act as the primary privacy contact for security and privacy incidents.
• Evaluate notification obligations and handle inquiries from regulators and customers in collaboration with Security Operations and external counsel.
• Escalate and provide advice on privacy terms in agreements with customers, partners, resellers, and vendors.
• Maintain data processing agreements, subprocessor disclosures, standard contractual clauses, and business associate agreements.
• Manage data subject requests, privacy escalations, and privacy diligence for customers and prospects.
• Develop playbooks, templates, and training materials for internal teams.
• Oversee external counsel and privacy tooling vendors, ensuring effective scope management, budget adherence, and quality of deliverables.
• Report directly to the VP of Commercial & Privacy.
• Juris Doctor (J.D.) from an accredited law school.
• Active membership in good standing with at least one U.S. state bar.
• Minimum of seven years of relevant legal experience, encompassing substantial privacy and data protection work, along with significant in-house experience at a technology firm.
• Extensive knowledge of GDPR, CCPA/CPRA, other major global privacy frameworks, and the evolving AI regulatory landscape.
• Proven experience in managing a privacy program, including conducting assessments, maintaining records of processing, handling data subject requests, vendor reviews, and advising Product and Engineering on privacy by design and technical data flows.
• Experience in supporting privacy and security incident response, including breach analysis and regulator inquiries.
• Strong skills in drafting and negotiating data processing agreements, standard contractual clauses, and privacy and security terms in commercial contracts.
• Excellent business judgment with a risk-based, solutions-oriented mindset, demonstrating an AI-first approach, adaptability to ambiguity, and a strong sense of ownership in a dynamic environment.
• Experience in a cybersecurity, security software, or managed security service provider setting, including familiarity with security telemetry, log data, threat intelligence data flows, and channel/MSP data-sharing arrangements.
• Background checks are mandatory for this position.
• Employment offer may be contingent on authorization to access software or technology governed by U.S. export control laws and regulations.
• IAPP certification such as CIPP/US, CIPP/E, CIPM, or CIPT is highly preferred.
• Familiarity with public sector customer privacy requirements across state, local, and educational markets in the U.S., Canada, Australia, and Europe is preferred.
• Equity options for all employees.
• Flexible time off and paid volunteer days.
• RRSP and 401(k) matching contributions.
• Training and career development opportunities.
• Comprehensive private benefits package including medical, mental health, dental, disability, life and AD&D insurance, and additional value-added services.
• Robust Employee Assistance Program (EAP) offering mental health services.
• Fertility assistance and paid parental leave.
• Variable incentive compensation.
• Equity grants for new hires.
DS Smith
Life360
NerdWallet
Automattic
Get handpicked remote jobs straight to your inbox weekly.