
Product & Privacy Counsel
Posted 22 hours ago

Posted 22 hours ago
This is a fully remote position, open to applicants in United States.
• Act as a daily legal advisor to the Product and Engineering teams regarding new products, features, integrations, and changes.
• Offer legal counsel throughout the product lifecycle, from initial design and development to launch and ongoing operations.
• Identify and provide guidance on legal and regulatory factors related to product functionality, data usage, telemetry, logging, APIs, integrations, and new technologies.
• Perform legal assessments of new products and features, and create practical strategies to mitigate identified risks.
• Counsel on product terms, disclosures, customer documentation, and legal obligations tied to product launches.
• Convert legal prerequisites into practical and scalable product controls in collaboration with Product, Engineering, Security, and Compliance teams.
• Advise on the development, deployment, and utilization of AI and other cutting-edge technologies.
• Create scalable playbooks, guidelines, and processes to identify legal requirements earlier in product development.
• Assist in managing and expanding Horizon3’s global privacy program.
• Provide advice on global privacy and data protection laws, including GDPR, UK GDPR, CCPA/CPRA, U.S. state privacy statutes, and emerging privacy regulations.
• Integrate privacy-by-design principles into products, systems, and business processes, including conducting and maintaining PIAs, DPIAs, and related evaluations.
• Counsel on obligations of controllers, processors, and subprocessors, along with evolving data processing activities.
• Oversee and provide advice on cross-border data transfer requirements, including SCCs, transfer impact assessments, and the Data Privacy Framework.
• Advise on data subject rights, retention and deletion practices, subprocessors, privacy notices, and privacy operations.
• Draft, review, negotiate, and sustain DPAs and other privacy and data protection agreements.
• Maintain and improve privacy policies, notices, internal guidelines, and customer-facing privacy resources.
• Collaborate with Security and Compliance on privacy incidents, regulatory obligations, audits, and customer diligence.
• Keep abreast of global privacy law changes and interpret these changes into actionable business requirements.
• Support enterprise customer negotiations and diligence regarding product, privacy, data protection, and emerging technology matters.
• Develop templates, playbooks, guidelines, and self-service resources.
• Provide pragmatic advice that balances legal obligations with product goals, customer expectations, and business priorities.
• J.D. from an accredited law institution.
• Active membership in good standing with at least one U.S. state bar.
• Over 4 years of relevant legal experience, particularly in product/technology counseling and privacy or data protection.
• Experience advising technology companies in sectors such as SaaS, cybersecurity, and software.
• Strong understanding of GDPR and UK GDPR.
• Strong understanding of CCPA/CPRA and U.S. state privacy laws.
• Strong understanding of DPAs, SCCs, and cross-border data transfer protocols.
• Strong understanding of privacy-by-design principles and conducting product privacy reviews.
• Experience collaborating directly with Product and Engineering teams.
• Ability to comprehend technical products, data flows, software architecture, APIs, and cloud services to identify and advise on legal and privacy risks.
• Strong legal judgment and capability to provide practical, risk-based recommendations.
• Excellent drafting, written and verbal communication, and project management skills.
• Proven ability to manage multiple priorities independently in a fast-paced, high-growth environment.
• U.S. work authorization is required; candidates must be legally authorized to work in the United States.
• Preferred: In-house experience at a SaaS, cybersecurity, AI, cloud, or other rapidly growing technology company.
• Preferred: Experience advising on AI, machine learning, or regulations concerning emerging technologies.
• Preferred: Familiarity with the EU AI Act, EU Data Act, or cybersecurity regulatory frameworks.
• Preferred: Experience conducting PIAs, DPIAs, TIAs, or similar privacy and data protection evaluations.
• Preferred: Familiarity with SOC 2, ISO 27001, or other security and compliance frameworks.
• Preferred: Experience supporting enterprise customer privacy and technology negotiations.
• Preferred: CIPP/US, CIPP/E, CIPM, or similar privacy certifications.
• Equity package in the form of stock options for all full-time positions.
• Health, vision, and dental insurance for you and your family.
• Flexible vacation policy.
• Generous parental leave.
• Opportunities for career development.
• An inclusive workplace culture.
• Options for remote and hybrid work models based on role and location.
• A collaborative environment that fosters creativity and innovative thinking.
AUMOVIO
GEICO
Praxis
Optro
Get handpicked remote jobs straight to your inbox weekly.