
Senior Counsel, Data Privacy & Protection
Posted 23 hours ago

Posted 23 hours ago
This is a fully remote position, open to applicants in United States.
• Serve as a subject matter expert and advisor on laws pertaining to data privacy and protection.
• Provide guidance to legal and business teams regarding U.S. and international data protection regulations, data collection and utilization, privacy disclosures, transparency, and consent.
• Collaborate with colleagues in privacy and security to strengthen the privacy program and mitigate privacy risks.
• Assist in privacy impact assessments, vendor risk evaluations, and internal reviews using data mapping and inventory information.
• Create and oversee privacy training and awareness programs.
• Review, draft, and negotiate contracts involving AI, privacy, and data security terms with business partners and vendors.
• Draft, review, and negotiate Business Associate Agreements, Data Processing Agreements, Data Protection Agreements, and Security Agreements.
• Provide advice on data protection laws that impact business operations and contractual relationships.
• Counsel on new products and technologies while addressing privacy considerations.
• Offer legal advice during investigations related to unauthorized access, loss, or disclosure of personal data.
• Support enterprise-wide readiness for incident response and provide guidance on privacy and cybersecurity incident responses.
• Identify critical legal issues for the privacy compliance team and foresee potential privacy challenges.
• Advise Information Security, Compliance, and other stakeholders on strategy and intricate matters regarding privacy and data handling.
• Assist in the governance of AI and responsible-use frameworks while monitoring new AI privacy and data protection regulations.
• Collaborate with stakeholders to evaluate privacy risks linked to AI and automated decision-making systems.
• Support compliance obligations under HIPAA Privacy, including incident response and regulatory alignment.
• A Juris Doctor (JD) degree is mandatory.
• Membership in a U.S. state bar in good standing is required.
• A minimum of 8–12 years of experience as an active attorney.
• At least 5–10 years of direct, hands-on experience in providing legal advice on data privacy and security issues.
• Familiarity with privacy statutes, regulations, and guidelines, including CPRA, VDCPA, CMIA, state breach notification laws, HIPAA, GDPR, TCPA, and CAN-SPAM.
• Significant experience evaluating legal risks related to data protection, privacy, and AI.
• Experience in drafting and negotiating contracts and provisions related to AI, privacy, and security.
• Experience with data loss prevention and cybersecurity incidents, forensic investigations, breach notifications, and cybersecurity preparedness.
• Proven experience managing privacy and/or cybersecurity incident response initiatives.
• Exceptional oral and written negotiation and communication abilities.
• Certifications in Privacy and AI such as CIPP-US, CIPP-C, CIPP-E, CIPM, AIGP, and CHPC are advantageous.
• Experience and interest in emerging technologies, particularly in healthcare and life sciences, is preferred.
• Strong skills in organization, teamwork, work ethic, multitasking, prioritization, initiative, project leadership, and both independent and collaborative work.
• Detail-oriented and self-driven.
• A strong commitment to integrity and professionalism, along with a demonstrated passion for excellence.
• Medical
• Dental
• Vision
• Life Insurance
• 401k
• Paid Time Off
• Flexible work environment
hims & hers
BECU
First American
Axiom
Get handpicked remote jobs straight to your inbox weekly.