Privacy Law Job Listings

Background Pink

Privacy Law Job Listings - TeachPrivacy Training 01

 

PRIVACY LAW JOB LISTINGS

This page gathers privacy job listings. Check links for further details, including salary, qualifications, location, and responsibilities. We advise you to apply even if you don’t quite meet requirements for years of experience, as employers often don’t adhere strictly to such requirements. Please write to us if you know of privacy law job listings we should include.

NOTE: As we often don’t know when positions are filled, not all positions listed on this page are still open.  Posted dates are approximations.

*  *  *

Yahoo – Privacy Counsel

Responsibilities:

  • Partner closely with product, engineering, and business teams throughout the product lifecycle, embedding privacy by design into new advertising products and features from ideation through launch.
  • Advise on the privacy implications of advertising technologies, including AI enabled products, machine learning models, personalization, identity resolution, cookie alternatives, first party data strategies, retail media, clean rooms, measurement technologies, and evolving addressability solutions.
  • Counsel product teams on U.S., Canadian, and global privacy laws, helping translate complex legal requirements into practical product guidance that supports innovation.
  • Advise on consent management frameworks, including Global Privacy Control (GPC), Global Privacy Platform (GPP), IAB Transparency & Consent Framework (TCF), and other industry standards, ensuring Yahoo’s platforms appropriately implement evolving privacy signals.
  • Structure, draft, review, and negotiate privacy and data protection provisions in commercial agreements, including MSAs, DPAs, data licensing agreements, and strategic technology partnerships.
  • Advise on cross border data transfers, international privacy compliance, Standard Contractual Clauses, and other global data governance requirements.
  • Partner with cross functional teams to conduct privacy impact assessments, AI risk assessments, and data protection reviews for new products and initiatives.
  • Support privacy incident response, advising on legal obligations, regulatory notification requirements, and coordination with security, communications, and outside counsel.
  • Design scalable legal infrastructure, including playbooks, templates, AI-enabled workflows, and self service guidance, that enables product teams to move quickly while maintaining compliance.
  • Represent Yahoo in industry organizations and standards bodies, including the IAB, NAI, DAA, and similar forums, helping shape the future of responsible digital advertising.

Posted July 15, 2026

Coursera – Senior Privacy Counsel

Responsibilities:

  • Global subject matter expert: Serve as the primary legal advisor on US privacy laws, including federal and state frameworks (such as CCPA/CPRA), while providing guidance on applicable global privacy and privacy-adjacent laws, including the EU and UK GDPR and key APAC and Latin American frameworks. Advise the business on legal and regulatory developments and their practical impact.
  • Privacy Program: Help to continuously develop, implement, and scale Coursera and Udemy’s global privacy program, including by developing and maintaining standardized privacy notices, internal policies, tools, processes, playbooks, and training.
  • Delivering Legal Guidance: Support and advise key stakeholders on a broad range of complex privacy, AI, and cyber issues and provide pragmatic and risk-based solutions in accordance with global privacy laws.
  • Incident reporting: Investigate and manage security incidents that impact personal information, together with Engineering, InfoSec and other stakeholders.
  • Regulatory responses: Respond to requests and inquiries from individuals and privacy regulators.
  • Strategic leadership: Act as a trusted advisor to senior leadership on privacy risk and strategy, and mentor and support other members of the Privacy and broader Legal and Compliance teams.

Posted July 15, 2026

MetLife – AVP & Assistant General Counsel, Privacy

Responsibilities:

  • Provide advice and counsel on legal and regulatory matters involving privacy having a potential global impact and requiring coordination across regions and businesses.
  • Identify and resolve legal issues and offer commercially viable solutions through research, analysis, creativity and teamwork that contribute to global business goals while ensuring appropriate management of legal risks.
  • Stay current on developments affecting privacy law around the world, including its intersection with technology and AI law.
  • Act as a trusted advisor and partner to Privacy Compliance, Global Government Relations, Global Technology & Operations, Employment Law, Human Resources and other business areas in developing and advocating positions to advance MetLife’s interests.
  • Negotiate and document privacy provisions in complex agreements, including vendor, customer and M&A agreements.

Posted July 14, 2026

RingCentral – Senior Privacy Counsel

Responsibilities:

  • Act as the dedicated privacy legal point of contact, providing proactive, risk-based counsel to Engineering and Product Management teams throughout the entire development lifecycle of new services and features.
  • Provide specialized legal advice on the privacy implications of any new features, including AI features, in collaboration with the Product Counseling and Regulatory Teams, ensuring compliance with emerging AI regulations and ethical guidelines as it relates to privacy.
  • Lead the execution and documentation of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new features and services, driving legal processes that embed privacy requirements early in the development process, in coordination with other Privacy Team Members.
  • Ensure that RingCentral services comply with evolving global privacy and security regulations.
  • Partner directly with the Information Security team to review product security controls, conduct risk analyses, align legal privacy requirements with technical security implementation for all new products, including as it relates to HIPAA, and ensure that security policies align with and take into account requirements for the protection of personal information.
  • Develop and update customer-facing collateral and resources on RingCentral Trust Centerto support transparency for customers and partners.
  • Support records of processing activities and documentation for products including data locations, data transfers, and subprocessor processing in coordination with other Privacy Team members.
  • Support the incident response program, by ensuring that the documentation is current and in alignment with applicable laws and by representing the privacy team in the incident response activities.
  • Monitor legal developments, collaborate and build relationships with industry peers, to stay abreast of trends and issues globally, as they may impact RingCentral’s privacy posture, templates, and commercial practices.

Posted July 14, 2026

NVIDIA – Senior Counsel, Data Privacy and Governance

Responsibilities:

  • Advising the HR and Recruiting teams on privacy requirements applicable to the collection, use, and retention of employee and candidate personal data, including background check data, assessment results, and hiring records.
  • Reviewing and negotiating vendor contracts and data processing agreements (DPAs) with HR technology vendors, background screening providers, recruiting platforms, and other third-party processors handling workforce data.
  • Advising on cross-border employee and applicant data transfers, including transfer impact assessments and applicable safeguards under GDPR, PIPL, and other international frameworks.
  • Counseling on privacy considerations related to AI-assisted recruiting tools, applicant tracking systems, automated decision-making, and workforce analytics, including obligations under emerging algorithmic transparency and automated decision laws.
  • Supporting employee-facing privacy notices, data subject rights requests from employees and candidates, and related HR data governance policies.
  • Tracking legal developments in employment privacy, including U.S. state laws and international regulations affecting the HR and recruiting lifecycle, and translating those developments into practical guidance.
  • Growing into broader privacy and data governance responsibilities as the program evolves.

Posted July 8, 2026

Uber – Counsel – Privacy & Cybersecurity Legal

Responsibilities:

  • Advise Uber product and engineering teams regarding data privacy and cybersecurity requirements, best practices, and Uber’s Privacy Principles
  • Drive privacy-by-design and -default throughout Uber’s product development process
  • Track and research developments relating to new and pending laws that impact Uber’s privacy and cybersecurity program, including U.S. state laws and the EU’s GDPR, AI Act, and Platform Work Directive; translate that into practical, effective advice; and lead compliance efforts relating to these laws
  • Negotiate privacy requirements in third-party agreements
  • Create and present engaging company-wide trainings regarding data privacy and security requirements and standard methodologies
  • Drive awareness regarding cutting-edge legal and business developments, including regarding use of AI and machine learning, and lead team efficiency, morale and collaboration efforts
  • Contribute to our ongoing mission to make magic in the marketplace, and drive Uber’s efforts to be a trusted steward of our users’ personal data in every market where Uber operates

Posted July 8, 2026

Lyra Health – Privacy & AI Counsel

Responsibilities:

  • Support Lyra’s privacy program and advise internal stakeholders on privacy concerns related to Lyra’s products and services, and the implementation of new technologies, such as AI.
  • As a core component of the role, participate extensively in AI use case reviews, including those involving generative AI and agentic AI for internal use at Lyra, and in legal reviews and assessments relating to the development by Lyra of AI-powered products, services, and tools. Drive the AI use case review process forward to meet established SLAs, ensuring the business remains agile.
  • Draft, maintain, and evolve AI governance documentation, including the Company’s Responsible AI Policy and related standards, procedures, and guidance.
  • Coordinate with internal teams to ensure corporate adherence to applicable state and federal privacy laws, including, but not limited to, CCPA and HIPAA.
  • Stay abreast of, analyze, and advise on evolving US laws and regulations relating to privacy and AI at both the state and federal level. Update the legal team and the business on relevant new regulatory requirements and feed into policy and procedural documentation.
  • Support international AI regulatory compliance by partnering with the Privacy Counsel, International on the EU AI Act and other global AI regulations, including leading horizon scanning efforts and proactively delivering insights and updates to the legal team and broader Lyra business.
  • Collaborate with commercial counsel to ensure that privacy provisions in commercial agreements and Business Associate Agreements (BAAs) appropriately manage risk and comply with privacy policies, laws, rules, regulations, and company objectives.
  • Review BAAs negotiated by commercial counsel and document data use permissions for new and existing customers.
  • Work cross-functionally to advise product and business teams on potential privacy and AI regulatory implications of Lyra’s new and existing product lines, including reviewing and approving product requirement documents (PRDs).
  • Investigate, manage, document and report privacy incidents, including breaches, in accordance with applicable law, contractual requirements and corporate strategy.
  • Participate in cross-functional teams working on AI governance and AI use case reviews.

Posted July 4, 2026

Nordstrom – Senior Corporate Counsel, Privacy (Hybrid, Seattle)

Responsibilities:

  • Serve as the primary legal advisor on U.S. state privacy laws, including CCPA/CPRA, and the growing patchwork of state comprehensive privacy statutes (Virginia, Texas, Colorado, etc.)
  • Lead and maintain the company’s U.S. privacy compliance program, including privacy notices, consent mechanisms, opt-out frameworks, and data subject rights processes
  • Monitor legislative and regulatory developments in U.S. privacy law and advise on required compliance changes in the context of rapidly evolving business processes
  • Monitor and assess emerging AI legislation, regulatory guidance, and enforcement trends across federal, state, and international jurisdictions, and advise on their practical implications for Nordstrom’s use of AI and automated decision-making

Posted July 3, 2026

Light & Wonder – Senior Counsel, AI and Data Governance

Responsibilities:

  • Serve as legal advisor on the Company’s enterprise-wide adoption, deployment, and use of AI and machine learning tools, including generative AI platforms and AI-enabled products.
  • Monitor, analyze, and advise on the rapidly evolving global AI regulatory landscape, including the EU AI Act, US federal and state AI legislation, and emerging frameworks across key jurisdictions (UK, Canada, Brazil, India, Australia, Singapore/APAC).
  • Support the Company’s AI governance framework, including internal policies, standards, and acceptable use guidelines governing the procurement, deployment, and employee use of AI tools.
  • Assess and classify AI systems in accordance with applicable regulatory risk tiers (e.g., EU AI Act high-risk classifications) and advise product, engineering, and business teams on applicable compliance obligations.
  • Provide legal guidance on AI-specific risks including algorithmic bias and discrimination, risks related to AI use in connection with employment and transparency obligations.
  • Work with the Legal Department’s IP team on risks related to IP ownership issues arising from AI-generated outputs.

Posted July 2, 2026

Walmart – Senior Counsel, Health Privacy

Responsibilities:

  • Provide expert guidance on HIPAA, state health privacy laws, and emerging regulations.
  • Lead health data privacy risk identification and mitigation, developing compliance programs and frameworks with cross-functional partners.
  • Advise on AI and health data issues, including data provenance, algorithmic decision-making involving PHI, and AI governance.
  • Support breach response and regulatory reporting.
  • Draft and negotiate health data and services contracts.
  • Develop privacy policies, playbooks, and training materials.
  • Partner with compliance, product, and technology teams on emerging health privacy and AI legislation.
  • Foster strong partnerships with business leaders to align legal strategies with corporate goals.

Posted June 30, 2026

Charles Schwab – Director, Legal Counsel, Data Privacy and Cybersecurity

Responsibilities:

  • Regulatory Compliance and Risk Advisor: Provide legal guidance on U.S. and global privacy and cybersecurity laws, regulations, and enforcement trends. Interpret evolving regulatory guidance and translate supervisory expectations into actionable legal advice. Monitor emerging issues including AI governance, data ethics, digital identity, and advanced cyber threats. Advise on privacy-by-design and security-by-design, data minimization and retention, cross-border data transfers, access controls, and other data-related issues.
  • Incident Response and Cyber Events: Lead the legal response to privacy and cybersecurity incidents, including investigation, legal risk assessment, and regulatory and contractual analysis. Coordinate closely with internal stakeholders and external forensic firms, outside counsel, and crisis management advisors. Advise on notification obligations, litigation risk, and regulatory engagement arising from cyber events.
  • Commercial Transactions and Technology Enablement: Advise on privacy and cybersecurity issues across commercial transactions, including vendor engagements, cloud services, SaaS platforms, fintech partnerships, strategic investments, and M&A. Draft, negotiate, and approve data protection and information security provisions in customer, vendor, and partner agreements.
  • Emerging Technology and Innovation: Advise on privacy, data protection, and cybersecurity considerations related to the design, development, and deployment of artificial intelligence, advanced analytics, and other data-driven products and business models.
  • Litigation and Investigations: Support the company’s management of privacy- and cybersecurity-related litigation, regulatory enforcement matters, inquiries, and internal investigations.
  • Education and Enablement: Educate legal, technology, and business teams on privacy and cybersecurity requirements in a pragmatic, business-focused manner. Identify and support efforts to scale consistent, risk-based legal guidance across the enterprise.

Posted June 29, 2026

Memorial Sloan Kettering Cancer Center – Assistant General Counsel, Privacy

Responsibilities:

  • Serve as subject matter expert to business, clinical, and research teams across MSK. Advise on key legal questions related to privacy by gaining detailed insight into business areas. Perform detailed legal research as needed and provide timely, effective advice.
  • Manage MSK’s operational compliance with GDPR and other global-privacy frameworks.
  • Advise other members of the MSK legal team on data privacy laws and collaborate on transactions led by those team members.
  • Lead negotiation of HIPAA Business Associate Agreements with MSK’s IT and supply chain vendors.
  • Draft, update, and regularly review consumer-facing privacy notices for MSK digital properties; Advise the Development, Marketing and Communications, and other digital teams on use of cookies, pixels and other trackers on MSK digital properties.
  • Provide legal guidance to other members of the Compliance team in their management of privacy-related inquiries from patients and staff.
  • Collaborate with departments across the organization, including clinical, research, hospital administration, IT, procurement, and Information Security departments, and MSK’s AI Governance Council to develop and enhance policies governing MSK’s use of personal data (PHI, PII).
  • Stay abreast of new domestic and global privacy and data protection requirements and assess their impact on existing operations and strategic plans.

Posted June 26, 2026

Engine – Sr. Data Privacy & Risk Counsel

Responsibilities:

  • Core Privacy & Risk Architecture: Craft and execute innovative strategies to build and operate Engine’s enterprise data privacy, AI governance, and risk management function, ensuring Engine stays ahead in the regulatory landscape.
  • Cross-Functional Risk Integration: Collaborate with cross-functional teams like Security, Product, and Finance to unlock new opportunities and deliver seamless, legally compliant experiences for our customers.
  • Program & Framework Leadership: Lead the design and implementation of automated workflows (such as CCPA/CPRA handling) and structured frameworks (including AI governance and tiered vendor risk programs) to enhance efficiency, scalability, and corporate compliance.
  • Strategic Legal Advisory: Provide exceptional support and insights to our clients and internal partners, ensuring every risk evaluation and incident response interaction with Engine exceeds expectations.

Posted June 26, 2026

Applied Intuition – Senior Counsel, Privacy & AI Governance

Responsibilities:

  • Own and operationalize the global privacy program across the company
  • Lead AI governance strategy, policy development, and implementation
  • Advise Product, Engineering, Data Science, Security, and Go-to-Market teams on privacy, data protection, and responsible AI issues
  • Conduct privacy and AI impact assessments and support regulatory compliance efforts worldwide
  • Advise on cross-border data transfers, SCCs, adequacy frameworks, and other transfer mechanisms
  • Manage engagement with data protection authorities, outside counsel, regulators, and standards bodies
  • Build and maintain data mapping, records of processing activities, consent frameworks, and vendor privacy diligence processes
  • Support commercial transactions and product launches requiring privacy review

Posted June 24, 2026

WEX – Counsel, Privacy & Data Protection

Responsibilities:

  • Horizon scanning, monitoring and advising of any changes or developments in global privacy and data protection, artificial intelligence, automated decision-making, and cybersecurity laws and regulations that may impact WEX;
  • Working with the Director, Global Privacy and Data Protection, advising on best practices and compliance with privacy and data protection, artificial intelligence, automated decision-making, and cybersecurity laws globally with primary accountability for Canada, Brazil, India, Singapore and Australia;
  • Advising the commercial legal teams on the negotiation of privacy, data security, and artificial intelligence terms in contracts and drafting and maintaining related contract templates and guidance documents;
  • Assisting the third party assurance team on customer questions relating to privacy and AI practices;
  • Participating in the review of new business and commercial initiatives for privacy, cybersecurity, and artificial intelligence legal risks;
  • Advising the marketing team on privacy and AI matters relating to marketing campaigns and cookie compliance obligations;
  • Participating on cross-functional teams to advise on the development, updating, and maintenance of policies and procedures relating to privacy, data protection, cybersecurity, and artificial intelligence.
  • Maintain an understanding of relevant laws, regulations, industry standards, and policy trends relevant to WEX products and technology;
  • Counseling other members of the WEX legal team regarding privacy and data protection matters in various types of agreements, including software (and cloud/SaaS), data license, and professional services agreements and a variety of other general commercial contracts.
  • The ability to coordinate cross-functionally, and with outside counsel in domestic and international markets, on issues related to data privacy, cybersecurity, and artificial intelligence; and
  • Independently and in collaboration with the Privacy Compliance team, develop training materials and conduct training sessions for product and business teams.

Posted June 23, 2026

Fiserv – Privacy Senior Counsel

Responsibilities:

  • Advise business, product, engineering, legal, risk, and compliance stakeholders on AI, data, and privacy laws, including the Colorado AI Act, European Union Artificial Intelligence Act, General Data Protection Regulation, California Consumer Privacy Act, California Privacy Rights Act, Fair Credit Reporting Act, and related regulatory requirements
  • Partner with the AI Center of Excellence to review, document, and support approval of artificial intelligence, generative artificial intelligence, and agentic artificial intelligence use cases, including risk categorization, required safeguards, and approval conditions
  • Assess Fiserv’s compliance posture under applicable AI and privacy laws and help build scalable governance processes, documentation standards, monitoring approaches, and reporting practices that evidence compliance
  • Draft, review, and negotiate data privacy addendum including AI related provisions with clients and vendors, including data usage, licensing, security, privacy, model output, audit, compliance, transfer, and protection terms
  • Participate in client-facing meetings and vendor negotiations on privacy, data, AI, and governance matters
  • Develop and maintain governance policies, notices, procedures, training materials, and tools that support accountability and consistent enterprise practices
  • Monitor developments in AI and privacy laws, regulatory guidance, and enforcement trends and translate impacts into practical recommendations for internal stakeholders
  • Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.

Posted June 23, 2026

GoodRx – Privacy Counsel

Responsibilities:

  • Counsel on privacy assessments and product-related matters
  • Create and contribute to training, playbooks, and FAQ libraries for various teams to ensure they have the most current privacy guidance
  • Act as a subject matter expert on all matters relating to privacy law, including providing practical, timely, strategic, and high-quality legal advice on data privacy and security matters
  • Actively monitor, brief, and advise on privacy laws and new legislative and regulatory developments, including taking lead on developing and updating policies and procedures and developing and updating internal workplans to comply with upcoming data privacy regulations
  • Lead in reviewing marketing initiatives to ensure compliance with data protection laws
  • Overall support of the Privacy Program and risk management processes
  • Support with reviewing, drafting, and negotiating of privacy and data security terms in contracts with business partners and vendors, including data processing agreements and data protection terms
  • Support with vendor management for privacy, including managing vendor offboarding

Posted June 18, 2026

OpenAI – Counsel, AI Policy

Responsibilities:

  • Analyze proposed laws and regulations concerning AI to understand their impact on OpenAI and the broader AI community.
  • Collaborate across Legal and Global Affairs to develop policy positions.
  • Provide strategic analysis and advice to the Global Affairs team and other internal stakeholders.
  • Advise on evolving regulatory and industry standards affecting OpenAI’s business and customers.

Posted June 13, 2026

LA 2028 Olympic & Paralympic Games – Managing Counsel, Privacy and Data Security

Responsibilities:

  • Serves as the primary contact and liaison for all data security and protection related matters; coordinating with internal and external stakeholders including applicable government authorities and other partners.
  • Draft and update the privacy policies, terms of use, and consents for LA28 and USOPP’s various business lines.
  • Develop, implement, and maintain data protection and privacy procedures and processes for LA28 and USOPP, considering domestic and applicable international requirements.
  • Provide advice to a range of LA28’s business teams on implementation of privacy regulations and compliance with applicable privacy laws. Collaborate with technology, marketing, and other functional area teams.
  • Advise, draft and negotiate the privacy and data security portions of contracts with vendors and other business partners.
  • Draft and advise on contracts regarding data privacy and protection requirements.
  • Work closely with Technology department to design and implement training and awareness on data protection and privacy.
  • Advise on cybersecurity incident response requirements concerning data privacy and protection issues.
  • Support data mapping, data analytics issues, and vendor management reviews.
  • Design metrics and reporting on compliance with all relevant data protection and privacy laws, regulations, policies and procedures and report, where appropriate.
  • Maintain and keep up-to-date expert knowledge of data protection and privacy laws, regulations, pending legislation and practices.
  • Assist with general contracts drafting and negotiations, and additional cross-functional projects within Legal department objectives in preparation for the Games.

Posted June 13, 2026

Netcracker Technology – Corporate Counsel, Information Security & Privacy

Responsibilities:

  • Negotiate and advise on information security, data protection, and compliance provisions in customer contracts, including MSAs, DPAs, Support and Maintenance agreements, and security annexes.
  • Act as a legal liaison between commercial legal, information security, sales, compliance, and other corporate and internal stakeholders.
  • Serve as a customer-facing legal contact for security, privacy, data protection, and related compliance discussions during contract negotiations and the project lifetime.
  • Support contracting for Telco/ISP software and professional services, including AI/SaaS/cloud and managed services offerings.
  • Advise internal teams on regulatory, contractual, and customer-specific requirements related to data protection, cybersecurity, and related compliance.
  • Ensure contractual commitments align with internal security controls, policies, and related compliance frameworks.
  • Track and interpret relevant global laws, regulations, and industry standards impacting telecom customers.
  • Contribute to the development and maintenance of standard contractual language, negotiation playbooks, and internal guidance.

Posted June 13, 2026

TikTok – Regulatory Privacy Counsel

Responsibilities:

  • Support privacy and data protection regulatory matters across LatAm, Canada, and AMA (Africa, Middle East and APAC), including enforcement actions, and regulator engagement
  • Advise on emerging privacy, AI, and digital regulation impacting platform operations, product features, data use, minors’ safety, and online safety obligations
  • Monitor and assess new laws, enforcement trends, and regulatory developments across multiple jurisdictions
  • Help coordinate cross-functional responses to regulators, including risk assessments, written submissions, compliance plans, and internal escalation materials
  • Partner closely with Product Legal, Privacy Legal, Public Policy, and regional legal teams on implementation strategies and regulatory readiness
  • Support development of global positions and frameworks on key topics such as age assurance, AI governance, data minimization, cross-border data transfers, and platform accountability
  • Contribute to broader regulatory strategy workstreams, including horizon scanning, tracker development, trend analysis, and global regulatory coordination

Posted June 12, 2026

Transamerica – Senior Counsel – AI, Privacy & Security Legal (Hybrid)

Responsibilities:

  • Work on complex legal issues where analysis requires identification and evaluation of multiple factors.
  • Manage legal matters provided to a number of in-house constituents within practice area(s).
  • Exercise independent judgment regarding legal advice with limited supervision of more senior attorneys.
  • Negotiate discrete disputes within practice area(s).
  • Review and draft documents and templates within practice area(s).
  • Serve as the primary legal advisor for enterprise AI guidance and governance, counseling on responsible AI, AI risk management, and legal/regulatory compliance across the AI lifecycle (use case intake, development, procurement, deployment, monitoring, and retirement).
  • Advise on AI-related risk issues, including automated decision-making, bias/fairness, transparency/notice, explainability, human oversight, and consumer disclosures, and help establish legally appropriate guardrails.
  • Negotiate and advise on contracts and provisions related to AI, privacy, and cyber security, including AI and cloud services, software licensing, data processing agreements, and AI development contracts.
  • Develop and maintain guidance and governance documentation related to AI, privacy, and cyber security, including policies, standards, procedures, frameworks, playbooks, and approval workflows for AI and privacy use cases.
  • Conduct legal research, monitor, review and analyze proposed legislation, assess applicability and operational impacts, and assist business in understanding the requirements and impact.
  • Coordinate legal matters handled by outside counsel. May provide input into the selection of outside counsel from preselected counsel list.
  • Participate in and may lead departmental and cross-functional working groups in identified areas of legal expertise or development.
  • May manage and/or mentor junior attorneys or paralegals and help scale legal support for AI, privacy and cybersecurity legal reviews and governance.

Posted June 10, 2026

Anduril Industries – Associate General Counsel, Cybersecurity

Responsibilities:

  • Serve as Anduril’s primary legal expert on cybersecurity law, providing strategic advice to executive leadership, the CISO, and business units on complex cybersecurity legal and regulatory issues
  • Advise on cybersecurity requirements in government contracts including FAR/DFARS cybersecurity clauses (DFARS 7012, 7019, 7020), CMMC compliance pathways, NIST 800-171 obligations, contractor classified infrastructure regulations (NISPOM, DAAG) and agency-specific security requirements (DoD, DHS, DoE)
  • Counsel on cybersecurity aspects of OTAs, prototype agreements, production contracts, and other non-traditional contract vehicles
  • Review, negotiate, and draft cybersecurity terms in government contracts, commercial agreements, teaming arrangements, and vendor/supplier contracts
  • Provide thought leadership on emerging cybersecurity regulations affecting defense contractors and autonomous systems operators

Posted June 5, 2026

Walmart – Senior Counsel, Tech and Data Regulatory – Privacy

Responsibilities:

  • Advise on existing and emerging global privacy laws and regulations, sector-specific privacy requirements, and regulatory developments.
  • Partner with the compliance team on the development, implementation, and maintenance of enterprise-level privacy assessments and compliance programs.
  • Lead legal risk identification and mitigation efforts related to privacy practices in business operations, product development, marketing, data analytics, and technology solutions.
  • Partner with cross-functional teams—including compliance, privacy operations, product, technology, and public affairs—to develop scalable and practical legal guidance.
  • Support the company’s response to privacy-related regulatory inquiries and enforcement actions, including managing communications, documentation, and advocacy strategy.
  • Manage and mentor junior attorneys and legal professionals supporting global privacy initiatives, providing oversight, guidance, and professional development.
  • Partner with Government Affairs teams and relevant stakeholders to establish enterprise-wide positions on emerging global privacy laws and consumer regulations advising on impact to the business.
  • Advise on agreement terms related to privacy and consumer disclosures.
  • Develop and maintain internal policies, playbooks, and training to promote privacy and consumer protection awareness across the organization.

Posted June 4, 2026

Chewy – Senior Corporate Counsel, Privacy

Responsibilities:

  • Monitor legislation and advise on new developments in global privacy and data protection laws and regulations, including U.S. state privacy laws (e.g., CCPA/CPRA), PIPEDA, and other frameworks.
  • Provide practical, business-focused guidance on the collection, use, sharing, retention, and protection of personal data across Chewy’s products and operations.
  • Support the development, implementation, and maintenance of privacy policies, notices, and internal governance standards.
  • Partner closely with engineering, data, and technology teams to embed privacy considerations into the design, development, and deployment of products and platforms (“privacy by design”).
  • Review and advise on privacy implications of new products, features, technologies, and data uses, including conducting and supporting privacy impact assessments.
  • Counsel on data-driven initiatives, including analytics, personalization, marketing technologies, and emerging technologies, from a privacy and data governance perspective.
  • Support responses to regulatory inquiries and customer data subject requests.
  • Contribute to ongoing maturation of Chewy’s privacy program through process improvements, training, and cross-functional collaboration.
  • Develop contract structures that address privacy and data protection requirements and lead the review of applicable privacy and data protection language in agreements with affiliates and vendors.
  • Serve as a trusted advisor and partner to colleagues at all levels of the organization

Posted June 4, 2026

Mastercard – Senior Counsel, Privacy, AI & Data Responsibility

Responsibilities:

  • Analyze Identity solutions in light of privacy and data protection law requirements with the aim of identifying the relevant process and infrastructure requirements to ensure compliance with applicable privacy and data protection laws globally
  • Develop contract structures that address privacy and data protection requirements and lead the review and negotiation of applicable privacy and data protection language in agreements with affiliates, vendors, and customers
  • Monitor regulatory and legislative developments pertaining to fraud and financial crime, support the engagement with key policy makers and other stakeholders and provide useful advice to business teams on the potential impact of these laws
  • Provide day-to-day support to Identity business teams, drive alignment globally and respond to all privacy questions that arise.
  • Perform privacy and data protection impact assessments in line with Mastercard’s privacy and data protection policies and processes.
  • Increase awareness among business clients, global privacy and legal teams regarding privacy and data protection pertaining to Mastercard Identity Solutions through training and other initiatives.

Posted May 31, 2026

Fiserv – Privacy Senior Counsel

Responsibilities:

  • Advise business, product, engineering, legal, risk, and compliance stakeholders on AI, data, and privacy laws, including the Colorado AI Act, European Union Artificial Intelligence Act, General Data Protection Regulation, California Consumer Privacy Act, California Privacy Rights Act, Fair Credit Reporting Act, and related regulatory requirements
  • Partner with the AI Center of Excellence to review, document, and support approval of artificial intelligence, generative artificial intelligence, and agentic artificial intelligence use cases, including risk categorization, required safeguards, and approval conditions
  • Assess Fiserv’s compliance posture under applicable AI and privacy laws and help build scalable governance processes, documentation standards, monitoring approaches, and reporting practices that evidence compliance
  • Draft, review, and negotiate data privacy addendum including AI related provisions with clients and vendors, including data usage, licensing, security, privacy, model output, audit, compliance, transfer, and protection terms
  • Participate in client-facing meetings and vendor negotiations on privacy, data, AI, and governance matters
  • Develop and maintain governance policies, notices, procedures, training materials, and tools that support accountability and consistent enterprise practices
  • Monitor developments in AI and privacy laws, regulatory guidance, and enforcement trends and translate impacts into practical recommendations for internal stakeholders
  • Responsibilities listed are not intended to be all-inclusive and may be modified as necessary.

Posted May 31, 2026

Solventum – Senior Managing Counsel, Privacy & Cybersecurity (Americas)

Responsibilities:

  • Provide expert legal counsel to Privacy and Cybersecurity teams to ensure compliance with contractual commitments and regulatory obligations related to data privacy and security.
  • Conduct privacy and data protection impact assessments to ensure sensitive health data is used in compliance with privacy regulations and contractual rights.
  • Advise cybersecurity teams on incident response and investigations, ensuring proper documentation to minimize risks, protect privacy, and fulfill legal obligations during and after security incidents.
  • Collaborate with Procurement and business contracting teams to draft, negotiate, and maintain privacy/data protection terms in contracts and agreements.
  • Lead the company’s legal response to product vulnerabilities, information security breaches, and cyber events, including advising on regulatory notifications at federal, state, and international levels.
  • Counsel IT operations, security teams, and business units on developing and implementing cybersecurity plans, incident response strategies, and compliance with industry standards and regulations.
  • Work closely with Cybersecurity, Procurement, and Legal teams to manage third-party risks, including creating contract templates, negotiation frameworks, and advising on third-party audits and assessments.
  • Advise on the de-identification, pseudonymization, and anonymization of sensitive health data.
  • Provide guidance to business and product teams on data handling requirements based on sensitivity and compliance standards.
  • Implement “privacy by design” principles in product development processes and contribute to product risk assessments.
  • Stay informed on emerging global regulatory requirements impacting data privacy and security and advise the business accordingly.
  • Develop and provide legal content for privacy training programs, awareness campaigns, and compliance with sensitive health information handling requirements.

Posted May 30, 2026

UnitedHealth Group – Staff Counsel, Privacy – Remote

Responsibilities:

  • Serve as a trusted privacy advisor to UnitedHealthcare, with a primary focus on HIPAA and state privacy law compliance
  • Advise marketing and product teams by reviewing initiatives, materials, and workflows for privacy and data protection considerations
  • Own and manage updates to UHC health plan Notices of Privacy Practices, Online Services Privacy Policy, and related notices, including coordination and rollout to impacted business areas
  • Operationalize health plan specific privacy programs, including training, communications, policies, and procedures
  • Provide privacy guidance in support of business associate agreements and other contracting matters, in collaboration with contracting and procurement teams
  • Advise on regulatory change management and support the implementation of new and updated federal and state privacy requirements
  • Advise on and respond to privacy related requests for proposals, customer and regulator audits, and compliance reviews
  • Partner closely with cross functional stakeholders across UnitedHealthcare’s lines of business to balance legal risk and business priorities
  • Operate effectively in a fast paced, high growth environment while exercising sound judgment

Posted May 30, 2026

Shopify – Associate General Counsel, Privacy

Responsibilities:

  • Provide privacy counsel on complex product launches, new features, and strategic partnerships — particularly where Shopify is handling merchant and buyer data in new ways.
  • Partner on managing regulatory relationships and responses for privacy-specific inquiries, including from DPAs and US state enforcement agencies.
  • Drive cross-functional privacy initiatives that move the program forward — not just maintain it. Build the resources, frameworks, and playbooks that let the privacy function scale with the business.
  • Advise on data protection aspects of commercial agreements with merchants, vendors, and partners.
  • Partner with Privacy Engineering and Trust on incident response, data governance, and compliance infrastructure.
  • Maintain subject matter expertise in evolving global privacy law — GDPR, CCPA and other state laws, UK data protection, EU AI Act privacy implications, and emerging frameworks.

Posted May 27, 2026

Nextdoor – Privacy Counsel

Responsibilities:

  • Preparing risk assessments, DPIAs, PIAs, transparency reporting, privacy and security reporting, and other documentation
  • Draft privacy and regulatory compliance reports necessary for various reporting requirements, internal and external
  • Investigate and respond to legislative and regulatory inquiries
  • Advise user-facing teams on processes for responding to user inquiries, prepare templates, and manage escalations
  • Develop and implement compliance plans that address legal risks in practical and business-centric ways and work in close collaboration with our cross-functional partners to implement those plans
  • Advise commercial teams on data governance matters, including DPAs, data transfer agreements, and required privacy terms for vendors, service providers, and subprocessors
  • Maintain and update essential privacy documentation, such as data processing addenda, privacy policies, and intergroup/intragroup data transfer agreements, and data mapping, including annual terms updates
  • Advise on and model use of AI in a responsible and effective manner, including evaluating and advising on risks but also exploring and finding appropriate uses of AI for productivity gains
  • Keep abreast of applicable legislation and legal developments in all relevant jurisdictions, including working independently and in conjunction with our trade associations to keep abreast of changes and opportunities for strategic engagement with pending legislation and regulations
  • Participate in in-person Nextdoor events, trainings, off-sites, volunteer days, and other team building exercises
  • Build relationships with team members across the company and contribute to Nextdoor’s culture
  • And whatever else might come our way! We are a small legal team with fluid and flexible roles that allow for exploration and growth

Posted May 27, 2026

Valvoline Global Operations – Counsel, Privacy, AI, and Data Protection

Responsibilities:

  • Accountable for the design, implementation, and ongoing effectiveness of Valvoline’s global privacy program, including governance structure, policies, and operational processes.
  • Owns enterprise interpretation and application of global privacy laws (e.g., GDPR, CCPA/CPRA), establishing company-wide standards and guidance.
  • Accountable for core privacy program operations, including DPIAs/PIAs, DSAR processes, data mapping, and records of processing activities, ensuring they are scalable, auditable, and consistently executed.
  • Establishes and monitors program KPIs and metrics to measure compliance, maturity, and operational effectiveness; drives remediation where gaps exist.
  • Leads integration of privacy-by-design principles into business processes, systems, and product development, ensuring consistent adoption across functions.
  • Artificial Intelligence Governance & Responsible Innovation
  • Accountable for the enterprise AI governance framework, including policy development, risk classification models, and required controls.
  • Owns the legal review and risk determination framework for AI/ML use cases, including defining approval thresholds and escalation criteria.
  • Ensures AI initiatives meet regulatory, ethical, and internal governance standards, providing final legal guidance on high-risk or ambiguous use cases.

Posted May 27, 2026

Verkada – Senior Privacy Counsel

Responsibilities:

  • Subject Matter Expert. Serve as a subject matter expert on global privacy laws and regulations. Monitor new and emerging developments in privacy and AI/ML laws and regulations, including identifying potential impacts on current and future Verkada products and services
  • Privacy Program Governance. Work with key privacy, security and product stakeholders at Verkada to develop the company’s Privacy program, including its operation, policies, and procedures to ensure ongoing compliance with Verkada’s evolving data privacy obligations
  • Responsible AI Governance. Work with key privacy, security and product stakeholders at Verkada to develop and lead the company’s AI framework and governance program, including its operation, policies, procedures, and SDLC implementation and support
  • Product Counseling Support. Collaborate with Product Counsel to provide privacy legal advice to Product and Engineering teams on new products and features, from ideation through launch
  • Commercial Support. Develop and maintain form agreements in support of the Privacy Program, including intra-group agreements, DPA/BAAs, and security terms. Advise the Commercial Legal team on transactions involving privacy issues, data sharing, biometrics, AI/ML, and related laws and regulations worldwide.
  • Audit Program Governance. Help oversee program auditing for compliance and global harmonization
  • Incident Response Management. Provide advice and counsel to stakeholders at Verkada about privacy incidents and assist with any response to inquiries from global regulators regarding privacy issues
  • Actively promote the importance of data privacy and security at Verkada, both internally and externally

Posted May 27, 2026

AmeriHealth Caritas – Sr Legal Counsel- Data, Privacy & Technology

Responsibilities:

  • Provide professional legal counsel, advice and recommendations on a variety of complex or specialized legal activities.
  • Employ established standards of the legal profession to protect the organization’s reputation and business interests.
  • Help the enterprise ensure compliance with all relevant laws and regulations.
  • Provide legal advice within area of expertise to area leaders to ensure their activities, policies, business practices, and transactions comply with all relevant laws and regulations.
  • Advise senior management on how to respond to legal issues or proposed changes in laws and regulations.
  • Train and mentor staff and/or may lead or manage sizable projects.
  • Possess advanced knowledge in a specialized legal discipline(s) and has a seasoned understanding of the business, healthcare industry environment and the strategic business context.
  • Review and approve legal contracts, letters of agreement, and other documents related to a variety of operational matters to protect the organization’s legal and business interests.
  • Strong understanding and experience in some or all of the following areas: Medicaid managed care; pharmacy benefit management; behavioral health; Exchange programs; Medicare and dual eligible Medicare/Medicaid plans; insurance; health care regulations; E-Privacy, data, HIPAA and security; healthcare/insurance regulations, provider ancillary and vendor contracts.

Posted May 18, 2026

RingCentral – Senior Privacy Counsel

Responsibilities:

  • Act as the dedicated privacy legal point of contact, providing proactive, risk-based counsel to Engineering and Product Management teams throughout the entire development lifecycle of new services and features.
  • Provide specialized legal advice on the privacy implications of any new features, including AI features, in collaboration with the Product Counseling and Regulatory Teams, ensuring compliance with emerging AI regulations and ethical guidelines as it relates to privacy.
  • Lead the execution and documentation of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new features and services, driving legal processes that embed privacy requirements early in the development process, in coordination with other Privacy Team Members.
  • Ensure that RingCentral services comply with evolving global privacy and security regulations.
  • Partner directly with the Information Security team to review product security controls, conduct risk analyses, align legal privacy requirements with technical security implementation for all new products, including as it relates to HIPAA, and ensure that security policies align with and take into account requirements for the protection of personal information.
  • Develop and update customer-facing collateral and resources on RingCentral Trust Centerto support transparency for customers and partners.
  • Support records of processing activities and documentation for products including data locations, data transfers, and subprocessor processing in coordination with other Privacy Team members.
  • Support the incident response program, by ensuring that the documentation is current and in alignment with applicable laws and by representing the privacy team in the incident response activities.
  • Monitor legal developments, collaborate and build relationships with industry peers, to stay abreast of trends and issues globally, as they may impact RingCentral’s privacy posture, templates, and commercial practices.

Posted May 18, 2026

Bloomberg Industry Group – Data Privacy Counsel (INDG)

Responsibilities:

  • Updating Records of Processing Activities (ROPA): Maintain existing ROPA (and adding new entries) to ensure accuracy & currency.
  • Privacy Impact Assessments: Conduct DPIAs, LIAs, and TIAs; maintain the assessment register; track mitigations.
  • Data Subject Rights: Fulfill DSARs end-to-end, including identity verification, data retrieval, response drafting, and evidence management.
  • Data Processing Agreements (DPAs): Draft and negotiate customer and vendor DPAs (as well as contract provisions associated with privacy); escalate complex or high-risk matters.
  • Vendor Due Diligence: Conduct privacy due diligence on vendors and manage routine DPAs.
  • Incident Response: Execute incident/breach runbooks, including evidence collection, reporting, and customer/vendor communication support.
  • Privacy by Design: Participate in Privacy by Design reviews within the SDLC/PLC, documenting advice and risk assessments.
  • Training & Awareness: Assist in development and delivery of privacy trainings.
  • Regulatory Monitoring: Conduct horizon scanning of evolving privacy laws; distill requirements into actionable obligations and communicate them to control owners.

Posted May 15, 2026

Fidelity Group – Privacy & Cybersecurity Counsel

Responsibilities:

  • Privacy matters, including operationalizing privacy programs and maintaining compliance with US and foreign privacy and data protection laws, regulations and frameworks.
  • Cybersecurity matters, including policies and procedures, incident response activities, and applicable laws, regulations and frameworks.
  • Use of new and emerging technology, such as artificial intelligence, machine learning and biometrics;
  • Data management and data governance policies and programs.
  • Strong working knowledge of US and European privacy and data protection laws and regulations, as well as familiarity with other international privacy regimes.
  • Experience with assessing, managing and responding to privacy-related incidents.
  • Experience negotiating complex vendor agreements and other commercial arrangements, including terms pertaining to data usage, privacy and information security.
  • Ability to navigate and advise on complex legal issues and provide clear, practical and business-focused advice.
  • Highly organized, self-motivated and capable of managing multiple priorities in a dynamic collaborative environment.
  • Excellent communication and interpersonal skills, with the ability to influence and build credibility with stakeholders at all levels of the organization.
  • Tech-savvy and curious. You stay current on emerging technology and actively seek to learn more about them and their impact on businesses.

Posted May 14, 2026

The New York Times – Senior Counsel, Data Privacy, Cybersecurity and Consumer Compliance

Responsibilities:

  • Advise clients, including senior leadership, in consumer-facing brand teams, as well as business-wide missions and functions as a subject matter expert on the development, collection, use, transfer, governance, and protection of sensitive data, including personal information, both from a domestic and an international perspective.
  • Counsel clients independently in a manner consistent with the Company’s goals and culture.
  • Orchestrate and supervise the preparation of risk and data protection impact assessments and records of processing by the data privacy analyst and relevant internal clients.
  • Serve as a Legal liaison to engineering with respect to privacy tech and advertising tech management and development, including with respect to data inventory, data subject requests, and consent management.
  • Serve as a member of the core team, alongside cybersecurity and communications representatives, who handle incident response matters and related legal obligations.
  • In coordination with Data, Growth, Technology, and other functions, developing, drafting, and implementing privacy, cybersecurity, subscription, marketing, advertising, and other consumer compliance processes, policies, and procedures; managing privacy policies, terms of use, and self-regulatory notices across digital properties;
  • Develop a wide array of data- and consumer protection-focused legal and compliance policies and procedures in coordination with other members of the Legal department.
  • Review, draft, and negotiate the data provisions of a wide variety of commercial agreements.
  • Advise internal clients on consumer protection laws, regulations, and best practices, including legal developments related to subscription matters such as renewals, cancellations, and price increases.
  • Provide holistic risk advice with a view to the objectives of past and current internal stakeholders, specifically considering emerging legal trends, existing and past business practices and legal advice, company contracts, and public-facing user interfaces and designs, among other factors.
  • Provide legal advice in connection with product development and releases.
  • Serve as a people manager for the data privacy manager.
  • Demonstrate support and understanding of our value of journalistic independence and a strong commitment to our mission to seek the truth and help people understand the world.

Posted May 12, 2026

Integrity – Counsel – Privacy, Risk, and Data Security

Responsibilities:

  • Serve as a senior legal advisor on compliance with U.S. state, federal, and applicable international data privacy laws and regulations.
  • Lead the development, interpretation, and enforcement of privacy policies, notices, data processing agreements, and consent mechanisms.
  • Advise on complex data subject rights matters and oversee risk‑based approaches to rights fulfillment.
  • Provide strategic guidance on privacy issues arising from new products, data initiatives, and technology deployments.
  • Design and oversee enterprise data governance frameworks, including data retention, destruction, defensible deletion, and records management.
  • Partner with IT, compliance, and business leaders to ensure effective data classification, cataloguing, and lifecycle management.
  • Lead or advise on data protection impact assessments and other legal risk assessments for high‑risk processing activities.
  • Provide senior‑level legal guidance on cybersecurity preparedness, incident response, and regulatory notification obligations.
  • Advise executive and technical teams during security incidents, including regulatory engagement and remediation strategy.
  • Lead or support tabletop exercises and post‑incident reviews to continuously strengthen organizational resilience.
  • Help define and evolve the organization’s AI governance framework, including principles, policies, roles, and accountability structures for responsible AI use.

Posted May 11, 2026

Okta – Senior Corporate Counsel – Cybersecurity

Responsibilities:

  • Lead a team of talented, high-performing cybersecurity legal professionals and serve as a point of escalation to provide cybersecurity legal expertise and guidance to executives, cross functional leaders and other stakeholders throughout the organization.
  • Advise, draft and negotiate cybersecurity and privacy terms associated with outbound cloud service Master Subscription Agreements, Information Security Exhibits, Data Processing Addendums and other documentation related to sales transactions, while partnering closely with Okta’s Commercial Legal team.
  • Provide day-to-day legal support surrounding cybersecurity and privacy-related contract requests and respond promptly and effectively to legal requests from internal clients with pragmatic and business-oriented guidance.
  • Provide advice and guidance to Okta Security, Engineering, Product, executives, and other stakeholders on compliance with applicable security and privacy laws and regulations, such as the General Data Protection Regulation, United States’ federal and state regulations, security/privacy by design, frameworks and industry certifications.
  • Support the investigation of potential security and privacy incidents, including analyzing relevant legal and regulatory responsibilities, and providing guidance to internal clients on mitigation, remediation and resolution efforts.
  • Develop, implement and maintain standards, processes, runbooks and guidance surrounding cybersecurity and privacy-related issues for Go-to-Market transactions, and partnering closely with members of the Legal, Security, Compliance and Engineering teams, among other key stakeholders.
  • Build critical relationships in order to effectively provide practical and strategic advice to assist the business in meeting its objectives, while ensuring information security and privacy compliance. Advise on recommended courses of action and legal risk, with the ability to judge when to escalate identified issues as appropriate.
  • Assist in the maintenance and review of various security and privacy programs and processes, including updates to security and privacy policies, plans, procedures, standards, certifications and customer-facing security and privacy documentation.
  • Support the procurement team in drafting and negotiating cybersecurity and privacy terms associated with vendor agreements.
  • Maintain an understanding of technical controls and assist in the creation of audit and monitoring frameworks to support stable, controlled operations.
  • Review cybersecurity and privacy-related marketing and other external communications content for accuracy and completeness.

Posted May 11, 2026

Rippling – Counsel, Data Products & Privacy

Responsibilities:

  • Partner closely with Product and Engineering teams to embed privacy-by-design into new and existing features
  • Advise on global privacy laws and regulatory developments (e.g., GDPR, CPRA, and related frameworks) as they impact product functionality and data use
  • Counsel on AI-enabled and automated decision-making features, including data inputs, outputs, training considerations, and governance controls
  • Draft and negotiate data protection terms, including DPAs, AI-related provisions, and product-specific contractual commitments
  • Conduct privacy risk assessments for new product launches and significant feature updates
  • Support incident response and internal investigations involving product or data risks
  • Build scalable playbooks, review processes, and documentation frameworks to improve efficiency and consistency across the privacy function
  • Monitor regulatory developments and translate evolving requirements into forward-looking product strategy

Posted May 9, 2026

Panda Restaurant Group – Privacy Counsel

Responsibilities:

  • Advises on compliance with applicable data privacy and protection laws (e.g., CCPA/CPRA, GDPR, and other U.S. state laws), ensuring alignment with business practices.
  • Manages and supports data subject rights requests (DSARs), including review of responses, issue‑spotting, and process improvements; conduct and review Privacy Impact Assessments (PIAs/DPIAs) for new technologies, vendors, products, and business initiatives.
  • Reviews, drafts, and negotiates privacy‑related contractual provisions, including Data Processing Agreements (DPAs) and vendor data protection terms; partner with Procurement, IT, Cybersecurity, and Risk Management to assess and mitigate third‑party privacy risk.
  • Supports the development, maintenance, and implementation of privacy policies, notices, disclosures, and internal processes to ensure accuracy and regulatory compliance.
  • Advises on cookie, tracking, and consent management matters in coordination with Marketing and Digital teams.
  • Provides guidance on data governance and data lifecycle issues, including data minimization, retention, and deletion.
  • Assists with privacy incident and data breach response efforts in coordination with Legal, IT, Cybersecurity, and Risk.
  • Monitors evolving privacy laws, regulations, and enforcement trends and assesses potential business impact.
  • Supports privacy considerations related to AI, analytics, and other data‑driven initiatives.
  • Contributes to incident response efforts, including assessing and advising on data breaches or security incidents from a legal and regulatory perspective.

Posted May 6, 2026

Cencora – Assistant General Counsel, MSO, Privacy, Responsible Data & Technology

Responsibilities:

  • Serve as lead counsel for MSO data governance, privacy, AI, and cybersecurity matters, including advising on MSO data flows and operating models; the use and protection of PHI and other sensitive data; and compliance with applicable U.S. federal and state privacy and security requirements (e.g., HIPAA/HITECH and state consumer health privacy laws, as applicable).
  • Counsel MSO business owners on privacy, security, and AI requirements for new and existing MSO offerings, including product counseling for MSO platforms, analytics, care/therapy services support, population health insights, and other data-enabled services.
  • Draft, review, and negotiate MSO-facing privacy and security contractual terms, including BAAs, DPAs, data sharing agreements, service agreements, and vendor/partner security addenda; advise on third-party risk management, subcontractor flow-downs, and MSO client requirements.
  • Partner with MSO information security and technology teams to support MSO security program needs (e.g., NIST-aligned controls, HITRUST/ISO considerations where required), including vulnerability management, application security, identity and access management, encryption, logging/monitoring, and secure SDLC practices.
  • Lead MSO incident preparedness and response legal support, including tabletop exercises; advise on breach assessment and notification obligations; and coordinate with privacy, security, compliance, communications, and client teams on MSO client and regulatory communications.
  • Support MSO governance and reporting, including board/executive updates and diligence support for MSO transactions and strategic partnerships; and respond to MSO client audits, questionnaires, and regulatory inquiries relating to privacy and cybersecurity representations.
  • Establish and maintain strong relationships and clear escalation paths with MSO stakeholders (clinical/medical, operations, product/engineering, security, compliance, commercial, and enterprise legal) to drive consistent, scalable MSO approaches to data governance, privacy, and security risk management and to enable MSO data innovation goals.

Posted May 5, 2026

The Hartford – Assistant General Counsel or Senior Counsel – Privacy and Cybersecurity

Responsibilities:

  • Counseling business partners on new business initiatives to ensure practices with regard to personal information of customers and employees comply with applicable privacy and data security laws and regulations.
  • Leading data incident response relative to incidents including malware/ransomware, mis-mailing/mis-emailing, coding/system issues, and vendor incidents.
  • Negotiating privacy and data security contractual provisions for business transactions, including vendor/ service provider and corporate customer contracts.
  • Advising on Ad-Tech issues, including cookies/ behavioral advertising, in accordance with applicable laws and regulations.
  • Developing and updating internal and external-facing cybersecurity and privacy policies/standards based on developments in applicable laws and industry standards.
  • Monitoring and advocacy regarding legislative proposals and implementation of new laws and regulations.
  • Advising on AI-related laws and regulations applicable to the company.
  • Serving as a subject matter expert with respect to cybersecurity, data breach response, AI and privacy for purposes of enterprise-wide employee training and awareness.
  • Seeking out opportunities to improve legal outcomes and internal/external processes based on legal or other trends and developments.

Posted May 1, 2026

*  *  *

Looking for an older job listing? In an effort to keep this page as up-to-date as possible, we have moved Job Listings older than the date above to our Condensed Job Listings page. We hope this comprehensive list will allow you to see the many different career opportunities that exist in Privacy and Data Security Law.