Privacy Law Job Listings

Background Pink

Privacy Law Job Listings - TeachPrivacy Training 01

 

PRIVACY LAW JOB LISTINGS

This page gathers privacy job listings. Check links for further details, including salary, qualifications, location, and responsibilities. We advise you to apply even if you don’t quite meet requirements for years of experience, as employers often don’t adhere strictly to such requirements. Please write to us if you know of privacy law job listings we should include.

NOTE: As we often don’t know when positions are filled, not all positions listed on this page are still open.  Posted dates are approximations.

*  *  *

Orion – Privacy & AI Governance Counsel

Responsibilities:

  • Serve as the primary enterprise advisor for privacy and AI governance, partnering with business leaders to integrate privacy and responsible AI principles into processes, products, services, and decision-making
  • Develop, maintain, and enhance privacy and AI governance frameworks, policies, standards, and controls aligned with organizational objectives and regulatory requirements
  • Translate legal and regulatory requirements into practical business guidance that enables innovation while mitigating privacy and AI-related risks
  • Monitor, assess, and communicate the impact of evolving privacy, security, and AI regulations on business operations
  • Investigate privacy and AI-related incidents, conduct root cause analyses, oversee remediation activities, and ensure timely resolution of identified risks
  • Lead enterprise privacy compliance activities, including privacy impact assessments, AI risk assessments, records of processing activities, data mapping, and regulatory reporting
  • Manage Data Subject Rights Request (DSRR) processes and support regulatory inquiries, audits, examinations, and investigations
  • Review and negotiate privacy and data protection provisions within contracts, vendor agreements, and third-party risk assessments
  • Collaborate with Legal, Information Security, Compliance, Product, Technology, and business teams to address privacy and AI governance requirements
  • Develop and deliver privacy, AI governance, and data protection training programs to increase organizational awareness and compliance
  • Establish, monitor, and report key privacy and AI governance metrics, risks, and compliance indicators to leadership
  • Support enterprise resilience and crisis management activities involving privacy, cybersecurity, and AI-related incidents
  • Maintain governance inventories for privacy and AI systems, including automated decision-making technologies and high-risk processing activities
  • Provide legal guidance regarding data minimization, purpose limitation, transparency, profiling, automated decision-making, and emerging AI regulations
  • Drive continuous improvement initiatives that enhance privacy operations, governance effectiveness, and regulatory readiness

Posted Sept 12, 2026

Scout Motors, Inc. – Associate General Counsel, Privacy, Cybersecurity & AI Governance

Responsibilities:

  • Lead the design, implementation and management of a comprehensive global data privacy program, including governance structures, policies, and procedures.
  • Advise on compliance with applicable laws and regulations (e.g., GDPR, CCPA/CPRA, U.S. state privacy laws, global data transfer regimes).
  • Advise on and partner with the Commercial and IT teams to build a best-in-class consumer privacy regime for Scout Motors’ direct-to-consumer business.
  • Advise on data protection terms in agreements including license, vendor, SaaS, technology, master services, confidentiality and other agreements.
  • Draft privacy policies, notices, related disclosures, disclaimers, FAQs and communications to support and enable internal business team compliance.
  • Act as the primary legal owner of data privacy obligations arising from connected vehicle operations, including telematics, over-the-air updates, and backend data processing.
  • Assist security and R&D teams in establishing mature privacy-by-design and privacy-by-default frameworks integrated into product development lifecycle.
  • Support incident response for privacy-related matters, including regulatory engagement.

Posted Sept 11, 2026

UnitedHealth Group – Staff Counsel, Privacy

Responsibilities:

  • Serve as a trusted privacy advisor to UnitedHealthcare, with a primary focus on HIPAA and state privacy law compliance
  • Advise marketing and product teams by reviewing initiatives, materials, and workflows for privacy and data protection considerations
  • Own and manage updates to UHC health plan Notices of Privacy Practices, Online Services Privacy Policy, and related notices, including coordination and rollout to impacted business areas
  • Operationalize health plan specific privacy programs, including training, communications, policies, and procedures
  • Provide privacy guidance in support of business associate agreements and other contracting matters, in collaboration with contracting and procurement teams
  • Advise on regulatory change management and support the implementation of new and updated federal and state privacy requirements
  • Advise on and respond to privacy related requests for proposals, customer and regulator audits, and compliance reviews
  • Partner closely with cross functional stakeholders across UnitedHealthcare’s lines of business to balance legal risk and business priorities
  • Operate effectively in a fast paced, high growth environment while exercising sound judgment

Posted Sept 8, 2026

Lennar – Director, Assistant General Counsel – Privacy

Responsibilities:

  • Lead Lennar’s data privacy function, with accountability for maintaining the privacy program, prioritizing the legal pipeline, and ensuring timely, high‑quality, and risk‑balanced delivery of legal services in support of business objectives.
  • Provide sophisticated, practical, and business‑forward privacy and commercial legal advice, including advice on data collection, use, sharing, retention, and cross‑border transfers, translating legal requirements and risk considerations into clear, actionable guidance that enables informed decision‑making and operational execution.
  • Oversee, negotiate, and resolve complex agreements, disputes, and matters, including drafting and negotiating data processing agreements, vendor and technology agreements, data‑sharing arrangements, and a broad range of other commercial agreements, including technology licensing and national supplier agreements, exercising sound judgment in managing legal risk, commercial considerations, and regulatory obligations.
  • Contribute to Lennar’s AI governance efforts and support broader privacy, compliance, and regulatory initiatives, partnering with senior legal leadership and cross‑functional stakeholders to implement required controls, respond to privacy and AI regulatory developments, and address compliance‑related issues.
  • Manage matter‑level financial responsibilities, including oversight of moderate outside counsel and settlement spend, budget tracking, and cost‑conscious decision‑making consistent with approved frameworks and escalation thresholds.
  • Develop and implement the privacy function’s foundational standards, processes, and playbooks, including privacy notices, data processing agreement templates, incident‑response and data‑subject‑request procedures, and negotiation guidance for vendor and technology matters, ensuring consistent application of policies, adherence to enterprise legal frameworks, and effective documentation and records integrity.

Posted Sept 5, 2026

Roblox – Privacy & Security Counsel

Responsibilities:

  • SME on Law: Provide subject-matter expertise and guidance on the evolving global security and privacy legal landscape, including legislation, regulations, enforcement actions, and best practices, translating analysis into clear, concise, and actionable guidance to both legal and security teams.
  • Incident Response Engagement: Engage with the Detection and Response and Global Security teams during incidents. Provide legal guidance throughout the incident, including during verification, triage, containment, remediation, post-mortem, table-top exercises, counseling internal stakeholders throughout the incident lifecycle, reporting to regulators, and notifying customers to meet our global obligations.
  • Security Compliance Support: Own and deliver complex, cross-functional cybersecurity legal initiatives end-to-end, including AI and agentic-AI governance, new regulatory regimes, major incident response improvements, with clear milestones, stakeholder alignment, and measurable outcomes. Continuously improve incident response policies and playbooks that meet the standards of applicable global data privacy and security laws.
  • Security Team Support: Embed within security pods as a trusted partner and go-to legal resource for regular expertise, insights, guidance, and support to different security teams, including Application Security, GRC, Privacy Engineering, Global Security, and Infrastructure/Platform teams, developing a working understanding of Roblox’s architecture, data flows, and operational constraints.
  • Cross-Functional Legal Advice: Provide subject matter expertise in privacy and security and support to cross-functional legal advocacy teams, including corporate, employment, compliance, policy, regulatory, product, privacy, and commercial.

Posted Sept 4, 2026

Cardinal Health – Privacy & Cybersecurity, Sr. Counsel

Responsibilities:

  • Serve as a functional expert working closely with and advising business leaders, commercial counsel, and other colleagues on privacy issues, including data protection, data retention, data usage, data security and data breaches
  • Review and negotiation of data privacy agreements, data processing agreements, business associate agreements and other similar privacy-related provisions
  • Advise on incident response and data breach reporting processes in coordination with the VP of Privacy
  • Collaborate with IT Security teams to ensure alignment between IT security and privacy compliance programs
  • Provide guidance, direction, and practical translation of privacy requirements to cross-functional teams on complex projects
  • Assist with the management of legislative and regulatory inquiries, investigations or administrative actions related to privacy and data security
  • Review policies and procedures to ensure compliance with applicable data privacy laws and regulations
  • Advise on the design and provision of the privacy training program
  • Remain up to date on legislative developments in Privacy at the state, federal and international level that may affect Cardinal Health

Posted Sept 4, 2026

lululemon – Privacy Counsel

Responsibilities:

  • Partner with company stakeholders to gather information and approvals necessary for privacy compliance matters.
  • Work with all members of the legal team across global office locations, including attorney and non-attorney personnel.
  • Serve as the primary point of contact supporting our APAC and China Legal partners.
  • Monitor for regulatory change, perform analysis of changes, and oversee business implementation of changes in a timely manner.
  • Conduct research and contribute to emerging privacy compliance projects related to new product launches.
  • Collaborate with the global legal team to develop and implement best practices and policies.
  • Provide direction to teams during incidents and engagement of outside counsel.
  • The Privacy Counsel works closely with the rest of the Privacy team on compliance execution, matter and regulatory tracking, program maturity and reporting to leadership.

Posted Sept 2, 2026

Empower – Counsel – Data Protection, Privacy & Cyber Security

Responsibilities:

  • Research, interpret, and provide legal guidance regarding federal, state, and evolving global privacy, data protection, cybersecurity, consumer protection, and related laws and regulations, including GLBA, state comprehensive privacy laws, FCRA, TCPA, CAN-SPAM, and other applicable requirements.
  • Advise business partners on privacy and data protection requirements affecting Empower’s products, services, operations, and customer interactions.
  • Support the development, implementation, and maintenance of privacy policies, notices, procedures, and other compliance frameworks.
  • Provide legal support regarding the collection, use, sharing, retention, and protection of personal information.
  • Assist with legal issues involving cybersecurity, data incidents, information security, online privacy, and evolving technology and data practices.
  • Review and draft privacy and data protection provisions in client, vendor, and other commercial agreements, and support contract negotiations and RFPs.
  • Assist with records retention and information governance matters, including interpreting legal and regulatory retention requirements.
  • Support regulatory examinations, inquiries, and other matters involving privacy, cybersecurity, data protection, and related issues.
  • Monitor emerging privacy, cybersecurity, technology, and consumer protection developments and help translate new legal requirements into practical guidance for the business.
  • Research and provide legal guidance on evolving laws, regulations, regulatory guidance, and industry standards governing artificial intelligence and other emerging technologies, including requirements relating to privacy, data use, transparency, automated decision-making, governance, and consumer protection.
  • Partner with Legal, Privacy, Compliance, Risk, Technology, Cybersecurity, Product, and other stakeholders on the responsible development, procurement, and use of AI-enabled tools and applications, including helping assess legal and regulatory considerations associated with new AI use cases.

Posted Sept 1, 2026

DoorDash – Corporate Counsel, Cybersecurity & Enforcement

Responsibilities:

  • Serve as a strategic legal advisor on cybersecurity risks, programs, technologies, incidents, and evolving legal and regulatory requirements.
  • Lead the legal response to cybersecurity incidents and investigations, including advising on response strategy, legal obligations, and communications.
  • Develop legal strategies to investigate, disrupt, and pursue bad actors who target DoorDash, its customers, merchants, and partners.

Posted Aug 30, 2026

CVS Pharmacy – Managing Senior Counsel – Privacy – Pharmacy Consumer Wellness

Responsibilities:

As a Managing Legal Counsel, you will lead the privacy legal and compliance team supporting our CVS Pharmacy business. Your team will be responsible for providing timely and strategic legal counsel to internal business partners with respect to Federal and state healthcare and consumer privacy regulations and laws. You will proactively advise business partners on a wide variety of matters and work collaboratively with other attorneys and partners on matters related to privacy compliance.

Responsibilities may include advising on privacy issues related to handling customer information associated with our retail operations, online advertising activities, electronic devices, product development, contracting, and/or other retail operations activities. You will also provide advice on appropriate use of patient information related to our provision of healthcare treatment and services in our pharmacies.

Posted Aug 30, 2026

FUJIFILM – Sr Counsel – Data Privacy & Protection

Responsibilities:

  • Act as a key subject matter expert and advisor to Fujifilm attorneys and business teams on all matters relating to data privacy and protection law, including providing practical, timely, strategic, and high-quality legal advice on data privacy and security matters.
  • Advise members of the legal and business teams on best practices and compliance with U.S. and global data protection laws, including legal and regulatory aspects of data collection and use, privacy disclosures and transparency, consent forms, and related issues.
  • Collaborate with privacy and security colleagues to support and enhance the company’s privacy program to enable consistent, effective data privacy practices and minimize privacy risk.
  • Support privacy impact assessments (PIAs/DPIAs), vendor risk reviews, and internal assessments using current data mapping and inventory information, collaborating with Data Governance Manager, as necessary.
  • Support the development and management of privacy training and awareness initiatives to educate employees on privacy obligations, appropriate data handling, and regulatory requirements.
  • Provide legal support for the strategic reviewing, drafting, and negotiating of AI, privacy and data security terms in contracts with business partners and vendors, including data processing agreements and data protection terms in agreements.
  • Provide legal support for the drafting, reviewing and negotiating of AI, privacy and security related agreements, including Business Associate Agreements, Data Processing Agreements, Data Protection Agreements and Security Agreements.

Posted Aug 26, 2026

Lenovo – Senior Counsel, Legal, Privacy & AI Products

Responsibilities:

  • Serve as a privacy legal advisor for product, engineering, and business teams developing AI-enabled products and services.
  • Provide practical, risk-based guidance throughout the product lifecycle and partner with product, engineering, security, AI governance, and business stakeholders to identify legal and regulatory risks, develop appropriate mitigation measures, and support launch readiness and ongoing governance of AI-enabled products and services.
  • Conduct and support privacy impact assessments, AI risk assessments, and other legal reviews, identifying requirements, mitigation measures, residual risks, and matters requiring escalation.
  • Review and advise on product requirements, architectures, data flows, privacy notices, consent mechanisms, launch plans, and supporting documentation.
  • Draft, review, and negotiate agreements involving AI technologies, data licensing, cloud services, software development, suppliers, and strategic technology partners.
  • Develop and maintain scalable governance frameworks, policies, standards, assessment templates, and review processes supporting privacy and AI compliance programs.
  • Support investigations and response activities involving privacy, data governance, AI, or cybersecurity-related issues.
  • Monitor global legal, regulatory, enforcement, and policy developments affecting AI and emerging technologies and advise stakeholders on business and product impacts.
  • Improve review processes, reduce bottlenecks, and create scalable guidance for recurring issues while maintaining strong documentation and defensible decision-making.

Posted Aug 26, 2026

Uber – Counsel – Privacy & Cybersecurity Legal

Responsibilities:

  • Advise Uber product and engineering teams regarding data privacy and cybersecurity requirements, best practices, and Uber’s Privacy Principles
  • Drive privacy-by-design and -default throughout Uber’s product development process
  • Track and research developments relating to new and pending laws that impact Uber’s privacy and cybersecurity program, including U.S. state laws and the EU’s GDPR, AI Act, and Platform Work Directive; translate that into practical, effective advice; and lead compliance efforts relating to these laws
  • Negotiate privacy requirements in third-party agreements
  • Create and present engaging company-wide trainings regarding data privacy and security requirements and standard methodologies

Posted Aug 26, 2026

Shiseido – Corporate Counsel, Privacy & Digital

Responsibilities:

  • Advise on U.S. privacy/data protection laws, regulations, and standards (e.g. CCPA/CPRA; PCI DSS), as well as global data privacy laws and regulations, particularly those most germane to the Company’s regional footprint (e.g., Canada and Brazil) and have a working understanding of the laws and regulations in other key jurisdictions (e.g., GDPR).
  • Lead development, implementation and maintenance of privacy compliance programs.
  • Collaborate cross-functionally with IT, Americas Digital Transformation, e-commerce, Brand Marketing, Legal, and global counterparts on data collection, use, and governance matters.
  • Review and draft privacy related policies and procedures.
  • Integration and negotiation of data protection clauses or data processing agreements in contracts with service providers, vendors, and other partners.
  • Stay abreast of ever-changing laws and regulations in privacy and digital space and take proactive steps to ensure business remains compliant.
  • Provide formal and informal training to cross-functional teams and partners on privacy compliance including emerging laws and regulations.
  • Provide support to G.C. in defense of adversarial claims and litigation of privacy related matters (e.g., CIPA; web ADA, TCPA).
  • Lend support on cyber security initiatives, external threats, and incident response.
  • Review, draft, negotiate and advise on digital and technology agreements, including SaaS, eCommerce services, CRM, data processing, analytics, AI, corporate media, and digital innovations and applications.

Posted Aug 23, 2026

State Farm – In-House Privacy & Info Security Counsel

Responsibilities:

  • Provide legal guidance on federal and state privacy and information security laws, enterprise risk management, and compliance and ethics programs
  • Counsel on related areas such as information retention, crisis management, AML/OFAC, business continuity, telematics, and technology-related matters
  • Collaborate cross-functionally to navigate the fast-changing landscape of law, technology, and business priorities.

Posted Aug 20, 2026

Shopify – Associate General Counsel, Privacy (Americas)

Responsibilities:

  • Provide privacy counsel on complex product launches, new features, and strategic partnerships — particularly where Shopify is handling merchant and buyer data in new ways.
  • Partner on managing regulatory relationships and responses for privacy-specific inquiries, including from DPAs and US state enforcement agencies.
  • Drive cross-functional privacy initiatives that move the program forward — not just maintain it. Build the resources, frameworks, and playbooks that let the privacy function scale with the business.
  • Advise on data protection aspects of commercial agreements with merchants, vendors, and partners.
  • Partner with Privacy Engineering and Trust on incident response, data governance, and compliance infrastructure.
  • Maintain subject matter expertise in evolving global privacy law — GDPR, CCPA and other state laws, UK data protection, EU AI Act privacy implications, and emerging frameworks.

Posted Aug 19, 2026

TD – Counsel – U.S. Privacy and Cybersecurity

Responsibilities:

The Counsel provides legal advice and support to management and employees in Corporate Group functions and Business units. Functions as a legal resource focusing on one or more defined subject matters and/or specific businesses. Typical tasks include managing litigation, negotiating contracts, assisting the Business with product roll-outs, and advising the Business regarding regulatory developments. Responsible for anticipating and addressing potential legal risks. Relies on legal skills, experience and judgment to accomplish goals.

Posted Aug 19, 2026

FUJIFILM Americas – Sr Counsel Data Privacy & Protection

Responsibilities:

  • Act as a key subject matter expert and advisor to Fujifilm attorneys and business teams on all matters relating to data privacy and protection law, including providing practical, timely, strategic, and high-quality legal advice on data privacy and security matters.
  • Advise members of the legal and business teams on best practices and compliance with U.S. and global data protection laws, including legal and regulatory aspects of data collection and use, privacy disclosures and transparency, consent forms, and related issues.
  • Collaborate with privacy and security colleagues to support and enhance the company’s privacy program to enable consistent, effective data privacy practices and minimize privacy risk.
  • Support privacy impact assessments (PIAs/DPIAs), vendor risk reviews, and internal assessments using current data mapping and inventory information, collaborating with Data Governance Manager, as necessary.
  • Support the development and management of privacy training and awareness initiatives to educate employees on privacy obligations, appropriate data handling, and regulatory requirements.
  • Provide legal support for the strategic reviewing, drafting, and negotiating of AI, privacy and data security terms in contracts with business partners and vendors, including data processing agreements and data protection terms in agreements.
  • Provide legal support for the drafting, reviewing and negotiating of AI, privacy and security related agreements, including Business Associate Agreements, Data Processing Agreements, Data Protection Agreements and Security Agreements.
  • Provide advice and legal direction on data protection laws impacting business operations and contractual relationships.
  • Strategically advise on emerging products and technologies while anticipating and successfully navigating privacy considerations.
  • Provide legal counsel on investigations involving reports of inappropriate or unauthorized access, loss or disclosure of personal data, including advising on potential liability, identifying legal obligations, and supporting incident response efforts.

Posted Aug 18, 2026

Uber – Counsel – Privacy & Cybersecurity Legal

Responsibilities:

  • Advise Uber product and engineering teams regarding data privacy and cybersecurity requirements, best practices, and Uber’s Privacy Principles
  • Drive privacy-by-design and -default throughout Uber’s product development process
  • Track and research developments relating to new and pending laws that impact Uber’s privacy and cybersecurity program, including U.S. state laws and the EU’s GDPR, AI Act, and Platform Work Directive; translate that into practical, effective advice; and lead compliance efforts relating to these laws
  • Negotiate privacy requirements in third-party agreements
  • Create and present engaging company-wide trainings regarding data privacy and security requirements and standard methodologies
  • Drive awareness regarding cutting-edge legal and business developments, including regarding use of AI and machine learning, and lead team efficiency, morale and collaboration efforts
  • Contribute to our ongoing mission to make magic in the marketplace, and drive Uber’s efforts to be a trusted steward of our users’ personal data in every market where Uber operates

Posted Aug 18, 2026

Aegon – Senior Counsel – Privacy, Cybersecurity and AI

Responsibilities:

  • Independently handle complex privacy, cybersecurity and AI legal matters with minimal supervision, serving as a trusted and collaborative member of the privacy team
  • Advise business stakeholders on privacy, cybersecurity and AI governance regulatory requirements, translating legal obligations into practical, actionable implementation strategies while effectively identifying, quantifying, and communicating risk to decision-makers
  • Partner on global AI governance initiatives, including reviewing AI use cases for legal and regulatory compliance and supporting the organization in successfully implementing AI governance frameworks
  • Support core privacy operations across the global enterprise, including privacy impact assessments (PIAs), data protection impact assessments (DPIAs), data subject access requests (DSARs), records of processing activities (RoPAs), and third-party privacy risk management
  • Draft, review, and negotiate privacy-related legal agreements, including data processing agreements and data transfer agreements
  • Design and implement scalable privacy and AI compliance frameworks and repeatable processes that support business growth while managing legal and regulatory risk across the globe
  • Identify training needs and develop and deliver privacy and AI regulatory training across the organization
  • Drive cross-functional projects to completion, coordinate outside counsel, and respond to regulatory inquiries

Posted Aug 13, 2026

LPL Financial – VP, Assistant General Counsel, Cybersecurity

Responsibilities:

  • Advise on legal and regulatory obligations applicable to cybersecurity incidents, including materiality assessments, regulatory notifications, disclosure requirements, and client/advisor communications.
  • Serve as the primary legal advisor for incident response, working closely with Information Security, Technology, Communications, Compliance, and executive leadership during cyber and data events.
  • Monitor and interpret evolving cybersecurity regulations (e.g., NYDFS Cybersecurity Rules, state breach laws, privacy laws, SEC/FINRA expectations) and assess their impact on business operations.
  • Support crisis management activities and provide legal guidance on escalation, response coordination, and regulatory engagement during high-priority events.
  • Draft, review, and update cybersecurity and incident response policies, standards, procedures, and playbooks, including enhancements to the firm’s incident response program and governance model.
  • Provide legal input into cyber tabletop exercises, readiness assessments, and cross-functional simulations to strengthen operational resilience.
  • Advise on cybersecurity requirements applicable to third-party service providers, vendor oversight, and technology integrations, including contractual terms, diligence, and supervisory expectations.
  • Partner with Information Security to evaluate cybersecurity controls and governance frameworks, including processes related to logging, monitoring, identity and access management, endpoint protection, and vulnerability management.
  • Support regulatory examinations, supervisory inquiries, remediation activities, and documentation efforts related to cybersecurity matters.
  • Collaborate cross-functionally with Technology, Risk, Compliance, Data Governance, and business teams to support cybersecurity regulatory compliance and operational alignment.
  • Educate internal stakeholders on cybersecurity legal risks, regulatory expectations, and best practices to promote a culture of cybersecurity awareness and accountability.

Posted Aug 12, 2026

Creative Artists Agency – Data Privacy Counsel, Office of the Chief Legal Officer

Responsibilities:

  • Develop, implement, and maintain a comprehensive companywide data privacy strategy and program, including policies, procedures, notices, and guidelines that ensure compliance with applicable federal, state, and international privacy laws and regulations
  • Act as a key leader for the selection and roll-out of CAA’s approved AI platforms, advising on safe and responsible implementation steps, model vulnerabilities, data protection considerations, employee trainings, evolving industry norms/best practices and any other issues that may arise throughout the integration process
  • Serve as the primary legal advisor on data privacy and data protection matters across the organization, providing counsel to business, technology, finance, tax, marketing, human resources, and other functional teams
  • Review, draft, and negotiate privacy and data protection provisions in vendor, partner, and client agreements, including data processing agreements (DPAs) and standard contractual clauses (SCCs)
  • Oversee and conduct privacy impact assessments and risk assessments relating to new and existing programs, products, and initiatives that involve the collection, use, or sharing of personal information
  • Monitor and interpret developments in global privacy laws and regulations, including GDPR, CCPA/CPRA, and other applicable laws, and advise on their impact to CAA’s business operations
  • Lead and manage the privacy incident response process, including breach assessment, regulatory notification, and remediation across relevant jurisdictions
  • Collaborate cross-functionally with IT, Information Security, Marketing, Human Resources, and other departments to embed privacy-by-design principles into business processes, systems, and new initiatives
  • Manage and respond to data subject rights requests in accordance with applicable law, and maintain internal processes for timely and accurate handling
  • Develop and deliver privacy training and awareness programs for employees across the organization, including communicating legal and regulatory developments in an accessible manner

Posted Aug 12, 2026

The Johns Hopkins University – Associate General Counsel & Privacy Officer

Responsibilities:

  • Advise the university on legal issues related to applicable privacy obligations, including FERPA, HIPAA, GDPR, MODPA, CCPA, GLBA, consumer protection laws, and other applicable state, federal, and international privacy regulations.
  • Oversee the daily operations of the University’s privacy program.
  • Serve as the primary point of contact for non-clinical data privacy compliance for the university.
  • Assist in the development, implementation, and maintenance of privacy policies, procedures, and standards.
  • Serve as a resource for university departments on privacy compliance questions and program implementation.
  • Help ensure privacy requirements are embedded into university operations and decision-making.
  • Monitor and assess program compliance with applicable laws, regulations, and internal policies.
  • Coordinate with university IT, the University Registrar, and other offices, and serve as the point of contact for the supervisory authority, as needed.
  • Manage the data subject access request process.
  • Develop contractual addendums, terms and conditions, and standard clauses to support compliance with evolving domestic and global privacy regulations.

Posted Aug 12, 2026

TIAA – Associate General Counsel – Privacy

Responsibilities:

  • Be a Trusted Privacy & Cybersecurity Advisor — Serve as the go-to legal partner for business, product, and technology teams, providing practical, risk-calibrated guidance on domestic and international privacy and cybersecurity frameworks across a diverse and dynamic portfolio of initiatives.
  • Shape Products & Digital Experiences — Embed privacy-by-design thinking into the development and launch of new products, services, and digital experiences, from concept through deployment, ensuring legal requirements are met without slowing down innovation.
  • Navigate AI and Emerging Technology — Advise on the privacy and data protection dimensions of artificial intelligence, quantum computing, and other next-generation technology deployments, applying foundational privacy principles and evolving regulatory guidance to some of the most interesting and complex technology questions in the field today.
  • Build Something That Lasts — Partner with Risk and Compliance to develop governance frameworks, shape enterprise policy, and strengthen the organization’s privacy and cybersecurity culture from the inside out
  • Lead When It Matters Most — Play an active role in cybersecurity governance and privacy incident response, including investigation, containment, and notification.
  • Drive Commercial Outcomes — Negotiate privacy and cybersecurity protections in vendor and strategic partnership agreements, directly reducing organizational risk while enabling the business to move forward with confidence.

Posted Aug 5, 2026

AON – Assistant General Counsel- Head of North America Privacy

Responsibilities:

  • Provide privacy and cyber legal advice to business, Law & Compliance, risk, cybersecurity, and other internal stakeholders
  • Manage a high-performing team with a focus on excellent business and client service, risk-based advice, and coaching/growth
  • Negotiate high-risk/large enterprise client privacy and data protection agreements
  • Oversee and provide legal advice on privacy and security incidents
  • Set strategic direction and priorities for North America privacy advisory function
  • Stay up-to-date on emerging privacy and cyber trends, laws, regulations, enforcement actions, and settlements in your region and provide information and updates to key partners
  • Advise and assist privacy assurance team colleagues on implementation of programs for new laws and regulations
  • Advise on the privacy and cyber law aspects of acquisitions and other M&A activities
  • Collaborate with colleagues across the company on privacy and cyber related projects
  • Manage the North America privacy advisory function, ensuring adherence to benchmarks, conducting reporting/metrics, and identifying and implementing improvements

Posted Aug 5, 2026

Fiserv – Privacy Managing Counsel

Responsibilities:

  • Advise business, product, engineering, compliance, risk, and legal stakeholders on privacy and data protection requirements applicable to embedded finance offerings, including the Gramm-Leach-Bliley Act, state privacy laws, California Consumer Privacy Act, California Privacy Rights Act, General Data Protection Regulation, Fair Credit Reporting Act, Health Insurance Portability and Accountability Act, and related frameworks
  • Partner with cross-functional teams to identify privacy implications, conduct risk assessments, and implement practical, scalable privacy-by-design controls across the product lifecycle
  • Advise on banking-as-a-service program structures and privacy-related compliance considerations across sponsor banks, program managers, processors, consumer-facing partners, and other third parties
  • Draft, review, and negotiate privacy and data protection terms in commercial and technology agreements, including data use, licensing, vendor, service provider, customer, and data transfer agreements
  • Lead partner and vendor negotiations on privacy matters and participate in client-facing discussions related to data use, compliance obligations, and contractual risk
  • Develop, maintain, and socialize privacy policies, notices, procedures, training materials, and tools that support accountability and consistent operational practices
  • Monitor changes in privacy laws and regulations and translate legal requirements into clear, actionable guidance for internal stakeholders

Posted Aug 2, 2026

Okta – Director, Corporate Counsel – Privacy

Responsibilities:

  • Lead and develop a team of talented, high-performing privacy legal professionals and serve as a point of escalation, providing privacy and data protection legal expertise to executives, cross functional leaders and other stakeholders throughout the organization.
  • Provide advice and guidance to Okta Security, Engineering, Product, executives and other stakeholders on compliance with applicable privacy and data protection laws and regulations, such as the General Data Protection Regulation, United States’ federal and state regulations, privacy by design, frameworks and industry certifications.
  • Provide advice negotiating privacy and data protection terms associated with Master Subscription Agreements, Data Processing Addendums and other documentation related to customer and vendor transactions.
  • Provide day-to-day legal support on privacy and data protection-related questions and respond promptly and effectively with pragmatic, business-oriented guidance.
  • Support the investigation of potential privacy incidents, including analyzing relevant regulatory responsibilities and contractual obligations.
  • Develop, implement and maintain privacy and data protection policies, procedures, standards, processes, runbooks, certifications and guidance.
  • Build critical relationships in order to effectively provide practical and strategic advice to assist the business in meeting its objectives, while ensuring privacy and data protection compliance.
  • Maintain an understanding of technical controls and assist in the creation of audit and monitoring frameworks to support stable, controlled operations.
  • Review privacy-related marketing and other external communications content for accuracy and completeness.
  • Strategically manage outside counsel relationships, including staffing, strategy, work product, day-to-day activity and budgets.

Posted July 31, 2026

D.R. Horton – Senior Privacy Counsel

Responsibilities:

  • Provide legal advice in connection with: (1) the company’s privacy, cybersecurity, data use, artificial intelligence (AI), information technology and data governance practices and procedures; (2) e-commerce, customer relationship management (CRM) and digital marketing practices, financial services and practices, and other programs for privacy and other compliance issues; draft documentation as necessary; (3) marketing and communication practices to comply with TCPA and CAN-SPAM requirements, including consent management, opt-out mechanisms, and record-keeping obligations; and (4) tracking and analysis of existing and new federal and state privacy, artificial intelligence (AI), cybersecurity, data use, breach notification and similar statutes and regulations to revise and implement the company’s privacy practices and procedures on an ongoing basis
  • Provide counsel in connection with the company’s data subject rights, privacy impact assessments, information incidents and data breach responses
  • Oversee privacy team for privacy inquiries, including monitoring intake channels
  • Develop, implement and maintain the company’s privacy and data governance program, including privacy policies, procedures, notices, consents, training and compliance reporting.

Posted July 28, 2026

RTX – Director & Assistant General Counsel, Privacy

Responsibilities:

  • Advise and counsel RTX and its businesses on all aspects of privacy law
  • Monitor and help shape privacy laws, regulations, government policies, and similar, as well as develop and strengthen external relationships with industry and government partners, groups, and regulators
  • Assist with the development, implementation, and maintenance of policies, standard work, playbooks, guidance, templates, and other documentation
  • Develop and deliver training on privacy law, including training for Privacy Professionals and Data Protection Officers, as well as general awareness training for employees, contractors, and others
  • Provide legal advice and counsel on all aspects of data breach response and management, and be responsible for ensuring timely satisfaction of legal reporting obligations
  • Review privacy impact and other privacy assessments and support data inventory activities
  • Participate in and support the annual privacy self-assessment program, the internal audit testing of privacy controls, and other program effectiveness monitoring efforts
  • Provide legal advice and counsel on privacy insurance matters, including on RTX’s privacy insurance policies and program
  • Provide legal advice and counsel on the privacy aspects of mergers, acquisitions, and divestitures (MA&D), including on MA&D agreements, representations and warranties, and diligence
  • Manage outside counsel and vendors engaged on privacy legal matters

Posted July 25, 2026

Alliant Energy – Counsel II – Cyber & Privacy

Responsibilities:

  • Develops strategy, advocates, and manages standard commercial litigation, transactions or regulatory dockets before state or federal regulatory agencies involving multiple parties to achieve successful outcomes.
  • Provides legal counsel on a wide range of standard legal matters, including transactional, human resources, litigation, intellectual property, real estate, public company or regulatory matters.
  • Responsible for specialized role in standard projects involving internal teams, business units and external resources.
  • Assignments are carried out with moderate guidance and direction. Supports executive and top-level management and legal counsel from other organizations and serves as a primary point of contact for internal clients related to legal issues.
  • Collaborates with business units and with various staff departments, facilitates compliance with federal and state regulations. Remains abreast of proposed legislation and regulatory changes across a number of disciplines which might affect the organization.
  • Drafts contracts, pleadings, memorandum and other legal documents for filing before regulatory agencies or state for federal courts, or for use by internal business teams. Ensures filings are supported by compelling evidence and present persuasive arguments to achieve objectives.
  • Monitors legal and business developments that may affect a project and determines the appropriate course of action. Responsible for assessing project risk. Evaluates the scope and resources used for the project and determines the level of expertise (internal and/or external) needed to complete a project. Manages stakeholder relationships and communications.

Posted July 25, 2026

Capital One – Sr. Manager, Sr. Counsel- Privacy and Data Protection

Responsibilities:

  • Identifying privacy issues in a complex, highly regulated environment
  • Communicating privacy legal requirements and risks effectively to legal, business, compliance, and risk partners
  • Developing customer-focused solutions to mitigate privacy risks and achieve business goals
  • Supporting partners in building technical and organizational privacy controls, drafting privacy notices and disclosures, developing policies and procedures, preparing internal documentation, and enhancing privacy operations and strategy
  • Advising on contract privacy language and providing transactional privacy advice in the context of mergers, acquisitions, and strategic partnerships
  • Collaborating with outside counsel, developing written legal guidance and presentations, monitoring legal developments and industry trends, and contributing to the legal privacy team’s existing knowledge and resources
  • Tracking and advising on privacy legislation and new privacy laws

Posted July 24, 2026

OneOncology – Sr. Counsel (Privacy & Data)

Responsibilities:

  • Develop, implement, and maintain comprehensive privacy policies and procedures and oversee organization’s, and its subsidiaries’ and legal affiliates’, compliance with HIPAA, HITECH, and other applicable privacy laws and regulations.
  • Oversee the response to platform privacy and security incidents and breaches, including investigation, mitigation, and notification for OneOncology-owned, affiliated and managed practices.
  • Serve as OneOncology’s Privacy Officer and the primary point of contact for privacy-related inquiries and complaints from patients, employees, practices, and regulatory bodies.
  • Collaborate with OneOncology’s Compliance, Information Security, Product/Engineering and other teams to ensure compliant, aligned and integrated privacy practices, procedures and product design across platform.
  • Monitor legal and regulatory developments and industry best practices to proactively update the privacy and security program.
  • Maintain documentation of the organization’s privacy and security practices and decisions.
  • Coordinate and support privacy audits, regulatory inquiries, and investigations and partner with OneOncology’s Security Officer on related security matters.
  • Identify, document, and mitigate privacy risks across business units.

Posted July 24, 2026

Nintendo – Counsel, Privacy

Responsibilities:

  • Provides legal advice and guidance to business teams on privacy, data protection, and online safety requirements affecting company products and services.
  • Responds to legal inquiries related to privacy, online safety, and data protection, including regulatory compliance, product design, data use, and consumer rights.
  • Supports implementation of applicable privacy and online safety laws and regulations across the U.S., Canada, and Latin America.
  • Monitors and maintains knowledge of relevant legal and regulatory developments and prepares summaries and guidance for internal stakeholders.
  • Conducts legal review and clearance of product features and services, including evaluation of privacy, online safety and data protection risks.
  • Supports the administration and operation of the company’s Information Management Program, including data protection impact assessments, documentation, and compliance processes.
  • Conducts privacy reviews of vendor and third-party engagements and supports related risk management processes in coordination with internal stakeholders.
  • Reviews and provides guidance on privacy-related provisions in vendor and partner agreements.
  • Supports artificial intelligence (AI) governance processes, including review of proposed use cases.
  • Assists with privacy-related aspects of incident response, including coordination of information, documentation, and follow-up actions.

Posted July 23, 2026

T-Mobile – Corporate Counsel – Data Governance & Privacy

Responsibilities:

  • Provide legal support for T-Mobile’s enterprise data governance and data stewardship programs, advising cross-functional stakeholders on the development and implementation of data governance processes and controls.
  • Provide strategic legal counsel on data lifecycle management, including records retention, defensible deletion, data minimization, enterprise data inventory, data access governance, and third-party data management.
  • Advise on compliance with domestic and international privacy laws and regulations and other legal requirements governing data governance, retention, and access, and assessing legal risks associated with evolving regulatory expectations.
  • Develop legal guidance, policies, standards, training, and playbooks to promote consistent enterprise practices related to data governance, records management, and data stewardship.
  • Partner with legal and business teams to support enterprise governance initiatives and further strengthen organizational readiness for litigation, investigations, audits, and regulatory inquiries.

Posted July 22, 2026

Samsung Electronics America – Senior Legal Counsel – Privacy

Responsibilities:

  • Counsel and support Samsung businesses on all privacy matters, ensuring compliance with CCPA, COPPA and other relevant state and federal privacy laws and regulations
  • Track and advise on legal, regulatory, and policy developments relating to data collection and use, online privacy, healthcare, tracking and analytics, advanced advertising, and related issues
  • Develop and implement comprehensive privacy policies and procedures
  • Conduct data privacy impact assessments and other analyses of personal data usage
  • Collaborate with various departments to integrate privacy considerations into business processes and projects
  • Stay abreast of regulatory developments and enforcement actions related to privacy and data protection
  • Manage data breach response and notification processes
  • Provide training and raise awareness on privacy and data protection issues among employees
  • Represent the company in privacy-related matters and liaise with regulatory authorities
  • Drafting and negotiating vendor and customer contracts and counseling the business with respect to privacy and information security issues
  • Partner with Samsung’s Korea Headquarter (HQ) Privacy team to support the rollout of local privacy initiatives and assist with projects as needed

Posted July 21, 2026

Uber – Counsel – Privacy & Cybersecurity Legal

Responsibilities:

  • Advise Uber product and engineering teams regarding data privacy and cybersecurity requirements, best practices, and Uber’s Privacy Principles
  • Drive privacy-by-design and -default throughout Uber’s product development process
  • Track and research developments relating to new and pending laws that impact Uber’s privacy and cybersecurity program, including U.S. state laws and the EU’s GDPR, AI Act, and Platform Work Directive; translate that into practical, effective advice; and lead compliance efforts relating to these laws
  • Negotiate privacy requirements in third-party agreements
  • Create and present engaging company-wide trainings regarding data privacy and security requirements and standard methodologies
  • Drive awareness regarding cutting-edge legal and business developments, including regarding use of AI and machine learning, and lead team efficiency, morale and collaboration efforts
  • Contribute to our ongoing mission to make magic in the marketplace, and drive Uber’s efforts to be a trusted steward of our users’ personal data in every market where Uber operates

Posted July 21, 2026

Snap, Inc. – Privacy & Cybersecurity Counsel

Responsibilities:

  • Partner closely with Snap’s Engineering Security team to provide legal and strategic advice on a range of matters, including vendor due diligence, third party privacy and security assessments, governance, risk and compliance, and privacy and security incident response
  • Collaborate with stakeholders to help develop, improve, and enforce Snap’s data security policies, standards, and practices, ensuring they meet global legal requirements
  • Ensure Snap’s data processing globally complies with all applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and state and federal consumer protection and privacy laws
  • Partner with Product Counsel on complex issues that arise in the development of new products and technologies, including privacy, data security, and encryption
  • Work with Snap’s Privacy Engineering team to continually improve Snap’s privacy-by-design program
  • Analyze potential legal risks and regulatory requirements for new products and technologies
  • Conduct privacy due diligence reviews, privacy impact assessments, and integration plans for potential acquisitions and partnerships
  • Help draft public-facing descriptions of new products and technologies
  • Track and analyze proposed, pending, and new domestic and global privacy, data security, and consumer legislation that could impact the business and recommend necessary modifications to practices, as well as advise Snap’s Policy team on policy engagement priorities
  • Conduct periodic privacy and security trainings across the company

Posted July 17, 2026

Yahoo – Privacy Counsel

Responsibilities:

  • Partner closely with product, engineering, and business teams throughout the product lifecycle, embedding privacy by design into new advertising products and features from ideation through launch.
  • Advise on the privacy implications of advertising technologies, including AI enabled products, machine learning models, personalization, identity resolution, cookie alternatives, first party data strategies, retail media, clean rooms, measurement technologies, and evolving addressability solutions.
  • Counsel product teams on U.S., Canadian, and global privacy laws, helping translate complex legal requirements into practical product guidance that supports innovation.
  • Advise on consent management frameworks, including Global Privacy Control (GPC), Global Privacy Platform (GPP), IAB Transparency & Consent Framework (TCF), and other industry standards, ensuring Yahoo’s platforms appropriately implement evolving privacy signals.
  • Structure, draft, review, and negotiate privacy and data protection provisions in commercial agreements, including MSAs, DPAs, data licensing agreements, and strategic technology partnerships.
  • Advise on cross border data transfers, international privacy compliance, Standard Contractual Clauses, and other global data governance requirements.
  • Partner with cross functional teams to conduct privacy impact assessments, AI risk assessments, and data protection reviews for new products and initiatives.
  • Support privacy incident response, advising on legal obligations, regulatory notification requirements, and coordination with security, communications, and outside counsel.
  • Design scalable legal infrastructure, including playbooks, templates, AI-enabled workflows, and self service guidance, that enables product teams to move quickly while maintaining compliance.
  • Represent Yahoo in industry organizations and standards bodies, including the IAB, NAI, DAA, and similar forums, helping shape the future of responsible digital advertising.

Posted July 15, 2026

Coursera – Senior Privacy Counsel

Responsibilities:

  • Global subject matter expert: Serve as the primary legal advisor on US privacy laws, including federal and state frameworks (such as CCPA/CPRA), while providing guidance on applicable global privacy and privacy-adjacent laws, including the EU and UK GDPR and key APAC and Latin American frameworks. Advise the business on legal and regulatory developments and their practical impact.
  • Privacy Program: Help to continuously develop, implement, and scale Coursera and Udemy’s global privacy program, including by developing and maintaining standardized privacy notices, internal policies, tools, processes, playbooks, and training.
  • Delivering Legal Guidance: Support and advise key stakeholders on a broad range of complex privacy, AI, and cyber issues and provide pragmatic and risk-based solutions in accordance with global privacy laws.
  • Incident reporting: Investigate and manage security incidents that impact personal information, together with Engineering, InfoSec and other stakeholders.
  • Regulatory responses: Respond to requests and inquiries from individuals and privacy regulators.
  • Strategic leadership: Act as a trusted advisor to senior leadership on privacy risk and strategy, and mentor and support other members of the Privacy and broader Legal and Compliance teams.

Posted July 15, 2026

MetLife – AVP & Assistant General Counsel, Privacy

Responsibilities:

  • Provide advice and counsel on legal and regulatory matters involving privacy having a potential global impact and requiring coordination across regions and businesses.
  • Identify and resolve legal issues and offer commercially viable solutions through research, analysis, creativity and teamwork that contribute to global business goals while ensuring appropriate management of legal risks.
  • Stay current on developments affecting privacy law around the world, including its intersection with technology and AI law.
  • Act as a trusted advisor and partner to Privacy Compliance, Global Government Relations, Global Technology & Operations, Employment Law, Human Resources and other business areas in developing and advocating positions to advance MetLife’s interests.
  • Negotiate and document privacy provisions in complex agreements, including vendor, customer and M&A agreements.

Posted July 14, 2026

RingCentral – Senior Privacy Counsel

Responsibilities:

  • Act as the dedicated privacy legal point of contact, providing proactive, risk-based counsel to Engineering and Product Management teams throughout the entire development lifecycle of new services and features.
  • Provide specialized legal advice on the privacy implications of any new features, including AI features, in collaboration with the Product Counseling and Regulatory Teams, ensuring compliance with emerging AI regulations and ethical guidelines as it relates to privacy.
  • Lead the execution and documentation of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) for new features and services, driving legal processes that embed privacy requirements early in the development process, in coordination with other Privacy Team Members.
  • Ensure that RingCentral services comply with evolving global privacy and security regulations.
  • Partner directly with the Information Security team to review product security controls, conduct risk analyses, align legal privacy requirements with technical security implementation for all new products, including as it relates to HIPAA, and ensure that security policies align with and take into account requirements for the protection of personal information.
  • Develop and update customer-facing collateral and resources on RingCentral Trust Centerto support transparency for customers and partners.
  • Support records of processing activities and documentation for products including data locations, data transfers, and subprocessor processing in coordination with other Privacy Team members.
  • Support the incident response program, by ensuring that the documentation is current and in alignment with applicable laws and by representing the privacy team in the incident response activities.
  • Monitor legal developments, collaborate and build relationships with industry peers, to stay abreast of trends and issues globally, as they may impact RingCentral’s privacy posture, templates, and commercial practices.

Posted July 14, 2026

NVIDIA – Senior Counsel, Data Privacy and Governance

Responsibilities:

  • Advising the HR and Recruiting teams on privacy requirements applicable to the collection, use, and retention of employee and candidate personal data, including background check data, assessment results, and hiring records.
  • Reviewing and negotiating vendor contracts and data processing agreements (DPAs) with HR technology vendors, background screening providers, recruiting platforms, and other third-party processors handling workforce data.
  • Advising on cross-border employee and applicant data transfers, including transfer impact assessments and applicable safeguards under GDPR, PIPL, and other international frameworks.
  • Counseling on privacy considerations related to AI-assisted recruiting tools, applicant tracking systems, automated decision-making, and workforce analytics, including obligations under emerging algorithmic transparency and automated decision laws.
  • Supporting employee-facing privacy notices, data subject rights requests from employees and candidates, and related HR data governance policies.
  • Tracking legal developments in employment privacy, including U.S. state laws and international regulations affecting the HR and recruiting lifecycle, and translating those developments into practical guidance.
  • Growing into broader privacy and data governance responsibilities as the program evolves.

Posted July 8, 2026

Uber – Counsel – Privacy & Cybersecurity Legal

Responsibilities:

  • Advise Uber product and engineering teams regarding data privacy and cybersecurity requirements, best practices, and Uber’s Privacy Principles
  • Drive privacy-by-design and -default throughout Uber’s product development process
  • Track and research developments relating to new and pending laws that impact Uber’s privacy and cybersecurity program, including U.S. state laws and the EU’s GDPR, AI Act, and Platform Work Directive; translate that into practical, effective advice; and lead compliance efforts relating to these laws
  • Negotiate privacy requirements in third-party agreements
  • Create and present engaging company-wide trainings regarding data privacy and security requirements and standard methodologies
  • Drive awareness regarding cutting-edge legal and business developments, including regarding use of AI and machine learning, and lead team efficiency, morale and collaboration efforts
  • Contribute to our ongoing mission to make magic in the marketplace, and drive Uber’s efforts to be a trusted steward of our users’ personal data in every market where Uber operates

Posted July 8, 2026

Lyra Health – Privacy & AI Counsel

Responsibilities:

  • Support Lyra’s privacy program and advise internal stakeholders on privacy concerns related to Lyra’s products and services, and the implementation of new technologies, such as AI.
  • As a core component of the role, participate extensively in AI use case reviews, including those involving generative AI and agentic AI for internal use at Lyra, and in legal reviews and assessments relating to the development by Lyra of AI-powered products, services, and tools. Drive the AI use case review process forward to meet established SLAs, ensuring the business remains agile.
  • Draft, maintain, and evolve AI governance documentation, including the Company’s Responsible AI Policy and related standards, procedures, and guidance.
  • Coordinate with internal teams to ensure corporate adherence to applicable state and federal privacy laws, including, but not limited to, CCPA and HIPAA.
  • Stay abreast of, analyze, and advise on evolving US laws and regulations relating to privacy and AI at both the state and federal level. Update the legal team and the business on relevant new regulatory requirements and feed into policy and procedural documentation.
  • Support international AI regulatory compliance by partnering with the Privacy Counsel, International on the EU AI Act and other global AI regulations, including leading horizon scanning efforts and proactively delivering insights and updates to the legal team and broader Lyra business.
  • Collaborate with commercial counsel to ensure that privacy provisions in commercial agreements and Business Associate Agreements (BAAs) appropriately manage risk and comply with privacy policies, laws, rules, regulations, and company objectives.
  • Review BAAs negotiated by commercial counsel and document data use permissions for new and existing customers.
  • Work cross-functionally to advise product and business teams on potential privacy and AI regulatory implications of Lyra’s new and existing product lines, including reviewing and approving product requirement documents (PRDs).
  • Investigate, manage, document and report privacy incidents, including breaches, in accordance with applicable law, contractual requirements and corporate strategy.
  • Participate in cross-functional teams working on AI governance and AI use case reviews.

Posted July 4, 2026

Nordstrom – Senior Corporate Counsel, Privacy (Hybrid, Seattle)

Responsibilities:

  • Serve as the primary legal advisor on U.S. state privacy laws, including CCPA/CPRA, and the growing patchwork of state comprehensive privacy statutes (Virginia, Texas, Colorado, etc.)
  • Lead and maintain the company’s U.S. privacy compliance program, including privacy notices, consent mechanisms, opt-out frameworks, and data subject rights processes
  • Monitor legislative and regulatory developments in U.S. privacy law and advise on required compliance changes in the context of rapidly evolving business processes
  • Monitor and assess emerging AI legislation, regulatory guidance, and enforcement trends across federal, state, and international jurisdictions, and advise on their practical implications for Nordstrom’s use of AI and automated decision-making

Posted July 3, 2026

Light & Wonder – Senior Counsel, AI and Data Governance

Responsibilities:

  • Serve as legal advisor on the Company’s enterprise-wide adoption, deployment, and use of AI and machine learning tools, including generative AI platforms and AI-enabled products.
  • Monitor, analyze, and advise on the rapidly evolving global AI regulatory landscape, including the EU AI Act, US federal and state AI legislation, and emerging frameworks across key jurisdictions (UK, Canada, Brazil, India, Australia, Singapore/APAC).
  • Support the Company’s AI governance framework, including internal policies, standards, and acceptable use guidelines governing the procurement, deployment, and employee use of AI tools.
  • Assess and classify AI systems in accordance with applicable regulatory risk tiers (e.g., EU AI Act high-risk classifications) and advise product, engineering, and business teams on applicable compliance obligations.
  • Provide legal guidance on AI-specific risks including algorithmic bias and discrimination, risks related to AI use in connection with employment and transparency obligations.
  • Work with the Legal Department’s IP team on risks related to IP ownership issues arising from AI-generated outputs.

Posted July 2, 2026

*  *  *

Looking for an older job listing? In an effort to keep this page as up-to-date as possible, we have moved Job Listings older than the date above to our Condensed Job Listings page. We hope this comprehensive list will allow you to see the many different career opportunities that exist in Privacy and Data Security Law.