Advise on operational privacy matters, state consumer privacy laws, GLBA, Internal Revenue Code Section 7216, and other applicable regulations
Draft, review, and negotiate data protection agreements, vendor contracts, and technology-related contracts
Partner with GRC to strengthen governance frameworks and conduct risk and privacy assessments and internal audit functions
Support AI governance and vendor diligence, ensuring responsible adoption of generative AI and LLM technologies
Collaborate cross-functionally with IT, cybersecurity, product, development and marketing teams on AI adoption and data privacy matters
Monitor and interpret AI and consumer privacy regulations to ensure compliance with applicable laws when implementing AI tools and other technologies and develop internal guidance and training on relevant topics
Advise on privacy and data protection issues related to cookies, pixels, SDKs, and other tracking technologies used for analytics, marketing, and advertising, including oversight of analytics tools and consent management solutions
Requirements
J.D. degree and admission to practice law in at least one U.S. jurisdiction
4–8 years of legal experience, preferably with a law firm and/or in-house with software/tech experience and a focus on privacy and emerging technologies (AI and LLMs)
Deep understanding of U.S. state privacy laws (CCPA/CPRA, etc.)
Proven experience drafting and negotiating commercial and technology contracts
Excellent communication and collaboration skills, with a pragmatic, business-focused approach