Solutus Legal Search Logo

Solutus Legal Search

Associate General Counsel, Privacy – Remote (USA) (993-SLS)

Posted 7 Days Ago
Remote
Hiring Remotely in USA
Expert/Leader
Remote
Hiring Remotely in USA
Expert/Leader
Own and scale the company’s global privacy and data protection program. Advise product, engineering, sales, marketing, security, and executives on privacy laws, data transfers, DPAs, AI governance, security commitments, incident response, and regulatory requirements. Manage privacy assessments, data inventories, notices, training, outside counsel, and vendor relationships. Partner with Security and GRC on audits, certifications, breach response, government requests, and customer obligations while building scalable processes and eventually a privacy team.
The summary above was generated by AI

Our client, the company behind the fastest open-source analytical database in the world and a mission-driven, fast-growing private cloud company and leader in real-time analytics, data warehousing, and data observability, has exclusively engaged Solutus Legal Search to assist its executives in hiring an attorney to serve as Associate General Counsel, Privacy.

The Role

    Reporting to the General Counsel, this attorney will own the company’s global privacy legal function, serving as the company’s principal legal advisor on domestic and international privacy and data protection matters, as well as be the Legal Team’s principal partner with the Security Team. This attorney will partner closely with business teams to develop and implement practical, business-oriented approaches to complex privacy issues and build scalable processes that support the company’s continued growth.

    This is a build role: you will take a growing set of privacy obligations, customer commitments, and regulatory exposures and turn them into a coherent, well-documented program that scales with the business.  You will be the privacy expert in the room for product and engineering decisions, the person Sales and Legal turn to on DPAs and cross-border transfer questions and data flow mapping, and the legal lead alongside Security and GRC functions on security commitments, audits, and incident response.  You will operate as an individual contributor, with the expectation that you build a team as the program matures.  This role suits someone who is comfortable with technical depth. You will be reading data flow diagrams, asking engineers precise questions about where data is stored and who can reach it, and giving answers a product team can actually implement.


What You'll Do

    Own the global privacy program

  • Advise on domestic and international privacy and data protection laws and regulations, including GDPR, HIPAA, CCPA/CPRA, other U.S. state and international privacy laws, and international data transfer requirements.
  • Own the data subject request process end to end, along with the privacy elements of vendor and subprocessor diligence.
  • Track regulatory and enforcement developments across jurisdictions and translate them into concrete changes to our product, contracts, and internal practices — not just memos.
  • Conduct and oversee privacy risk assessments, including data protection impact assessments (DPIAs), transfer impact assessments, and related documentation.
  • Manage and build out the function

  • Enhance and mature the company’s privacy program to continue meeting evolving regulatory requirements. Scale core program components with respect to data subject rights requests, privacy notices, consent management, impact assessments, and policy management.
  • Maintain the program's operating machinery: records of processing, data inventories and mapping, retention schedules, DPIAs and transfer impact assessments, and privacy policies and notices.
  • Deliver privacy and security training that people remember, and drive internal awareness across engineering, sales, marketing, partner relationships and support.
  • Manage outside counsel and privacy vendors against a budget.
  • Serve as, or manage the relationship with, our EU representative and data protection officer arrangements as required.
  • Advise Marketing on adtech, cookies and tracking technologies, and electronic marketing compliance.
  • Report to leadership on privacy and security risk and support Board and audit reporting on the program.
  • Counsel product and engineering

  • Embed with product and engineering teams as they design features, giving privacy-by-design guidance early enough to shape architecture rather than block launches.
  • Advise on data residency and localization, telemetry and usage data, encryption and key management, access controls, logging, anonymization and pseudonymization, and retention and deletion mechanics.
  • Advise on AI and machine learning features — training data provenance, customer data use restrictions, model and vendor terms, and emerging AI regulatory requirements.
  • Support commercial contracting

  • Own our DPA and its negotiation strategy, including standard contractual clauses, the UK IDTA and Addendum, and other transfer mechanisms; negotiate the privacy and security terms in customer and vendor agreements.
  • Serve as escalation point for Legal and Deal Desk on privacy and security terms, and build the playbooks, fallback positions, and self-service guidance that let the rest of the team resolve most of these without you.
  • Support enterprise, public sector, and regulated-industry deals with sector-specific requirements, including HIPAA business associate agreements and financial services and payments obligations.
  • Partner with Security and GRC

  • Serve as legal counsel to the Security organization on our security commitments, control frameworks, and audit and certification programs — SOC 2, ISO 27001, HIPAA, PCI DSS, and the frameworks we take on next.
  • Lead the legal workstream in security incident response: assess breach notification obligations across jurisdictions and contracts, manage regulator and customer notification, direct outside counsel and forensics under privilege, and run tabletop exercises with Security.
  • Advise on law enforcement and government data requests, preservation obligations, and the policies governing how we respond.
  • Support the GRC and Compliance functions on customer security questionnaires, trust center content, and the accuracy of our public privacy and security representations

Requirements:

  • Strong academic credentials and membership in good standing with at least one U.S. state bar.
  • 7-10+ years of relevant legal experience, with strong training at a top-rated national or international law firm. Law firm and in-house experience at a high-growth B2B SaaS company, preferably in the data infrastructure sector.
  • Significant experience advising on domestic and international privacy and data protection matters.
  • Deep knowledge of global privacy laws and regulatory frameworks, including GDPR, HIPAA, CCPA/CPRA, other U.S. state and international privacy laws, cross-border data transfer requirements, and evolving privacy and data governance regulations.
  • Experience advising business and technical teams on privacy issues across the product lifecycle, including with respect to AI, machine learning, and emerging technologies, is strongly preferred.
  • Experience supporting security matters, including with respect to customer-facing security commitments, security incident support, and related regulatory requirements, is preferred.
  • Excellent judgment, strong business orientation, and ability to translate complex legal issues into practical advice.
  • Strong interpersonal and communication skills and the ability to work effectively with executives and cross-functional stakeholders.
  • Exceptional attention to detail, strong organizational skills, and ability to manage multiple priorities in a fast-moving, high-growth environment.

The current targeted base salary for this position ranges from $260,000 - $295,000, plus equity and a generous benefits package. Actual compensation is determined based on several factors, including a candidate’s qualifications, number of years of directly relevant experience, and location.

Solutus has been selected as the retained representative on this desirable search. Resumes submitted directly to our client will be forwarded to Solutus for review and evaluation.

Ref. #993-SLS

Similar Jobs

A Minute Ago
Easy Apply
Remote
United States
Easy Apply
250K-349K Annually
Expert/Leader
250K-349K Annually
Expert/Leader
Cloud • Security • Software • Cybersecurity • Automation
Leads technical direction for GitLab’s Core DevOps services, covering CI, CD, planning, and source control. Defines architecture, quality metrics, migration strategies, and technical roadmaps; addresses systemic risk and complex design decisions; prototypes and writes code when needed; partners with Infrastructure, Security, SRE, and Product; adopts AI capabilities; mentors senior engineers; supports incident response and senior technical hiring.
Top Skills: Agentic FrameworksAIAutonomous WorkflowsCi/CdDevOpsDistributed SystemsFault ToleranceGitlabHuman-In-The-Loop ControlsLarge Language ModelsMachine LearningMulti-Tenant SystemsObservabilityResponsible Ai
A Minute Ago
Easy Apply
Remote
United States of America
Easy Apply
200K-220K Annually
Expert/Leader
200K-220K Annually
Expert/Leader
Information Technology • Cybersecurity
Lead the technical vision and architectural evolution of Huntress’s Core Platform. Build complex Ruby on Rails features, solve scaling challenges, manage cross-team dependencies, drive architectural decisions, and oversee system lifecycle and technical risk. Mentor engineers, establish engineering excellence, collaborate with managers and product leaders, and help teams adopt AI coding tools responsibly.
Top Skills: Ai Coding ToolsAWSLinuxRubyRuby On Rails
3 Minutes Ago
Remote or Hybrid
New York, NY, USA
230K-290K Annually
Expert/Leader
230K-290K Annually
Expert/Leader
Fintech • Mobile • Social Impact • Financial Services
Lead Brigit's product organization across product management, design, and research. Own product vision, roadmaps, and outcomes (acquisition, conversion, engagement, monetization). Build and scale cross-functional teams, drive data-informed experimentation, and partner with engineering, data, and marketing to optimize product velocity and business metrics in a regulated consumer fintech environment.

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account