Senior Privacy & Security Counsel

🔥 1 hour ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GC AI

GC AI

11 - 50 employees

Founded 2023

🤖 Artificial Intelligence

⚖️ Legal

☁️ SaaS

Artificial Intelligence • Legal • SaaS

GC AI is an AI-driven legal assistant platform built for in-house legal teams. It helps lawyers draft, review, and analyze contracts and legal documents rapidly with features like Easy Prompt™ for turning plain language into legal prompts, Exact Quote with verifiable citations, a Skill Library and agents to chain tasks, and integrations such as GC AI for Microsoft Word. The product emphasizes security and privacy (SOC 2 Type II, AES-256 encryption, TLS in transit, data isolation) and explicitly does not use customer data for commercial model training. Founded by former General Counsel Cecilia Ziniti, GC AI targets in-house counsel workflows and legal research (including access to 13M+ U. S. court opinions) and is positioned as a B2B SaaS tool trusted by 1,900+ legal teams.

📋 Description

• Own GC AI's privacy and security legal posture across every regulatory framework that touches the business. • Serve as the internal subject matter expert that product, engineering, sales, and the commercial legal team rely on for privacy and security guidance. • Directly enable enterprise deals by handling the DPA and security addendum negotiations that sophisticated customers require. • Build and maintain the privacy and security playbook positions that scale with GC AI's growth. • Keep GC AI ahead of the regulatory curve on AI governance, international privacy frameworks, and emerging US state privacy laws. • Own the legal framework for GC AI's SOC 2, ISO 27001, and ISO 42001 compliance programs, partnering with the GRC and Compliance team on operational execution. • Advise product and engineering on privacy-by-design, data protection impact assessments, and AI governance requirements. • Own GC AI's regulatory compliance posture for GDPR, CCPA/CPRA, EU AI Act, and emerging US state privacy laws. • Serve as the escalation point for complex DPA and security addendum negotiations, working alongside the commercial legal team. • Directly handle DPA and security addendum redlines for strategic and high-value customer deals. • Maintain and evolve GC AI's standard DPA, security addendum, and Information Security Addendum templates and playbook positions. • Support enterprise sales by joining security calls with sophisticated prospects and responding to detailed security and privacy inquiries. • Assist with managing relationships with external auditors and compliance vendors (e.g., SOC 2 auditors, penetration testing firms, privacy tooling providers). • Advise on incident response legal obligations, breach notification requirements, and customer communications. • Own the legal review of the Trust Center, security marketing claims, and subprocessor disclosures. • Provide guidance on cross-border data transfers, international privacy frameworks, and jurisdiction-specific data protection requirements. • Assist with other compliance projects (including entity compliance management) • Take on additional projects and tasks as needed in response to the evolving needs of a fast-growing startup.

🎯 Requirements

• JD and active bar membership in at least one US jurisdiction. • 5-10 years of privacy and security legal experience, with a meaningful portion in-house at a technology or SaaS company. • Deep working knowledge of GDPR, CCPA/CPRA, and the broader US and international data protection regulatory landscape. • Experience supporting sales processes at a B2B SaaS company, including security reviews, procurement questionnaires, and customer-facing calls. • Experience negotiating DPAs and data protection terms in a B2B SaaS context, including GDPR Article 28 processor obligations, standard contractual clauses, and cross-border transfer mechanisms. • Demonstrated ability to work independently, prioritize competing demands, and deliver under pressure. • Comfort working at startup pace with ambiguity, shifting priorities, and limited precedent.

🏖️ Benefits

• Health insurance • Professional development opportunities • Flexible work arrangements

Apply Now

Similar Jobs

🔥 1 hour ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

ICAM ISSO overseeing information systems security compliance for Koniag Government Services in cybersecurity initiatives. Responsible for managing security risks and ensuring adherence to federal mandates.

🔥 1 hour ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Information System Security Manager supporting cybersecurity and compliance for Okta-based systems in federal environments. Overseeing risk management and security posture for government customers.

🔥 1 hour ago

Koniag Government Services

1001 - 5000

🏛️ Government

🎖️ Defense

💼 Consulting

Security Lead / Release Lead overseeing security compliance and release management for government IT programs. Supporting Koniag IT Systems in a remote capacity with a Secret security clearance.

🔥 1 hour ago

Dropzone AI

51 - 200

🤖 Artificial Intelligence

Senior Security Engineer ensuring AI SOC Analyst generates accurate, timely reports for cybersecurity transformation at Dropzone AI. Collaborating across teams for continuous investigation quality improvement

🔥 1 hour ago

rater8

51 - 200

🏥 Healthcare

☁️ SaaS

🤝 B2B

Senior Security and Compliance Lead at rater8, overseeing information security and compliance programs. Managing governance, risk, and compliance efforts in the healthcare industry while ensuring alignment with regulatory standards.