Privacy Counsel
Job description
About the role
HackerOne is actively seeking a seasoned Privacy Counsel to join its LEGIT legal team and take ownership of global data protection, AI governance, and commercial contracting initiatives. The successful candidate will serve as a primary legal partner, working cross-functionally with product, sales, and engineering to de-risk privacy challenges associated with rapidly evolving technologies. You will own the strategic analysis and execution of privacy programs that enable secure innovation while maintaining regulatory compliance. This position requires a professional who thrives in a fast-paced, ambiguous environment and applies structured legal reasoning to novel problems. You will be responsible for translating complex regulatory landscapes into actionable business guidance that protects the company and empowers growth. The role offers the opportunity to shape privacy practices and AI policies that impact users and customers on a global scale. If you are passionate about building robust privacy frameworks within a high-growth tech organization, this role is a direct opportunity to own that mission end to end.
Key facts
What you'll do
- Lead global privacy assessments by designing and executing Data Protection Impact Assessments (DPIAs), AI DPIAs, Transfer Impact Assessments (TIAs), and Legitimate Interest Assessments (LIAs) for new and existing processing activities.
- Partner with product and engineering teams to embed privacy-by-design and privacy-by-default principles into new product features and AI capabilities before launch.
- Own the negotiation and drafting of data processing agreements, data sharing agreements, privacy terms of service, and commercial contracts containing complex data protection clauses.
- Develop, maintain, and update internal privacy policies, standardized templates, playbooks, and contractual documentation to ensure consistency and legal defensibility.
- Plan and deliver internal training programs focused on privacy obligations, AI governance, regulatory updates, and practical contract interpretation for cross-functional stakeholders.
- Coordinate privacy audits by collaborating with internal stakeholders and external advisors, managing findings, and tracking remediation plans to closure.
- Establish a monitoring function for global privacy laws and AI-specific regulatory frameworks, translating legislative changes into timely policy recommendations and compliance strategies.
- Leverage AI-assisted tools and legal technology to streamline document drafting, accelerate legal research, and improve the accuracy of privacy analyses.
- Serve as a subject matter expert for privacy matters, providing clear, actionable guidance to executives, engineers, sales teams, and other internal customers.
- Drive continuous improvement of the privacy program by identifying gaps, proposing enhancements, and measuring the effectiveness of implemented controls.
Requirements
- Hold qualifications as a qualified lawyer in the United Kingdom or European Union with a minimum of 5 years of post-qualification experience in either in-house roles or private practice.
- Demonstrate deep knowledge of the UK General Data Protection Regulation (UK GDPR) and EU GDPR, along with familiarity with privacy legal frameworks in the United States, Asia, and the Middle East.
- Bring proven experience in managing data breach responses, regulatory notifications to supervisory authorities, and internal and external privacy audits.
- Show strong proficiency in negotiating and finalizing data processing agreements, data protection clauses, and commercial privacy terms across multiple jurisdictions.
- Possess the ability to distill intricate legal concepts into clear, concise explanations for non-legal business partners, facilitating informed decision-making.
- Show understanding of artificial intelligence technologies, associated ethical considerations, and relevant legal frameworks governing AI systems and data usage.
- Demonstrate hands-on experience with privacy management software platforms, specifically OneTrust, to manage assessments, disclosures, and records of processing activities.
- Commit to working in a fully remote or hybrid capacity, respecting time zone expectations and maintaining high productivity without direct supervision.
Nice to have
- Hold recognized privacy certifications such as Certified Information Privacy Professional (CIPP) or Certified Information Privacy Manager (AIGP).
- Show fluency in the German language, enabling effective communication with stakeholders in German-speaking regions.
- Bring a background in SaaS business models, cybersecurity product lines, or experience within offensive security environments.
Practical notes
- Visa or work permit sponsorship is not available for this position.
- Employment within the United States is contingent upon successful completion of a background check.
- The company offers a comprehensive benefits package that includes medical, vision, and dental insurance, retirement plans, equity stock options, unlimited paid time off, and paid parental leave.
- For locations outside the United States, the United Kingdom, the Netherlands, and India, HackerOne utilizes Remote.com as an Employer of Record to facilitate employment and compliance.
- The role is fully remote, allowing the selected candidate to work from an eligible country without mandatory relocation, provided they can perform the essential functions within the stated expectations.
- Interested candidates should be prepared to detail their experience with privacy law, AI governance, and contract negotiation during the interview process.
- The company maintains an equal opportunity policy and encourages diverse candidates to apply for this position.
- This job description is intended to convey the general nature and level of work performed and does not limit the scope of responsibilities, which may evolve based on business needs and regulatory developments.