Associate General Counsel, Privacy & Compliance
Job description
About the role
Neuralink seeks an Associate General Counsel to define and lead privacy and compliance for a medical device company operating at the intersection of neurotechnology and healthcare. In this role, you will establish and manage the privacy and compliance program for highly sensitive neural data, working directly with Clinical, Regulatory, and Engineering teams. The ideal candidate is an operator who builds governance frameworks early and takes ownership of impactful, company-wide initiatives. You will be the primary architect of the privacy strategy, ensuring that neural data handling is governed by rigorous standards from the outset. This position requires a proactive leader who anticipates compliance risks before they escalate into organizational issues. You will translate complex regulatory landscapes into actionable frameworks for a fast-paced, innovation-driven environment. The role demands close collaboration with technical and clinical stakeholders to embed legal requirements into product design and study execution. Ultimately, you will safeguard the company and its participants by ensuring all activities adhere to the highest legal and ethical standards.
Key Facts
What you'll do
- Design and implement intake processes for privacy requests and data governance across product and clinical operations.
- Embed privacy by design principles, advising on data minimization and retention strategies for neural recordings, and guiding product and engineering teams.
- Manage vendor privacy reviews and negotiate data processing agreements, including subprocessor oversight and transfer impact assessments.
- Lead the development of incident response playbooks, conducting breach assessments, and managing notification and regulator communication for healthcare data events.
- Serve as the subject matter expert on HIPAA, shaping Business Associate Agreements, study protocols, and ensuring alignment with clinical investigators and ethics committees.
- Drive global privacy compliance, including oversight of US state privacy laws, and support the responsible expansion of clinical trials internationally.
- Maintain data flow maps, privacy notices, internal data handling standards, and manage DSAR and data rights response processes.
- Guide healthcare compliance infrastructure, including training, monitoring, and reporting aligned with OIG Seven Elements expectations.
- Advise on interactions with healthcare professionals, ensuring adherence to AdvaMed Code, Sunshine Act reporting, and regional HCP interaction rules.
- Track regulatory developments and translate them into concrete operational changes for Clinical, Regulatory, and Engineering.
- Establish metrics and reporting mechanisms to measure the effectiveness of the privacy and compliance program.
- Partner with Clinical teams to ensure that neural data collection and usage in studies comply with evolving privacy regulations.
- Collaborate with Engineering to implement technical controls that enforce privacy policies and data access restrictions.
- Oversee the lifecycle management of data, from collection through archival or secure deletion, in accordance with legal requirements.
- Act as a strategic advisor to executive leadership on privacy risks and compliance investments.
Requirements
- Hold a Doctor of Jurisprudence from an accredited law school and maintain active bar membership in California or Texas.
- Possess hands-on privacy experience within a medical device or high-growth health technology environment.
- Have a minimum of 10 years of privacy-focused legal practice, with demonstrated in-house leadership of a privacy program.
- Hold CIPP/US and CIPP/E credentials are strongly preferred.
- Demonstrate deep, practical knowledge of HIPAA Privacy, Security, and Breach Notification Rules, including experience with Business Associate Agreements.
- Show understanding of clinical trial data governance, informed consent, and research ethics committee expectations for patient privacy.
- Exhibit proven ability to manage complex regulatory compliance programs in a dynamic, high-growth setting.
- Display strong judgment and the ability to interpret regulations and apply them to emerging business scenarios.
- Communicate effectively with both technical and non-technical audiences, translating legal concepts into practical guidance.
- Thrive in an environment that demands agility, ownership, and a high tolerance for ambiguity.
Nice to have
Experience advising digital health, wearable tech, or life science companies managing sensitive health data is valued. No specific tools are listed for this role.
Practical notes
Please What you'll do
- Meet the bar About the company
We build brain interfaces that link nervous systems with digital tools. Our teams work to restore autonomy for people with unmet medical needs, using implants that record and stimulate neural activity.
Across product, science, and engineering, we focus on long term safety and precise outcomes. We invest in durable hardware, software, and clinical workflows so the technology integrates responsibly into medical practice.