Managing Legal Counsel - Privacy
$174,000–$297,000 year
HybridBaltimore, Maryland, United States or Owings Mills, Maryland, United States
Job Summary
Review and advise on product development and business initiatives to ensure privacy legal compliance, including privacy-by-design and security-by-design principles. Negotiate, draft, and review privacy-related contracts, including Investment Management & Distribution Agreements, Data Processing Agreements, Vendor agreements, and AdTech contracts. Ensure compliance with U.S. privacy laws (CCPA/CPRA, and other state laws), digital and AdTech regulations, and global privacy frameworks, such as GDPR and privacy legislations in APAC. Monitor, track and analyze global regulatory developments, industry trends, and enforcement actions to proactively address legal issues as regards use of AI, including privacy issues in the use of AI, and other privacy legal risks and opportunities. Provide strategic guidance to business leaders and cross-functional teams on privacy related legal issues and risk mitigation. Lead and support the Global Privacy Office in performing privacy impact assessments (PIAs/DPIAs), data mapping, and records of processing activities. Develop, implement, and maintain privacy policies, procedures, and training materials. Manage and coordinate responses to privacy and data security incidents, including potential regulatory notifications and remediation. Represent the company in industry groups and advocate for privacy best practices. Collaborate with cross-functional teams to implement legally compliant privacy best practices.
Required Qualifications
- J.D. from an accredited law school
- active membership in at least one U.S. state bar
- 10+ years of total relevant work experience
- Deep knowledge of U.S. privacy laws (CCPA, CPRA, and other state laws)
- familiarity with global privacy frameworks (including GDPR, Singapore's PDPA, Hong Kong's PDPO, Japan's APPI and the Privacy Act 1988 of Australia including its APPs)
- Demonstrated ability to draft and negotiate complex data or privacy-related contracts and technology contracts
- Demonstrated experience providing robust and practical legal advice relating to privacy and data protection
- Strong communication, negotiation, and teamwork skills, with the ability to influence and collaborate across different functions in a global organization with stakeholders with diverse background from various countries including not only US, but also EMEA and APAC
- Proven ability and experience to independently manage multiple complex projects engaging with cross-functional stakeholders in a global context and provide practical, actionable, and business-oriented legal advice
Desired Qualifications
- Prior in-house experience as an attorney
- Experience advising clients within the asset management/financial services sector with global coverage
- Certification in privacy (e.g., CIPP/US, CIPP/A, CIPM, CIPT)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.