Privacy & Product Counsel
HybridSan Francisco, California, United States
Job Summary
Design and run Hilbert's privacy program from the ground up, covering policies, data mapping, retention, and vendor management across US, UK, and EU entities. Advise product and engineering on privacy-by-design for agentic workflows and document data access, retention, and inference under CCPA/CPRA, UK GDPR, and EU GDPR. Review and negotiate enterprise contracts, DPAs, and security addenda while partnering on incident response and breach notifications. Serve as the primary point of contact for enterprise customers' legal and security teams regarding AI data handling. Work directly with the founding team and cross-functional groups to build scalable legal frameworks that move at startup speed.
Required Qualifications
- 6–7 years of PQE in privacy and product/commercial counsel
- ideally split between in-house work at a data-intensive or AI company and enterprise contract negotiation
- genuinely fluent across US, UK, and EU privacy law — CCPA/CPRA and the state patchwork, UK GDPR/DPA 2018, and EU GDPR
- negotiated enterprise DPAs, security addenda, and cross-border transfer mechanisms directly
- San Francisco or London, hybrid, with occasional travel for customer engagements and to work with the other office
Desired Qualifications
- think like a product person, not just a lawyer
- sit in a design review and shape a data flow before it's built than redline it after
- communicate with clarity and conviction
- explain a data-retention tradeoff to a founder
- hold your ground with an enterprise customer's outside counsel
- walk an engineer through why a feature needs a consent gate
- take ownership
- move at startup speed
- available and responsive without needing a legal-ops process to get there
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.