Incident Management: Independently manage the legal response to privacy-related incidentsProcess & Training: Draft and maintain policies, playbooks, checklists, FAQs, and training materials to improve process and streamline stakeholder engagement on privacy and regulatory mattersOperational Support: Oversee and conduct Data Protection Impact Assessments (DPIAs), maintain Records of Processing Activities (RoPAs), and support audits, law enforcement requests, and platform-abuse process and policyWhat We're Looking For:Education & Credentials: JD from a respected institution and membership in good standing with at least one U.S. state barExperience: 8+ years of relevant legal experience, with significant in-house experience advising on global privacy and regulatory matters at a technology company, especially in the cloud or SaaS spaceRegulatory Expertise: Advanced knowledge of U.S. and global privacy and data protection laws and experience with emerging technology regulations, including AI regulatory schemesProgram Management: Experience building and managing a privacy program and providing clear, actionable legal guidance to business, product, and engineering teamsTechnical Literacy: Technology industry experience and familiarity with technical concepts such as APIs, encryption, LLMs, and cloud architectureProblem-Solving: A pragmatic, solution-oriented approach to problem-solvingCommunication: Excellent written and verbal communication skills and the ability to simplify complex legal issues for a business audienceExecution: Ability to own matters and prioritize, manage, and complete projects independently in a dynamic, evolving environmentCollaboration: A collaborative team player who enjoys working across disciplines and values building relationships and improving processesWork Hours:This position will require you to be available during core business hours. This position reports to the Assistant General Counsel leading the Product, Technology, and Regulatory team, and will be based out of one of our offices with a preference for San Francisco, CA.What You'll Do:Domain Leadership: Architect, scale, and lead a global privacy program, managing stakeholder engagement across the companyRegulatory Strategy: Manage compliance strategy for emerging regulatory and technical issues related to cutting-edge products and new jurisdictions, including evolving cybersecurity, critical infrastructure, and AI regulations (e.g., NIS2, CRA, ISP-specific frameworks, global privacy laws)Policy Management: Design and drive internal company policies, external assets, and sales collateral addressing global privacy, data protection, and other regulatory frameworks (e.g., GDPR, EU Data Act, EU AI Act)Regulator Engagement: Respond to regulatory inquiries and investigations, and collaborate with outside counsel where specialized jurisdictional expertise is requiredProduct Counseling: Partner closely with product and engineering teams to provide end-to-end legal guidance on product and feature development, incorporating "privacy by design" and similar principlesCommercial Negotiations: Serve as our subject matter expert on privacy and other relevant regulations in complex customer, partner and vendor negotiations, including reviewing, drafting and negotiating agreements in collaboration with other Legal and business partnersTalent Support: Partner with our People team to advise on global employee data protection, workforce privacy initiatives, and talent-related privacy matters.