远程工作雷达

高级隐私顾问

Senior Privacy Counsel

职能支持限定地区(需当地身份)
公司Abnormal
薪资未公开
工作地点Remote - USA
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间2026-08-13
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - USA 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职位描述

Abnormal AI 是一家以人工智能为核心的网络安全公司。我们利用行为人工智能来阻止其他所有防护措施都无法拦截的攻击,我们的产品依赖于在不断扩展的全球司法管辖区中负责任地大规模处理数据。我们正在寻找一位高级隐私顾问,负责我们全球隐私计划的重要部分——法律判断、日常运营执行和监督,以及将两者联系在一起的人工智能驱动工具。

这是一个高级隐私职位,向 AGC、PPIP 汇报,并在其指导下开展工作。您将就如何在人工智能原生平台上构建隐私功能向产品和工程团队提供建议,从法律和隐私角度支持人工智能治理,与产品法律总监一起提供产品隐私法律咨询,并与隐私经理合作,后者负责大部分日常运营执行工作,共同管理日常隐私计划(DSAR、评估、ROPAs、通知、审计)。您将帮助构建和运营人工智能自动化系统,与法律运营和其他内部团队合作,使该计划得以扩展,并通过商业法律与客户进行沟通,发挥隐私方面的专业声音。

我们希望找到一位具备专业知识、动力和主动性的人才,能够在较少监督的情况下主导项目并将其完成——既擅长撰写合法基础分析,也能推动实现自动化流程。

为什么加入我们

  • 在一家定义行业标准的、以人工智能为核心的网络安全公司,帮助建立和扩展隐私职能。
  • 不仅是提供建议,而是实际参与建设,拥有真正的权限去设计改变隐私工作方式的人工智能自动化系统。
  • 在隐私、人工智能治理、产品咨询和安全的交汇点上,解决真正新颖的问题。
  • 具有竞争力的薪资、福利和股权,以及随着计划扩展而逐步扩大职责范围的清晰成长路径。

您将负责

  • 全球隐私计划的执行。支持设计并推动实施和持续改进 Abnormal 的全球隐私计划,与相关利益相关者合作制定策略、政策、标准和控制措施,涵盖 GDPR/UK GDPR、欧盟人工智能法案、NIS2、DORA、欧盟数据法案、美国各州隐私法以及其他适用的国际框架。在数据流动和产品足迹扩展至不同司法管辖区时,就国际数据传输策略(SCCs、英国 IDTA、欧美数据隐私框架、传输影响评估)提供建议并加以执行。
  • 人工智能治理执行。
查看英文原文

About the Role

Abnormal AI is an AI-native cybersecurity company. We use behavioral AI to stop the attacks that get past everything else, and our products depend on processing data responsibly, at scale, across a growing set of global jurisdictions. We are looking for a Senior Privacy Counsel to own significant portions of our global privacy program — the legal judgment, the day-to-day operational execution and oversight, and the AI-enabled tooling that ties the two together.

This is a senior privacy role, reporting to and operating under the direction of the AGC, PPIP. You will advise product and engineering on building privacy into an AI-native platform, support AI governance from the legal and privacy side, provide product-privacy legal counseling alongside the Director, Legal (Product), and partner with the Privacy Manager, who handles much of the operational execution, to run the day-to-day privacy program (DSARs, assessments, ROPA, notices, audits). You will help build and operate the AI automation, working with Legal Ops and other internal teams, that makes the program scale, and serve as a privacy voice with customers via commercial legal.

We want someone with the expertise, drive, and assertiveness to own initiatives and drive them to completion with limited oversight — as comfortable writing a lawful-basis analysis as they are shipping a workflow that automates it.

Why Join Us

  • Help build and scale the privacy function at a category-defining, AI-native cybersecurity company.
  • Build, not just advise, with real license to design AI automation that changes how privacy work gets done.
  • Work at the intersection of privacy, AI governance, product counseling, and security, on problems that are genuinely new.
  • Competitive salary, benefits, and equity, and a clear path to grow the role toward greater program ownership as the program scales.

What You Will Do

  • Global privacy program execution. Support the design of, and drive implementation and continuous improvement of Abnormal's global privacy program, partnering with applicable stakeholders on strategy, policies, standards, and controls, across GDPR/UK GDPR, EU AI Act, NIS2, DORA, EU Data Act, US state privacy laws, and other applicable international frameworks. Advise and execute on the international data transfer strategy (SCCs, UK IDTA, EU–US Data Privacy Framework, transfer impact assessments) as data flows and product footprint expand across jurisdictions.
  • AI governance execution. Drive the day-to-day execution of the AI governance program from the legal and privacy side, including EU AI Act classification and related obligations, seeing initiatives through to completion in partnership with R&D, Security, and AI governance stakeholders.
  • Privacy by Design for AI products and product counseling. Partner with the Privacy Manager and R&D to embed privacy into the design of new AI-driven features, including model data governance, secondary data-use analysis, and the privacy implications of behavioral AI. Set privacy diligence standards for AI/LLM vendors and model providers. Partner with the Director Legal, Product to provide ongoing product and privacy legal counseling to R&D for product and feature development.
  • Privacy operations. Partner with the Privacy Manager to help oversee the privacy operations program — DSARs and data-subject rights, Records of Processing Activities and data mapping, impact assessments (DPIA/PIA/TIA/LIA), retention, consent and cookie management, and audit support (SOC 2, ISO 27701/42001). Contribute to privacy governance forums, as appropriate.
  • Build and operate AI automation. Use AI to make the privacy program scale. Design, deploy, and improve AI-enabled privacy workflows (e.g., DPIA triage and drafting, subprocessor determination) with Legal Operations and engineering. A build-it role, not just a use-it one — specify, prototype, and iterate, holding tooling to a high accuracy and human-review bar.
  • Legal & Regulatory Horizon Scanning. Monitors emerging legal and regulatory developments, including privacy and AI regulation, in current and target expansion markets; flagging jurisdiction-specific requirements to the AGC, PPIP to inform market entry or launch decisions, and translates confirmed guidance into execution support for R&D (product and privacy considerations) and GTM (contracting posture, customer requirements).
  • Vendor, subprocessor, and customer contracts (escalation point). Serve as the privacy subject matter escalation point for the Commercial and Procurement teams on vendor, subprocessor, and customer agreements (DPAs, SCCs, subprocessor terms). Partner with the AGC, PPIP to set the privacy positions and playbook the teams work from.
  • Incident and breach response. Advise on and help lead the privacy and legal aspects of incident response, including AI incidents, breach assessment, notification decisions, and mitigation, working within the company's procedures and regulatory deadlines.
  • Data Protection Officer support & regulatory engagement. Support the DPO function as a day-to-day advisor, conducting first-line assessments, and support delegate-level assessments in line with the company's DPO governance framework. Serve as a privacy contact for supervisory-authority inquiries, customer privacy audits, and security questionnaires. Track developments across the privacy and adjacent-regulatory landscape (e.g., NIS2, DORA, and EU Data Act), and translate regulatory change into concrete program action decisions.

Must Haves

  • J.D. from an accredited law school and member in good standing of at least one U.S. state bar.
  • CIPP/E, CIPP/US certifications
  • 6-8+ years of relevant experience, with strong depth in privacy and data protection law and program execution.
  • Deep, current expertise in European privacy and digital regulation — GDPR/UK GDPR and working familiarity with NIS2, DORA, the EU AI Act, and the EU Data Act — and how they interact for an AI company.
  • Demonstrated experience operating in or advising technology companies, ideally in cybersecurity, SaaS, or cloud, including AI/ML products.
  • Meaningful experience contributing to and helping run a privacy program (beyond pure advisory work) in a fast-moving, global environment.
  • Experience providing product legal counseling alongside privacy.
  • Pragmatic judgment. Starts from the business objective and finds the compliant path, offering options and conditions rather than a reflexive "no," and earning trust as an enabler, not a gate.
  • Strong drafting and judgment on complex privacy agreements (DPAs, SCCs, subprocessor terms), and the ability to set positions, act as an escalation point for the teams who negotiate them, and flag novel issues for escalation.
  • Sound judgment applied to significant, novel, and ambiguous issues, with accountability for outcomes and escalating direction calls as appropriate, while developing subject-matter credibility internally.
  • The drive and assertiveness to own initiatives and drive them to completion with minimal oversight, and the ability to lead through influence, including to persuade diverse senior stakeholders.
  • Excellent communication and presentation skills, with the ability to explain complex privacy issues to business stakeholders.
  • Fluency with AI tooling and the ability to build and iterate on automation workflows — you have used AI to do real work and can specify, prototype, and refine it, holding it to a high accuracy and human-review standard.

Nice to Have

  • Experience supporting a DPO, including familiarity with independence and governance expectations.
  • Familiarity with privacy and data protection regimes beyond the EU/US — e.g., LGPD (Brazil), PIPEDA (Canada), APPI (Japan).
  • Experience supporting Works Councils and multi-jurisdiction employee/candidate privacy.
  • Experience with privacy tooling and with AI/LLM-based workflow automation.
  • Familiarity with security and privacy audit frameworks (SOC 2, ISO 27001/27701/42001).
  • CIPM, CIPT, AIGP certifications

#LI-ME1
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:
$199,800—$235,000 USD

A note on AI in our process: 
Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI's policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位