Key technologies and capabilities for this role
Common questions about this position
The role requires 6+ years of privacy and/or commercial privacy experience, ideally a mix of global law firm and in-house work.
You will own DPA and Security Addendum negotiations, run core privacy tasks like DSARs, DPIAs/PIAs, cookie compliance, and data mapping, and track evolving frameworks like EU AI Act and GDPR.
Candidates need a JD from an accredited law school and an active bar in at least one U.S. state, or eligibility for in-house counsel registration.
This is a small and rapidly growing Legal org at an early-stage company where you'll collaborate cross-functionally with Sales, Security, Procurement, Product, HR, and Ops, rolling up your sleeves for practical problem-solving.
A strong candidate has in-depth privacy expertise with hands-on experience in DSAR processes, DPIAs/PIAs, global privacy notices, cookie compliance, familiarity with U.S. state privacy laws and EU frameworks, plus interest in open-source licensing.
Supply chain risk management and audits
Chainguard specializes in managing risks in supply chains, particularly for businesses that rely on software. They conduct audits to identify risks and provide detailed reports with recommendations for improvement. Their unique offering includes a curated base container image distro, which helps businesses transition to secure software environments. Chainguard also provides supply chain observability services, allowing companies to track their software's origins and dependencies.