Senior Privacy Counsel

Abnormal AI

United States

On-site

USD 200,000 - 235,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Competitive salary
Benefits package

Job summary

Abnormal AI, a leading AI-native cybersecurity company, seeks a Senior Privacy Counsel to own significant portions of our global privacy program and oversee AI-enabled tooling that ties legal judgment to practical execution.

You will drive day-to-day privacy operations, partner with R&D for privacy by design in AI features, manage international data transfers, and guide incident response in a fast-growing, global environment.

Qualifications

  • J.D. from an accredited law school and US state bar admission.
  • CIPP/E and/or CIPP/US certifications.
  • 6-8+ years of privacy and data protection law experience.
  • Deep expertise in GDPR/UK GDPR and EU AI Act interactions for AI companies.
  • Experience advising technology companies (SaaS/cloud) incl. AI/ML products.
  • Proven ability to run a privacy program beyond advisory work in a fast-moving, global environment.

Responsibilities

  • Global privacy program execution across GDPR/UK GDPR, EU AI Act, NIS2, DORA, EU Data Act, and US state laws.
  • Drive AI governance execution with R&D, Security, and governance stakeholders.
  • Embed privacy into AI product design; oversee model data governance and data-use analyses.
  • Oversee privacy operations: DSARs, DPIAs, data mapping, retention, consent, audits.
  • Build AI-enabled privacy workflows with Legal Ops and engineering; maintain accuracy and human-review standards.
  • Monitor regulatory developments and translate guidance into actionable program actions.
  • Escalation point for vendor, subprocessor, and customer contracts (DPAs, SCCs).
  • Lead incident response from a privacy and legal perspective; assist DPO framework.

Skills

Privacy law experience
AI governance understanding
Regulatory horizon scanning
Product counseling with privacy
Stakeholder management

Education

J.D. from an accredited law school
CIPP/E certification
CIPP/US certification
6-8+ years privacy experience

Job description

About The Role

Abnormal AI is an AI-native cybersecurity company. We use behavioral AI to stop the attacks that get past everything else, and our products depend on processing data responsibly, at scale, across a growing set of global jurisdictions. We are looking for a Senior Privacy Counsel to own significant portions of our global privacy program - the legal judgment, the day-to-day operational execution and oversight, and the AI-enabled tooling that ties the two together.

About The Role

Abnormal AI is an AI-native cybersecurity company. We use behavioral AI to stop the attacks that get past everything else, and our products depend on processing data responsibly, at scale, across a growing set of global jurisdictions. We are looking for a Senior Privacy Counsel to own significant portions of our global privacy program - the legal judgment, the day-to-day operational execution and oversight, and the AI-enabled tooling that ties the two together.

Why Join Us
  • Help build and scale the privacy function at a category-defining, AI-native cybersecurity company.
  • Build, not just advise, with real license to design AI automation that changes how privacy work gets done.
  • Work at the intersection of privacy, AI governance, product counseling, and security, on problems that are genuinely new.
  • Competitive salary, benefits, and equity, and a clear path to grow the role toward greater program ownership as the program scales.
What You Will Do
  • Global privacy program execution. Support the design of, and drive implementation and continuous improvement of Abnormal’s global privacy program, partnering with applicable stakeholders on strategy, policies, standards, and controls, across GDPR/UK GDPR, EU AI Act, NIS2, DORA, EU Data Act, US state privacy laws, and other applicable international frameworks. Advise and execute on the international data transfer strategy (SCCs, UK IDTA, EU-US Data Privacy Framework, transfer impact assessments) as data flows and product footprint expand across jurisdictions.
  • AI governance execution. Drive the day-to-day execution of the AI governance program from the legal and privacy side, including EU AI Act classification and related obligations, seeing initiatives through to completion in partnership with R&D, Security, and AI governance stakeholders.
  • Privacy by Design for AI products and product counseling. Partner with the Privacy Manager and R&D to embed privacy into the design of new AI-driven features, including model data governance, secondary data-use analysis, and the privacy implications of behavioral AI. Set privacy diligence standards for AI/LLM vendors and model providers. Partner with the Director Legal, Product to provide ongoing product and privacy legal counseling to R&D for product and feature development.
  • Privacy operations. Partner with the Privacy Manager to help oversee the privacy operations program — DSARs and data-subject rights, Records of Processing Activities and data mapping, impact assessments (DPIA/PIA/TIA/LIA), retention, consent and cookie management, and audit support (SOC 2, ISO 27701/42001). Contribute to privacy governance forums, as appropriate.
  • Build and operate AI automation. Use AI to make the privacy program scale. Design, deploy, and improve AI-enabled privacy workflows (e.g., DPIA triage and drafting, subprocessor determination) with Legal Operations and engineering. A build-it role, not just a use-it one - specify, prototype, and iterate, holding tooling to a high accuracy and human-review bar.
  • Legal & Regulatory Horizon Scanning. Monitors emerging legal and regulatory developments, including privacy and AI regulation, in current and target expansion markets; flagging jurisdiction-specific requirements to the AGC, PPIP to inform market entry or launch decisions, and translates confirmed guidance into execution support for R&D (product and privacy considerations) and GTM (contracting posture, customer requirements).
  • Vendor, subprocessor, and customer contracts (escalation point). Serve as the privacy subject matter escalation point for the Commercial and Procurement teams on vendor, subprocessor, and customer agreements (DPAs, SCCs, subprocessor terms). Partner with the AGC, PPIP to set the privacy positions and playbook the teams work from.
  • Incident and breach response. Advise on and help lead the privacy and legal aspects of incident response, including AI incidents, breach assessment, notification decisions, and mitigation, working within the company's procedures and regulatory deadlines.
  • Data Protection Officer support & regulatory engagement. Support the DPO function as a day-to-day advisor, conducting first-line assessments, and support delegate-level assessments in line with the company's DPO governance framework. Serve as a privacy contact for supervisory-authority inquiries, customer privacy audits, and security questionnaires. Track developments across the privacy and adjacent-regulatory landscape (e.g., NIS2, DORA, and EU Data Act), and translate regulatory change into concrete program action decisions.
Must Haves
  • J.D. from an accredited law school and member in good standing of at least one U.S. state bar.
  • CIPP/E, CIPP/US certifications
  • 6-8+ years of relevant experience, with strong depth in privacy and data protection law and program execution.
  • Deep, current expertise in European privacy and digital regulation - GDPR/UK GDPR and working familiarity with NIS2, DORA, the EU AI Act, and the EU Data Act - and how they interact for an AI company.
  • Demonstrated experience operating in or advising technology companies, ideally in cybersecurity, SaaS, or cloud, including AI/ML products.
  • Meaningful experience contributing to and helping run a privacy program (beyond pure advisory work) in a fast-moving, global environment.
  • Experience providing product legal counseling alongside privacy.
  • Pragmatic judgment. Starts from the business objective and finds the compliant path, offering options and conditions rather than a reflexive "no," and earning trust as an enabler, not a gate.
  • Strong drafting and judgment on complex privacy agreements (DPAs, SCCs, subprocessor terms), and the ability to set positions, act as an escalation point for the teams who negotiate them, and flag novel issues for escalation.
  • Sound judgment applied to significant, novel, and ambiguous issues, with accountability for outcomes and escalating direction calls as appropriate, while developing subject-matter credibility internally.
  • The drive and assertiveness to own initiatives and drive them to completion with minimal oversight, and the ability to lead through influence, including to persuade diverse senior stakeholders.
  • Excellent communication and presentation skills, with the ability to explain complex privacy issues to business stakeholders.
  • Fluency with AI tooling and the ability to build and iterate on automation workflows - you have used AI to do real work and can specify, prototype, and refine it, holding it to a high accuracy and human-review standard.
Nice to Have
  • Experience supporting a DPO, including familiarity with independence and governance expectations.
  • Familiarity with privacy and data protection regimes beyond the EU/US - e.g., LGPD (Brazil), PIPEDA (Canada), APPI (Japan).
  • Experience supporting Works Councils and multi-jurisdiction employee/candidate privacy.
  • Experience with privacy tooling and with AI/LLM-based workflow automation.
  • Familiarity with security and privacy audit frameworks (SOC 2, ISO 27001/27701/42001).
  • CIPM, CIPT, AIGP certifications

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:

$199,800-$235,000 USD

AI and our hiring process

Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Privacy Counsel
Senior Privacy Counsel

Socket.dev • United States

On-site
USD 200,000 - 235,000
Senior Privacy Counsel
Senior Privacy Counsel

Abnormal • United States

On-site
USD 180,000 - 240,000
Senior Privacy Counsel
Senior Privacy Counsel

EngineersOfAI • Northern (KY)

Hybrid
USD 180,000 - 240,000
Staff Software Engineer, Security & Privacy
Staff Software Engineer, Security & Privacy

Menlo Ventures • United States

On-site
USD 210,000 - 303,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Socket.dev • United States

On-site
USD 153,000 - 220,000
bonus or incentive compensation
Equity
Comprehensive benefits
Senior Cloud Security Engineer (AWS)
Senior Cloud Security Engineer (AWS)

Menlo Ventures • United States

On-site
USD 153,000 - 220,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Abnormal AI • United States

On-site
USD 153,000 - 220,000
Bonus eligibility
Equity
Benefits package
Senior Customer Trust Analyst, EMEA
Senior Customer Trust Analyst, EMEA

Abnormal AI • United States

Remote
GBP 120,000 - 150,000
Senior Product Manager
Senior Product Manager

Abnormalsecurity • United States

On-site
USD 164,000 - 237,000
Comprehensive benefits package
Equity opportunities
Bonus compensation
Application Security Engineer II
Application Security Engineer II

Socket.dev • United States

On-site
USD 130,000 - 187,000