gc-ai - Senior Privacy & Security Commercial Counsel
Requirements
• JD and active bar membership in at least one US jurisdiction. • 5-10 years of privacy and security legal experience, with a meaningful portion in-house at a technology or SaaS company. • Deep working knowledge of GDPR, CCPA/CPRA, and the broader US and international data protection regulatory landscape. • Experience supporting sales processes at a B2B SaaS company, including security reviews, procurement questionnaires, and customer-facing calls. • Experience negotiating DPAs and data protection terms in a B2B SaaS context, including GDPR Article 28 processor obligations, standard contractual clauses, and cross-border transfer mechanisms. • Demonstrated ability to work independently, prioritize competing demands, and deliver under pressure. • Comfort working at startup pace with ambiguity, shifting priorities, and limited precedent. • CIPP/US, CIPP/E, or similar privacy certification. • Experience with AI governance frameworks (EU AI Act, NIST AI RMF) or ISO 42001. • Hands-on experience supporting security compliance programs (SOC 2, ISO 27001, or similar), including policy drafting, audit support, and gap analysis. • Background in cybersecurity incident response or breach management. • Experience at a high-growth startup or scale-up company (Series B through pre-IPO). • Prior big law firm experience in privacy, data protection, or technology transactions • We’re building something new in a once-in-a-generation shift in technology and the legal industry, so we move at a relentless pace. We expect urgency, ownership, and good judgment even when things aren’t perfectly clear. If you need structure and consensus to do your best work, this isn’t the right place for you. If you thrive in ambiguity and growth, work with intensity, and want real responsibility, keep reading. We’re excited to meet you. • How We Work Together • GC AI is a distributed company with team members across North America, and soon Europe. We believe that because our business is AI, human connection matters more, not less. We invest in bringing people together through our hub model: regular coworking sessions, customer dinners, team and company offsites. If you’re in a location without an office, expect up to 10% travel (and more for customer-facing roles). • Team members in the San Francisco Bay Area and Provo, UT (within 50 miles of the office) work together on Tuesdays, Wednesdays, and Thursdays. As we grow, we plan to establish permanent offices in more hub cities, and we will look to our team members to help build that in-person culture. We currently hire across the United States and Canada. • Equal Opportunity Employment
Responsibilities
• Own GC AI's privacy and security legal posture across every regulatory framework that touches the business. • Serve as the internal subject matter expert that product, engineering, sales, and the commercial legal team rely on for privacy and security guidance. • Directly enable enterprise deals by handling the DPA and security addendum negotiations • that sophisticated customers require. • Build and maintain the privacy and security playbook positions that scale with GC AI's growth. • Keep GC AI ahead of the regulatory curve on AI governance, international privacy • frameworks, and emerging US state privacy laws. • Own the legal framework for GC AI's SOC 2, ISO 27001, and ISO 42001 compliance • programs, partnering with the GRC and Compliance team on operational execution. • Advise product and engineering on privacy-by-design, data protection impact assessments, and AI governance requirements. • Own GC AI's regulatory compliance posture for GDPR, CCPA/CPRA, EU AI Act, and emerging US state privacy laws. • Serve as the escalation point for complex DPA and security addendum negotiations, working alongside the commercial legal team. • Directly handle DPA and security addendum redlines for strategic and high-value customer deals. • Maintain and evolve GC AI's standard DPA, security addendum, and Information Security Addendum templates and playbook positions. • Support enterprise sales by joining security calls with sophisticated prospects and responding to detailed security and privacy inquiries. • Assist with managing relationships with external auditors and compliance vendors (e.g., SOC 2 auditors, penetration testing firms, privacy tooling providers). • Advise on incident response legal obligations, breach notification requirements, and customer communications. • Own the legal review of the Trust Center, security marketing claims, and subprocessor disclosures. • Provide guidance on cross-border data transfers, international privacy frameworks, and jurisdiction-specific data protection requirements. • Assist with other compliance projects (including entity compliance management) • Take on additional projects and tasks as needed in response to the evolving needs of a fast- growing startup.
Benefits
• Final compensation will vary based on leveling, market conditions, geographic location, and candidate qualifications, including relevant knowledge, skills, and experience assessed during the interview process. • Upload your resume here to autofill key application fields. • Drop your resume here! • Parsing your resume. Autofilling key fields... • or drag and drop here • What motivated you to apply to GC AI? • GC AI Privacy Policy • Another Gender Identity • I prefer not to answer • Asian or Asian American • Black or African American • Hispanic or Latine • Indigenous or Native American • Native Hawaiian or Other Pacific Islander • Recruiting Privacy Policy
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT