GC AI

GC AI

Senior Privacy & Security Counsel

Remote - United States · Senior

Sponsorship not specifiedDetected 20 days ago
CybersecurityPenetration TestingIncident ResponseComplianceSalesValuationProcurementCommunication

About the role

  • You will be the go-to lawyer for everything from GDPR and CCPA compliance to SOC 2 and ISO certification programs, DPA negotiations, and AI governance.
  • Serve as the internal subject matter expert that product, engineering, sales, and the commercial legal team rely on for privacy and security guidance.
  • Directly enable enterprise deals by handling the DPA and security addendum negotiations

Responsibilities

  • Own the legal framework for GC AI's SOC 2, ISO 27001, and ISO 42001 compliance
  • Advise product and engineering on privacy-by-design, data protection impact assessments, and AI governance requirements.
  • Own GC AI's regulatory compliance posture for GDPR, CCPA/CPRA, EU AI Act, and emerging US state privacy laws.
  • Maintain and evolve GC AI's standard DPA, security addendum, and Information Security Addendum templates and playbook positions.
  • Support enterprise sales by joining security calls with sophisticated prospects and responding to detailed security and privacy inquiries.
  • Own the legal review of the Trust Center, security marketing claims, and subprocessor disclosures.

Requirements

  • 5-10 years of privacy and security legal experience, with a meaningful portion in-house at a technology or SaaS company.
  • Deep working knowledge of GDPR, CCPA/CPRA, and the broader US and international data protection regulatory landscape.
  • Experience supporting sales processes at a B2B SaaS company, including security reviews, procurement questionnaires, and customer-facing calls.
  • Experience negotiating DPAs and data protection terms in a B2B SaaS context, including GDPR Article 28 processor obligations, standard contractual clauses, and cross-border transfer mechanisms.
  • Comfort working at startup pace with ambiguity, shifting priorities, and limited precedent.

Nice to have

  • CIPP/US, CIPP/E, or similar privacy certification.
  • Experience with AI governance frameworks (EU AI Act, NIST AI RMF) or ISO 42001.
  • Background in cybersecurity incident response or breach management.
  • Experience at a high-growth startup or scale-up company (Series B through pre-IPO).
  • Prior big law firm experience in privacy, data protection, or technology transactions
  • We expect urgency, ownership, and good judgment even when things aren't perfectly clear.
  • If you need structure and consensus to do your best work, this isn't the right place for you.
  • If you thrive in ambiguity and growth, work with intensity, and want real responsibility, keep reading.

Skills

  • frameworks, and emerging US state privacy laws.

Company info

  • At a company that builds legal AI, you will also be shaping how privacy and security counsel work gets done in the future.
  • that sophisticated customers require.

Equal opportunity

  • GC AI is an equal opportunity employer that supports workplace diversity and does not discriminate on the basis of race, color, religion, gender identity/expression, national origin, age, military service eligibility, veteran status, sexual orientation, marital status, physical or mental disability, or any other protected class. GC AI is committed to working with and providing reasonable accommodation to applicants with physical and mental disabilities. #LI-GCAI
  • To protect yourself against phishing and recruitment fraud, please note that GC AI only accepts job applications through our official careers page at https://gc.ai/careers and through sponsored jobs on LinkedIn. All legitimate communication from our team regarding job opportunities will come from a GC AI team member with a @gc.ai http://gc.ai or @getgc.ai http://getgc.ai email address.
  • GC AI will never:
  • Refer you to external websites to apply

This listing is sourced directly from GC AI's careers page and normalized into a canonical job model.