Back to Jobs
Horizon3 ai
Legal & HR Just now

Product & Privacy Counsel

Horizon3 ai
United StatesUnited States
Full-time
$139,000 - $163,000 annually
Mid-Level

Job Description

Key Skills Required

Master these to land this role

SOC 2Privacy-by-design principlesData Processing AgreementsCCPA/CPRAGDPR

Want to know if you're a match for this job?

Calculate My Match Score

We’re looking for a practical, business-minded Product & Privacy Counsel to join our Legal team and serve as a key legal partner across Horizon3.

This role will have a balanced focus across product counseling and privacy, with meaningful ownership in both areas. You will partner closely with Product and Engineering throughout the product lifecycle, advising on new products, features, technologies, and regulatory requirements, while also helping operate and scale Horizon3’s global privacy program.

You will work cross-functionally with Product, Engineering, Security, Compliance, GTM, and Operations to translate complex legal and regulatory requirements into practical, scalable solutions that protect the business without creating unnecessary friction.

This role is ideal for an attorney who enjoys working directly with technical and business teams, can independently own matters, and is comfortable making practical, risk-based recommendations in a fast-moving cybersecurity environment.

Product & Technology Counseling

  • Serve as a day-to-day legal partner to Product and Engineering on new products, features, integrations, and product changes.

  • Provide legal guidance throughout the product lifecycle, from early design and development through launch and ongoing operation.

  • Identify and advise on legal and regulatory considerations involving product functionality, data use, telemetry, logging, APIs, integrations, and emerging technologies.

  • Conduct legal reviews of new products and features and develop practical approaches to mitigate identified risks.

  • Advise on product terms, disclosures, customer-facing documentation, and other legal requirements associated with product launches.

  • Partner with Product, Engineering, Security, and Compliance to translate legal requirements into practical and scalable product controls.

  • Advise on the development, deployment, and use of AI and other emerging technologies, including applicable AI and technology regulation.

  • Develop scalable playbooks, guidance, and processes that help teams identify and address legal requirements earlier in the product development lifecycle.

Privacy & Data Protection

  • Help operate and scale Horizon3’s global privacy program.

  • Advise on global privacy and data protection requirements, including GDPR, UK GDPR, CCPA/CPRA, U.S. state privacy laws, and other emerging privacy regulations.

  • Embed privacy-by-design principles into products, systems, and business processes, including conducting and maintaining PIAs, DPIAs, and related assessments.

  • Advise on controller, processor, and subprocessor obligations and new or changing data processing activities.

  • Manage and advise on cross-border data transfer requirements, including Standard Contractual Clauses (SCCs), transfer impact assessments, the Data Privacy Framework, and other applicable transfer mechanisms.

  • Advise on data subject rights, retention and deletion, subprocessors, privacy notices, and related privacy operations.

  • Draft, review, negotiate, and maintain Data Processing Agreements (DPAs) and other privacy and data protection terms.

  • Maintain and enhance privacy policies, notices, internal guidance, and customer-facing privacy resources.

  • Partner with Security and Compliance on privacy incidents, regulatory requirements, audits, and customer diligence.

  • Monitor developments in global privacy law and translate changes into practical requirements for the business.

Cross-Functional Enablement

  • Partner with Legal, Product, Engineering, Security, Compliance, GTM, and Operations to resolve product and privacy matters efficiently.

  • Support enterprise customer negotiations and diligence involving product, privacy, data protection, and emerging technology issues.

  • Develop templates, playbooks, guidance, and self-service resources that allow the business to operate efficiently while maintaining appropriate legal guardrails.

  • Provide clear, practical advice that balances legal and regulatory requirements with product objectives, customer expectations, and business priorities.

Success in this role means becoming a trusted partner across both Product and Privacy—helping Product and Engineering identify and address legal requirements early, independently owning core elements of Horizon3.ai’s global privacy program, and providing practical solutions that allow the company to innovate and scale responsibly.

What You’ll Bring

Required

  • A J.D. from an accredited law school and active membership in good standing with at least one U.S. state bar.

  • 4+ years of relevant legal experience, with meaningful experience in both product/technology counseling and privacy or data protection.

  • Experience advising SaaS, cybersecurity, software, or other technology businesses.

  • Strong working knowledge of:

    • GDPR and UK GDPR

    • CCPA/CPRA and U.S. state privacy laws

    • DPAs, SCCs, and cross-border data transfer mechanisms

    • Privacy-by-design principles and product privacy reviews

  • Experience partnering directly with Product and Engineering teams.

  • Ability to understand technical products, data flows, software architecture, APIs, and cloud-based services sufficiently to identify and advise on legal and privacy risks.

  • Strong legal judgment and the ability to provide practical, risk-based recommendations.

  • Strong drafting, written and verbal communication, and project-management skills.

  • Proven ability to independently manage multiple priorities in a fast-paced, high-growth environment.

Preferred

  • In-house experience at a SaaS, cybersecurity, AI, cloud, or other high-growth technology company.

  • Experience advising on AI, machine learning, or emerging technology regulation.

  • Familiarity with the EU AI Act, EU Data Act, or cybersecurity regulatory frameworks.

  • Experience conducting PIAs, DPIAs, TIAs, or similar privacy and data protection assessments.

  • Familiarity with SOC 2, ISO 27001, or similar security and compliance frameworks.

  • Experience supporting enterprise customer privacy and technology negotiations.

  • CIPP/US, CIPP/E, CIPM, or similar privacy certification.

How would you rate this job post?

See what other professionals think about this role.

banner

Horizon3.ai is a leading cybersecurity firm that revolutionized the industry with NodeZero, the world's first fully autonomous penetration testing platform. Founded in 2019 by former US Special Operations and national security experts, the company shifts the paradigm from reactive defense to proactive offense. Under the hood, NodeZero acts as an automated ethical hacker, continuously discovering, exploiting, and providing remediation paths for critical vulnerabilities across on-premise, cloud, and hybrid environments. Their primary target audience includes enterprise CISOs, IT directors, and managed service providers (MSPs) who need to rigorously validate their security posture without the massive cost and infrequent cadence of traditional human pentesting. What sets Horizon3.ai apart in the crowded InfoSec market is its ability to safely execute real-world attack vectors in production environments at scale, allowing security teams to fix exploitable weaknesses before threat actors can weaponize them.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Product & Privacy Counsel at Horizon3 ai | HireSkys