Skip to content

Open nowPosted 7 days ago

Assistant General Counsel - Data Regulation, Privacy, Security & Governance

cooley9 open roles

Where
San Francisco
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAssistant General Counsel - Data Regulation, Privacy, Security & Governancecooley · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on cooley's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.4%1 day
  2. 3.5%3 days
  3. 7.7%7 days
  4. 13.4%14 days
  5. 34.5%30 days
This job: posted 7 days ago

The posting

Assistant General Counsel - Data Regulation, Privacy, Security & Governance

Cooley is seeking an Assistant General Counsel to join the General Counsel's Office.

About Cooley: Cooley is a global law firm with an expansive practice and more than 3,000 employees and partners worldwide. We value and celebrate diverse perspectives and strive to create a workplace where every individual can thrive. At the core of Cooley’s success is the exceptional talent and unwavering spirit of our people. We embrace individuality while fostering a ‘one-firm’ culture where collaboration and creativity thrive. Our people are the foundation of our success and the driving force behind everything we do.

Hybrid Schedule Philosophy: As part of the Cooley culture, we recognize and appreciate the value of being together, in person, to build comradery with others in the office and to be a contributing member of the Cooley office. However, we also appreciate the benefits and flexibility that come from remote working. As such, the default assumption for employees and partners is a hybrid schedule: some in-office presence and some work from home days.

Position summary: Guided by department objectives and priorities, the Assistant General Counsel - Data Regulation, Privacy, Security and Governance develops, leads, and maintains the firm’s legal strategy for data regulation, privacy, data security, data governance and data protection. The Assistant General Counsel will ensure appropriate use of data use and sharing; export controls, vendor and client data processing arrangements; and emerging regulatory frameworks and compliance with privacy regulations.

The role will prepare, implement, review, and update data-related and privacy-related policies and procedures; advise on compliance with U.S. state and federal privacy laws and global regimes (including GDPR and CCPA/CPRA); guide readiness for evolving data rules such as those governing bulk data, export controls and similar regulated data flows; and collaborate closely with the Office of the General Counsel, including the Client Engagement Counsel, the firm’s Data Protection Officer, Technology, Innovation and other stakeholders. The Assistant General Counsel demonstrates strong business acumen, applied legal expertise, and global privacy fluency to support time-sensitive outcomes that align with firm strategy and risk posture. Specific duties include, but are not limited to, the following:

Position responsibilities:

  • Advise the firm, in coordination with relevant stakeholders from Security, Technology, Innovation and other lawyers in the Office of the General Counsel, on data regulation and governance issues spanning privacy, data security, records retention and disposition as they relate to compliance with data laws, data inventories and maps, cross-border transfers, data subject requests, and lawful data use across firm operations and client interactions.
  • Work closely with Chief Security & Technology Officer and Chief Innovation Officer on evaluating technology vendor data privacy.
  • Prepare and update firm privacy and data governance policies and procedures to comply with applicable regulations, including GDPR and U.S. state privacy laws such as CCPA/CPRA, and maintain public-facing notices that reflect current legal and firm practices.
  • Provide privacy input on business projects and initiatives as requested by the firm’s Data Protection Officer and/or the Office of the General Counsel.
  • Assist with continuing improvements to a sustainable governance framework for client and firm data, including policy development for client file handling and retention, oversight of records and information management as they relate to compliance with applicable data laws and regulations, and integration with information security and data governance functions.
  • Support incident preparedness and response for privacy and data security events, including investigation, containment, remediation, notifications where required, and post-incident improvement in collaboration with the Chief Security & Technology Officer and firm leadership, as needed.
  • Act as cyber security subject matter expert in close collaboration with cyber security tech team.
  • Assist with drafting, reviewing, and negotiating data-related terms in client and vendor contracts, including data processing and transfer agreements, privacy-related clauses, and security addenda, applying advanced knowledge of global privacy regulations and contracting practices to manage risk and drive successful outcomes. Ensure key contracts, firm procurement initiatives and sourcing strategies are aligned with the overall priorities of the firm’s legal function, paying special attention to privacy/data security and risk management practices as they develop.
  • Perform or oversee privacy and data protection risk assessments, including PRAs and DPIAs where required, and coordinate compliance monitoring and audits of higher-risk vendors or third parties that process personal data on the firm’s behalf.
  • Monitor, assess, and advise on evolving laws, regulations, standards, and enforcement trends—including developments in federal and state privacy, cross-border transfers, data governance, and other emerging data rules—and recommend appropriate actions for the firm.
  • Develop and deliver training and communications to attorneys, paralegals and business professionals regarding privacy, data governance, records, and related obligations to promote privacy by design/default and a culture of compliance.
  • Collaborate with department representatives and firm leaders to align key procurement initiatives, sourcing strategies, and data-intensive projects with legal, privacy, data security, and risk management priorities, and prioritize deal and project support accordingly.
  • Identify and escalate potential risks in business transactions and operational processes, and document negotiation positions and areas of potential conflict (including liability, indemnities, assignments, payment terms, and other key provisions) to minimize disputes and advance firm objectives.
  • All other duties as assigned or required.

Skills and experience:

Required:

· After orientation at Cooley LLP, exhibit proficiency in the Microsoft Office suite, iManage and other firm applications

· Ability to work extended and/or weekend hours, as required

· Ability to travel, as required

· JD from an ABA accredited law school

· Active member in good standing of the jurisdiction in which the attorney is resident and the jurisdiction of the Cooley office to which the attorney is assigned

· Substantial experience advising on data protection, privacy, and governance, including direct experience with U.S. export control regulations and data privacy/protection laws in the U.S., Europe, and Asia

· 6+ years of relevant experience, preferably as a practicing attorney

· Advanced knowledge of privacy and data governance frameworks; experience drafting and operationalizing privacy and data policies

· Depth in technology and commercial contracting, particularly with data processing/transfer agreements and privacy/security provisions

· Advanced knowledge of GDPR

Preferred:

  • Experience with risk assessments, compliance monitoring, and vendor oversight in privacy, as well as incident response and regulatory engagement
  • Expertise in cybersecurity
  • Certifications such as CIPP/US, CIPP/E, or CIPT

Competencies:

  • Excellent communication and organizational skills; strong sense of accountability
  • Ability to analyze needs and determine priorities based on business objectives in a fast-paced environment
  • Sound professional judgment and ability to translate complex legal requirements plainly for non-legal audiences
  • Effective collaboration across global, cross-functional stakeholders

Cooley offers a competitive compensation and excellent benefits package and is committed to fair and equitable employment practices. EOE.

The expected annual pay range for this position with a full-time schedule is $240,000 to $300,000. Please note that final offer amount will be dependent on geographic location, applicable experience and skillset of the candidate.

We offer a full range of elective benefits including medical, health savings account (with applicable medical plan), dental, vision, health and/or dependent care flexible spending accounts, pre-tax commuter benefits, life insurance, AD&D, long-term care coverage, backup care for children and/or adults and other parental support benefits. In addition to elective benefit options, benefited employees receive firm-paid life insurance, AD&D, LTD, short term medical benefits as well as 20 days of vacation, 10 days of sick and 10 paid holidays each year. We provide generous parental leave and fertility benefits. New employees will attend a detailed benefit orientation to learn more about our many benefits and resources.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against cooley's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on cooley's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    cooley's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.