Sr Counsel, Data Governance in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr Counsel, Data Governance based in the United States.
As Sr Counsel, Data Governance, you’ll own the legal and regulatory strategy governing how data is collected, used, shared, retained, and applied to AI. Reporting to the Chief Compliance and Privacy Officer, you’ll serve as a key legal partner to senior leadership and teams across Sales, Technology, Product, Security, and other functions. This is a hands-on owner-operator role where you’ll translate complex privacy, data, and AI requirements into contracts, policies, controls, and practical operating processes. You’ll lead sophisticated negotiations around data rights while also running critical privacy and AI governance programs. The role offers significant exposure to high-impact business decisions and requires strong judgment in a highly regulated healthcare environment. You’ll build, implement, monitor, audit, and continuously improve governance frameworks rather than simply providing legal advice. This is an opportunity to shape responsible data and AI practices within a technology-driven organization focused on advancing healthcare.
- Lead negotiations involving data rights across client and partner agreements, including BAAs, DPAs, data use agreements, data sharing agreements, and other contracts governing data use, ownership, secondary use, AI training and application, system outputs, intellectual property, retention, deletion, de-identification, disclosure, and downstream use.
- Proactively review and renegotiate existing agreements when necessary to secure appropriate data rights and manage regulatory and contractual risk.
- Lead the day-to-day operation of the Privacy Program, including HIPAA and state privacy and consumer health data requirements, privacy notices and consents, consumer rights, privacy incidents, breach determinations, required notifications, regulatory inquiries, and ongoing compliance activities.
- Operate and administer the AI Governance Program, including interpreting federal and state AI requirements, maintaining governance frameworks and policies, supporting the AI Governance Committee, managing approval processes and AI inventories, conducting risk assessments, implementing responsible AI controls, maintaining governance records, and managing regulatory change.
- Develop and implement the legal and regulatory framework for data governance, covering data collection, use, sharing, secondary use and reuse, AI applications, retention, de-identification, deletion, disclosure, data residency, and cross-border transfers.
- Translate changing legal and regulatory requirements into practical policies, controls, procedures, implementation plans, and operational standards.
- Build and maintain data governance systems and controls, including data maps, records of processing, data classification and handling standards, contractual obligation repositories, retention and disposal requirements, and vendor and third-party privacy reviews.
- Partner with Product, Engineering, Security, AI, Commercial, User Support, and other teams to implement privacy, data, and AI requirements through product design, technical controls, notices, consents, and operational processes.
- Serve as a day-to-day escalation point for questions involving privacy, data rights, permissible data use, and AI governance, escalating material risks to senior compliance leadership.
- Lead privacy, data, and AI risk and incident management, including assessments, incident response, breach analysis, required notifications, corrective actions, and remediation through completion.
- Manage compliance monitoring and assurance activities, including audits, client audits, regulatory inquiries, investigations, certifications, attestations, and enterprise customer trust and assurance requests.
- Review representations concerning privacy, data, and AI practices and drive remediation when compliance gaps are identified.
- Develop and maintain policies, playbooks, training materials, and reporting for privacy, data governance, AI governance, responsible AI, and data rights.
- Provide training to Product, Engineering, Commercial, User Support, and other relevant teams, as well as executive-level reporting on program performance, risks, findings, and remediation.
Requirements:
- 8+ years of legal experience with substantial healthcare regulatory, privacy, and compliance experience within a HIPAA-regulated organization; healthcare experience is required.
- Significant experience negotiating complex data rights with sophisticated enterprise clients and partners, ideally including health plans, healthcare organizations, or other heavily regulated counterparties.
- Demonstrated ability to independently lead difficult negotiations involving data use, ownership, AI rights, secondary use, retention, deletion, de-identification, and related contractual restrictions.
- Experience operating healthcare privacy and compliance programs, including regulatory interpretation, risk assessments, incident and breach response, monitoring, auditing, corrective actions, and remediation.
- Strong compliance judgment and an owner-operator mindset, with the ability to move from legal interpretation to practical implementation and drive initiatives through resolution.
- Advanced AI fluency and automation capabilities, including extensive use of AI in substantive legal and compliance work and the ability to automate repeatable workflows.
- Comfort building and using AI agents or similar tools to improve speed, quality, consistency, and leverage within a lean team.
- Experience with AI governance, including emerging AI laws, risk assessments, approval workflows, AI inventories, responsible AI controls, and ongoing monitoring.
- Exceptional judgment, executive presence, and communication skills, with the ability to represent the organization in high-stakes negotiations and effectively challenge sophisticated internal and external stakeholders when necessary.
- Active license to practice law and membership in good standing with a U.S. state bar.
- Experience with international privacy and data protection requirements, including cross-border data transfers, is a plus.
- Privacy or AI governance certifications such as CIPP/US, CIPM, or AIGP are advantageous.
- Experience building privacy or AI governance programs within a growth-stage or high-growth company is a plus.
- Experience managing client trust programs, security questionnaires, certifications, attestations, or enterprise customer assurance programs is beneficial.
Benefits:
- Base salary of $204,000–$226,000 USD.
- Equity and comprehensive benefits may be provided in addition to base salary.
- Remote work within the United States.
- Positive, diverse, and supportive work environment.
- Collaborative culture that values creativity, courage, and diverse perspectives.
- Opportunity to work directly on privacy, data governance, and responsible AI initiatives within a healthcare technology environment.
- Significant exposure to senior executives and high-impact legal, regulatory, and business decisions.
- Opportunity to build and operate governance programs in a technology-driven organization.
- Candidates must be legally authorized to work in the United States.