Provide day-to-day legal advice and counsel to internal clients (e.g., Compliance, Legal, Operations, and Digital Technology)
Serve as subject matter expert on US data privacy and data security laws and regulations, including federal and state privacy and consumer protection laws
Provide legal advice on data privacy, data governance, and data security issues, including advising on data privacy compliance, privacy impact assessments, and privacy training, anticipating evolving legal, regulatory, and enforcement trends, and supporting timely updates to internal privacy compliance programs and procedures
Provide proactive legal guidance and training on data privacy, technology, and data governance, including emerging AI and machine learning use cases and associated regulatory considerations
Analyze new data privacy, data governance, and data security related laws and regulations and advising proactively on regulatory and contractual implications
Monitor the evolution of cyber best practices and ensure continuous calibration of cyber compliance framework
Support government relations team on matters related to data privacy, data governance, and data security
Assist in providing legal coverage for regulatory exams
Provide legal advice and support on data security incident issues, including data and response/preparedness, data breach notification laws, third-party breach response, client/regulatory inquiries, and client-facing documentation
Review, analyze, draft and negotiate vendor contracts including but not limited to data processing agreements and provisions related to data privacy, data governance, and data security, among others
Oversee and provide periodic advice on information governance issues, such as litigation holds, document retention, and destruction policies
Requirements
Juris Doctorate from accredited university
Minimum 7 years of professional experience as a practicing attorney with a focus in privacy and information management, including experience in-house, at a regulatory agency or law firm, or a combination
Member in good standing with the State Bar
Demonstrated, significant legal experience advising on relevant federal and state data privacy and data security laws (e.g., GLBA, HIPAA, NYDFS Cybersecurity Regulation), preferably at an insurance company or in another highly regulated industry
Strong understanding of and familiarity with current legal and regulatory requirements relating to data privacy and data security, and related legal and regulatory environments, especially those applicable to insurance companies/financial institutions
Significant experience as the lead negotiating and drafting contracts for technology products, including products with AI features
Strong analytical, problem-solving and legal research skills
Strong business judgment, strategic thinking, and client counseling skills
Proven ability to independently identify issues, analyze problems, and provide viable solutions
Excellent verbal, written, interpersonal, organizational and negotiation skills
Ability to communicate and interact effectively with all levels of personnel and management, including senior executives
Ability to follow up on assignments in a timely manner, exercise good business judgment, and work accurately under pressure
CIPP certification preferred.
Tech Stack
Cyber Security
Benefits
Healthcare benefits include medical, dental, vision, and prescription drug coverage
Retirement benefits include GE Aerospace Retirement Savings Plan, a 401(k) savings plan with company matching contributions and company retirement contributions
Access to Fidelity resources and planning consultants