Attorney
Day Pitney LLP · Connecticut, United States · 1 mo ago
HybridFull-time
About the role
The ideal candidate will have demonstrated experience advising clients on privacy compliance, cybersecurity incident response, data governance, and related regulatory matters. Qualified candidates should have experience with the following:
- Privacy compliance and advisory matters, including U.S. state privacy laws, GDPR and global privacy issues, and federal privacy laws, particularly GLBA and HIPAA
- Drafting, reviewing, and negotiating privacy policies, data processing agreements, and related privacy documentation
- Advising clients on the use of cookies and other tracking/data collection technologies
- Cybersecurity and incident response matters, including breach response, ransomware/extortion events, and regulator and state attorney general engagement
- Supporting time-sensitive cybersecurity incident response matters, including matters that may require availability outside of regular business hours
Requirements
- 3–6 years of data privacy and cybersecurity experience
- Excellent drafting, written, and verbal communication skills
- Strong legal research, analytical, and technical skills
- Proven ability to manage complex matters with a high degree of accuracy, organization, and attention to detail.
- Ability to work both independently and collaboratively in a team environment
- Admission to the bar in the jurisdiction where the candidate will be resident, and in good standing, is required
Pay
Compensation is competitive and commensurate with experience.
Schedule
The firm offers a hybrid work environment that allows attorneys to work remotely two days per week.
Benefits
Day Pitney offers a comprehensive benefits package including health insurance, retirement plans, and paid time off.
Skills
Additional experience in one or more of the following areas is preferred:
- Data governance and information risk, including retention and records, vendor risk, data transfers, and regulatory risk assessments
- Privacy and cybersecurity due diligence, including buy-side and sell-side diligence, data transfer reviews, and investment privacy and security diligence
- Regulatory investigation counseling, including representing clients in non-litigation administrative matters before the FTC, HHS, state attorneys general, and in connection with data privacy-related demands and interactions with law enforcement
Qualifications
Qualified candidates should have experience with the following:
- Privacy compliance and advisory matters, including U.S. state privacy laws, GDPR and global privacy issues, and federal privacy laws, particularly GLBA and HIPAA
- Drafting, reviewing, and negotiating privacy policies, data processing agreements, and related privacy documentation
- Advising clients on the use of cookies and other tracking/data collection technologies
- Cybersecurity and incident response matters, including breach response, ransomware/extortion events, and regulator and state attorney general engagement
- Supporting time-sensitive cybersecurity incident response matters, including matters that may require availability outside of regular business hours