Contracts Manager
About Zello
Zello is a voice-first communication platform, powered by our industry-leading push-to-talk technology, to improve collaboration and productivity for desk-less workers. With over 175+ million users, we’re the #1 rated push-to-talk app in the world, delivering 9 billion messages a month. At Zello, our company values are at the heart of what we do every day. We’re proud to serve the frontline, we’re privileged to connect people in times of crisis across the globe, and we’re honored to support first responders.
About the role
This role owns customer and vendor contracting end-to-end — NDAs, MSAs, DPAs, AI data-processing addendums, and security exhibits — with outside counsel reserved for what is genuinely novel. Embedded in the role is support for Zello's governance, risk, and compliance program, which rewards exactly the traits a strong contracts manager already has: structure, discipline, and a clean paper trail. No GRC background is required; we will teach it.
Responsibilities
- Own the customer contract lifecycle: review, redline, and negotiate NDAs, MSAs, DPAs, AI data-processing addendums, BAAs, amendments, and security exhibits from first draft to signature.
- Decide when an issue is genuinely novel enough to loop in outside counsel — and handle everything else yourself.
- Build the contracting infrastructure: playbooks, fallback positions, template libraries, and the escalation bar that keeps routine deals out of anyone else's inbox.
- Own the vendor lifecycle: intake, due diligence, tiering, approval, renewal, and termination.
- Run data subject requests in support of GDPR and subpoena/legal-request intake end-to-end, and track the contractual notification commitments tied to Zello products and AI data changes to support compliance with respective requirements.
- Support the administration of Zello's compliance stack — Drata, KnowBe4 — and run the policy lifecycle (drafting, review cadence, attestation) and periodic access reviews.
- Use AI on the repetitive parts of this work — first-pass review, questionnaire drafting, clause comparison, obligation tracking — and keep improving how you use it.
Who you are
- You have 3+ years owning commercial contracts in-house, and you've independently redlined and closed NDAs, DPAs, and MSAs without an attorney walking you through them.
- You are organized to a degree other people find slightly excessive. Every open redline, obligation, and renewal date is tracked, and nothing falls off.
- You are at home in the detail. A DPA with three conflicting definitions of “Personal Data” is a puzzle you enjoy, not a chore you dread.
- Law was a real consideration for you at some point — you may have prepped for the LSAT, worked shoulder-to-shoulder with attorneys, or come close to applying — and you concluded the operating side of legal is where you do your best work.
- You are already using AI in your work, or you are impatient to. You don't need to know how the models work; you need to believe the first draft should come from a machine and your judgment should be spent on what matters.
- GRC is new to you and that reads as interesting rather than intimidating. You've noticed it runs on the same things contracting does — structure, evidence, follow-through — and you want the surface area.
- You spot a manual or error-prone process before anyone points it out, and you fix it — building a clause library instead of redlining from scratch every time.
- You communicate clearly and concisely with Sales, Customer Success, Engineering, and outside counsel, without over-explaining or leaving people guessing.
Role scope
- Not an attorney role — no JD or bar admission is required or expected. Outside counsel handles the genuinely novel; you handle the rest.
- Not a management role — there are no direct reports.
- Not a GRC or security engineering role — you own the compliance program's operational rigor, not the underlying technical controls (IAM, SIEM, pen testing), and you do not need a GRC background walking in.
- Not a redline-only role — contracting is the core, but vendor management and the compliance program's operational cadence come with it.