Privacy & AI Governance Counsel
As a key member of Orion’s leadership team, you will serve as the enterprise’s lead advisor on privacy, AI governance, and responsible technology use. Reporting to the Risk Officer, this role partners with business leaders, Legal, Information Security, Compliance, Product, and Technology teams to embed privacy and responsible-AI principles into business operations, products, and strategic initiatives.
About the role
- Serve as the primary enterprise advisor for privacy and AI governance, partnering with business leaders to integrate privacy and responsible-AI principles into processes, products, services, and decision-making.
- Develop, maintain, and enhance privacy and AI governance frameworks, policies, standards, and controls aligned with organizational objectives and regulatory requirements.
- Translate legal and regulatory requirements into practical business guidance that enables innovation while mitigating privacy and AI-related risks.
- Monitor, assess, and communicate the impact of evolving privacy, security, and AI regulations on business operations.
- Investigate privacy and AI-related incidents, conduct root-cause analyses, oversee remediation activities, and ensure timely resolution of identified risks.
- Lead enterprise privacy compliance activities, including privacy impact assessments, AI risk assessments, records of processing activities, data mapping, and regulatory reporting.
- Manage Data Subject Rights Request (DSRR) processes and support regulatory inquiries, audits, examinations, and investigations.
- Review and negotiate privacy and data-protection provisions within contracts, vendor agreements, and third-party risk assessments.
- Collaborate with Legal, Information Security, Compliance, Product, Technology, and business teams to address privacy and AI governance requirements.
- Develop and deliver privacy, AI governance, and data-protection training programs to increase organizational awareness and compliance.
- Establish, monitor, and report key privacy and AI governance metrics, risks, and compliance indicators to leadership.
- Support enterprise resilience and crisis-management activities involving privacy, cybersecurity, and AI-related incidents.
- Maintain governance inventories for privacy and AI systems, including automated decision-making technologies and high-risk processing activities.
- Provide legal guidance regarding data minimization, purpose limitation, transparency, profiling, automated decision-making, and emerging AI regulations.
- Drive continuous improvement initiatives that enhance privacy operations, governance effectiveness, and regulatory readiness.
Requirements
- Strong knowledge of privacy laws and regulations, including U.S. state privacy laws, GDPR, and emerging AI governance requirements.
- Knowledge of AI governance, automated decision-making systems, data lifecycle management, and responsible-AI principles.
- Ability to interpret complex legal, regulatory, and compliance requirements and translate them into actionable business recommendations.
- Strong risk assessment, issue resolution, and investigative skills.
- Experience conducting privacy impact assessments, AI risk assessments, and privacy compliance reviews.
- Experience reviewing, drafting, and negotiating contractual privacy and data-protection provisions.
- Strong analytical and problem-solving skills with sound judgment and decision-making capabilities.
- Excellent written and verbal communication skills, including the ability to present complex concepts to executive leadership.
- Ability to build relationships and influence stakeholders across all organizational levels without direct authority.
- Strong project management and organizational skills with the ability to manage multiple priorities simultaneously.
- Effective collaboration skills across Legal, Compliance, Information Security, Technology, and business functions.
- Ability to work independently in a fast-paced, highly regulated environment.
- Minimum of a Juris Doctor (J.D.) degree.
- Minimum of 3 years of experience in privacy, data protection, AI governance, compliance, cybersecurity, legal, risk management, or a related field.
- Experience supporting privacy compliance programs and regulatory requirements within financial services, fintech, wealth management, investment advisory, or similarly regulated industries preferred.
- Experience managing privacy incidents, regulatory inquiries, audits, vendor risk assessments, and data governance initiatives preferred.
- Experience advising on AI governance, emerging technologies, or automated decision-making systems preferred.
- Demonstrated experience working cross-functionally with legal, compliance, security, technology, and business teams.
Benefits
- Health, dental, vision, and disability coverage on day one.
- 401(k) plan with employer match.
- Paid parental leave.
- Pet benefits including pawternity leave and pet insurance.
- Student loan repayment.
Pay
$94,869.00 – $146,945.00. The pay listed in this posting indicates the estimated pay at the time of this posting; however, may vary depending on geographic location, job-related knowledge, skills, and experience.
Schedule
Hybrid schedule requiring three (3) or more days each week on-site at one of the listed office locations. Candidates should be located within a commutable distance to an office.