Jobs · Legal

Privacy Counsel

EVERSANA · Chicago, IL · 1 mo ago
RemoteRemoteLegalFull-time

At EVERSANA, we are proud to be certified as a Great Place to Work across the globe. We’re fueled by our vision to create a healthier world. Our global team of more than 7,000 employees is committed to creating and delivering next-generation commercialization services to the life sciences industry. We serve more than 650 clients ranging from innovative biotech start-ups to established pharmaceutical companies. Our products, services, and solutions help bring innovative therapies to market and support the patients who depend on them. We embrace diversity in backgrounds and experiences, believing our people make all the difference in cultivating an inclusive culture that embraces our cultural beliefs.

About the role

We are a forward-thinking, agile legal team dedicated to safeguarding the trust between people and the organizations that serve them. In a world where data is the new currency, we believe privacy is a fundamental right—not a privilege. Our mission is to help our internal clients and customers innovate responsibly, ensuring that personal information is handled with integrity, transparency, and compliance with evolving global regulations. As part of a health science services company, we support the responsible use of sensitive health, research, and business data in a manner that advances better outcomes while maintaining the highest standards of privacy, ethics, and compliance.

As Privacy Counsel, you will report into the Privacy Office and serve as a key member of our in-house legal team, helping shape how our company navigates the complex and rapidly changing privacy landscape. Your work will directly influence how our organization protects sensitive information, supports health science services, responds to data incidents, and designs privacy-first processes, products, and services.

Responsibilities

  • Advise internal business teams on compliance with U.S. federal and state privacy laws (e.g., CCPA/CPRA, HIPAA, GLBA) and international frameworks (e.g., GDPR, UK GDPR), with a focus on laws relevant to health science services and sensitive health-related information.
  • Draft, review, and negotiate privacy-related agreements, including data processing addenda, vendor agreements, customer agreements, business associate agreements, and cross-border data transfer arrangements.
  • Develop and implement privacy policies, notices, consent management strategies, and internal governance frameworks tailored to a health science services environment.
  • Guide internal stakeholders through incident response, including breach notification requirements, escalation procedures, risk assessments, and regulatory reporting.
  • Conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, systems, and data uses.
  • Monitor legislative developments and advise on emerging privacy trends, technologies, and enforcement actions affecting the company’s operations.
  • Collaborate closely with cross-functional teams—including IT, security, compliance, marketing, product, operations, and research-focused teams—to embed privacy into business operations.
  • Provide practical, risk-based legal advice to internal clients on the collection, use, sharing, retention, and de-identification of personal and health-related information.
  • Demonstrate a commitment to diversity, equity, and inclusion through continuous development, modeling inclusive behaviors, and proactively managing bias.
  • Perform all other duties as assigned.

Requirements

  • Juris Doctor (JD) from an accredited law school and active bar membership in at least one U.S. jurisdiction.
  • 2-4 years of experience practicing law with a focus on data privacy, cybersecurity, technology law, or healthcare regulatory matters.
  • Corporate experience (preferred) or prior in-house experience (a plus) or substantial experience advising corporate clients.
  • Demonstrated operational experience in data privacy programs, including direct involvement in real-world implementations and support of business operations.
  • Proven ability to manage and respond to data privacy incidents (e.g., data breaches, unauthorized disclosures), including risk assessment, legal analysis, and coordination with cross-functional teams.
  • Strong working knowledge of major privacy laws and regulatory frameworks (GDPR, CCPA/CPRA, HIPAA, and similar laws).
  • Experience drafting and negotiating privacy-related contractual provisions in a commercial setting.
  • Experience supporting privacy compliance in the healthcare, health technology, life sciences, or health science services sector.
  • Familiarity with privacy technologies, data governance tools (OneTrust, TrustArc, Osano), and operational privacy compliance processes.
  • Data privacy certifications such as CIPM, CIPP/E, or AIGP are a plus.
  • Exceptional research, analytical, and communication skills—able to translate complex legal concepts into clear, actionable guidance for business stakeholders.
  • A proactive, solutions-oriented mindset with the ability to balance legal risk and business objectives in a fast-paced, fully remote environment.

Schedule

Monday-Friday, 40+ hours per week. Travel required (less than 10%).

Pay

This role is eligible for hire in select U.S. locations based on business and operational considerations. If this job posting includes a base salary range, it represents the low and high end of the salary range for this position and is not applicable to locations outside of the U.S. Compensation will be determined based on relevant experience, other job-related qualifications/skills, and geographic location (to account for comparative cost of living).

Similar jobs

Privacy Counsel

NextdoorSan Francisco, CA· 2 mo ago
Legal$220k–$260k/yrapply on boards.greenhouse.io

Privacy Counsel

StackAdaptUnited States· 2 mo ago
RemoteLegalapply on grnh.se

Privacy Counsel

HackerOneWashington, DC· 3 wk ago
RemoteLegal$180k–$215k/yrapply on jobs.ashbyhq.com

Privacy Counsel

HackerOneSeattle, WA· 3 wk ago
RemoteLegal$180k–$215k/yrapply on jobs.ashbyhq.com

Privacy Counsel

Beacon SoftwareSan Francisco, CA· 2 wk ago
Legalapply on jobs.ashbyhq.com

Privacy Counsel

Beacon SoftwareNew York, NY· 2 wk ago
Legalapply on jobs.ashbyhq.com