SlipstreamJobsFresh Startup & VC-Backed Jobs

Privacy Counsel

Beacon Software - San Francisco, CA, United States - In-office - posted 2026-08-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Beacon Software is seeking a strategic Privacy Counsel to build and lead the company's data privacy program from the ground up. Reporting to the VP of Legal, you will establish foundational privacy strategy, governance structures, and operating models across Beacon and its growing portfolio of vertical market software companies. Key responsibilities include: **Privacy Program Architecture**: Design and implement Beacon's enterprise data privacy program, establishing foundational strategy, governance structures, and operating models. Define privacy principles and risk appetite, translating them into scalable policies, controls, and accountability structures. **M&A Privacy Diligence & Integration**: Own the privacy workstream across the full deal lifecycle. Conduct privacy due diligence on acquisition targets, assessing data inventories, consent frameworks, cross-border transfer mechanisms, and regulatory exposure. Develop standardized diligence checklists and playbooks. Lead post-close privacy integration planning to align acquired companies with Beacon's privacy standards. **Policy & Documentation**: Draft and maintain core privacy documentation including privacy policies, data processing agreements (DPAs), records of processing activities (ROPAs), consent frameworks, data subject rights procedures, data retention schedules, and vendor privacy terms. Build reusable templates and precedents for portfolio deployment. **Cross-Functional Partnership**: Serve as primary privacy advisor to IT, Governance, and Risk functions. Partner with engineering, product, and operations teams to embed privacy-by-design principles into technology development and business processes. Translate regulatory requirements into actionable guidance for non-legal stakeholders. **Multi-Jurisdictional Compliance**: Monitor and advise on compliance with applicable data privacy laws across operating jurisdictions, with depth in U.S. federal and state privacy law (CCPA/CPRA), Canadian privacy law (PIPEDA, Law 25/Bill 64), and EU/UK GDPR. Manage cross-border data transfer requirements and implement appropriate transfer mechanisms. **Data Breach Response**: Develop and maintain data breach and privacy incident response playbooks. Serve as legal lead on privacy incidents, advising on investigation, containment, notification obligations, and regulatory reporting across multiple jurisdictions. **Vendor Management**: Own third-party privacy risk framework, including vendor assessments, DPA negotiations, and ongoing monitoring. Ensure data sharing arrangements meet legal requirements and reflect Beacon's standards. **Emerging Technology**: Advise on privacy implications of AI tools and emerging technologies. This is a foundational, high-autonomy role for a privacy lawyer who wants to build lasting infrastructure rather than maintain status quo.

Similar roles