SlipstreamJobsFresh Startup & VC-Backed Jobs

Privacy Counsel

Waltz Health - Chicago, IL, United States - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

EVERSANA is a global health science services company with 7,000+ employees supporting life sciences commercialization for 650+ clients ranging from biotech startups to established pharmaceutical companies. The Privacy Office is seeking a Privacy Counsel to join the in-house legal team and help navigate the complex, rapidly evolving privacy landscape. In this role, you will serve as a key advisor to internal business teams on compliance with U.S. federal and state privacy laws (CCPA/CPRA, HIPAA, GLBA) and international frameworks (GDPR, UK GDPR), with particular focus on health science services and sensitive health-related information. You will draft, review, and negotiate privacy-related agreements including data processing addenda, vendor agreements, customer agreements, business associate agreements, and cross-border data transfer arrangements. Key responsibilities include developing and implementing privacy policies, notices, consent management strategies, and internal governance frameworks tailored to a health science services environment. You will guide internal stakeholders through incident response, including breach notification requirements, escalation procedures, risk assessments, and regulatory reporting. You'll conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, systems, and data uses. You will monitor legislative developments and advise on emerging privacy trends, technologies, and enforcement actions. Collaboration with cross-functional teams—IT, security, compliance, marketing, product, operations, and research-focused teams—is essential to embed privacy into business operations. You'll provide practical, risk-based legal advice on collection, use, sharing, retention, and de-identification of personal and health-related information. The role requires a Juris Doctor from an accredited law school and active bar membership in at least one U.S. jurisdiction. You should have 2-4 years of experience practicing law with a focus on data privacy, cybersecurity, technology law, or healthcare regulatory matters, preferably with corporate experience or in-house experience. Demonstrated operational experience in data privacy programs with direct involvement in real-world implementations is essential. Travel is less than 10%; standard Monday-Friday, 40+ hours per week.

Similar roles