SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Privacy Counsel

Abnormal AI - Remote - Remote - posted 2026-08-13

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Abnormal AI, an AI-native cybersecurity company, is seeking a Senior Privacy Counsel to own significant portions of its global privacy program. Reporting to the AGC, PPIP, you will drive legal judgment, day-to-day operational execution, and AI-enabled tooling across the privacy function. Key responsibilities include: **Global Privacy Program Execution**: Design and implement Abnormal's privacy program across GDPR, UK GDPR, EU AI Act, NIS2, DORA, EU Data Act, and US state privacy laws. Manage international data transfer strategies (SCCs, UK IDTA, EU–US Data Privacy Framework) as the product footprint expands globally. **AI Governance**: Execute the AI governance program from the legal and privacy side, including EU AI Act classification and obligations, partnering with R&D, Security, and AI governance teams. **Privacy by Design**: Embed privacy into AI-driven product features, including model data governance, secondary data-use analysis, and behavioral AI implications. Set privacy diligence standards for AI/LLM vendors and model providers. Provide ongoing product and privacy legal counseling alongside the Director, Legal (Product). **Privacy Operations**: Oversee DSARs, data-subject rights, Records of Processing Activities, data mapping, impact assessments (DPIA/PIA/TIA/LIA), retention, consent and cookie management, and audit support (SOC 2, ISO 27701/42001). **AI Automation**: Design, deploy, and improve AI-enabled privacy workflows (DPIA triage and drafting, subprocessor determination) with Legal Operations and engineering. This is a build-it role—specify, prototype, and iterate to high accuracy standards. **Regulatory Horizon Scanning**: Monitor emerging privacy and AI regulations in current and target markets; flag jurisdiction-specific requirements to inform market entry decisions and translate guidance into execution support. **Vendor & Customer Contracts**: Serve as privacy escalation point for Commercial and Procurement teams on vendor, subprocessor, and customer agreements (DPAs, SCCs, subprocessor terms). **Incident & Breach Response**: Advise on and lead privacy and legal aspects of incident response, including AI incidents, breach assessment, notification decisions, and mitigation. **DPO Support & Regulatory Engagement**: Support the DPO function as a day-to-day advisor and serve as a privacy contact for supervisory authorities. You will work with the Privacy Manager on operational execution and partner across product, engineering, and commercial teams. The role offers the opportunity to build and scale the privacy function at a category-defining AI-native cybersecurity company, with real license to design AI automation that transforms how privacy work gets done.

Similar roles