SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Spring Health, a global mental health platform, is seeking a Vice President of Privacy and Data Protection Officer to lead the company's US and global privacy strategy. Reporting to the General Counsel, you will own comprehensive privacy and data protection programs while partnering with Security, Product, and Engineering teams.
Key responsibilities include: serving as the designated US Privacy and Global Data Protection Officer providing strategic leadership; leading and mentoring a privacy legal team including attorneys and paraprofessionals; developing creative legal strategies at the intersection of healthcare privacy and AI; architecting a scalable privacy framework for international expansion compliant with GDPR, HIPAA, and local regulations; advising executives on privacy implications of emerging technologies and ethical AI use in clinical settings; overseeing enterprise-wide privacy risk assessments with "Privacy by Design" integration; directing data incident and breach response strategies; collaborating with Sales and Customer Success on complex contract negotiations; defining and maintaining internal and external privacy policies; and partnering with People Team on employee data practices.
Success metrics include establishing a risk-based AI governance framework, achieving 100% HIPAA and privacy training completion, reducing sales-cycle friction through a comprehensive Trust Center, implementing scalable Privacy Impact Assessment workflows, successfully navigating compliance for two new international markets within year one, and maintaining zero-finding status on SOC2 Type II and HITRUST audits.
Required qualifications: JD from accredited law school with active state bar membership; 12+ years legal experience with 8+ years focused on data privacy, security, and healthcare law; proven track record leading and scaling privacy teams in high-growth global tech environments; deep expertise in HIPAA/HITECH, GDPR, CCPA/CPRA, and international frameworks (LGPD, PIPEDA); professional privacy certifications (CIPP/US, CIPP/E, CIPM, or CIPT); exceptional communication skills translating complex legal requirements into actionable business strategies; experience navigating AI/ML privacy complexities in regulated industries; and mission-driven commitment to mental health access.