About the Role
As Privacy Managing Counsel, you will support the company's Embedded Finance business by advising on privacy-by-design, responsible data use, and scalable compliance across products, partnerships, and commercial arrangements. You will work closely with product, engineering, compliance, risk, business, and legal stakeholders, as well as sponsor banks and consumer technology partners. Your work will help enable compliant growth, strengthen privacy governance, and support practical decision-making throughout the product lifecycle.
Responsibilities
- Advise business, product, engineering, compliance, risk, and legal stakeholders on privacy and data protection requirements applicable to embedded finance offerings, including the Gramm-Leach-Bliley Act (GLBA), state privacy laws, the California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), General Data Protection Regulation (GDPR), Fair Credit Reporting Act (FCRA), Health Insurance Portability and Accountability Act (HIPAA), and related frameworks.
- Partner with cross-functional teams to identify privacy implications, conduct risk assessments, and implement practical, scalable privacy-by-design controls throughout the product lifecycle.
- Advise on Banking-as-a-Service (BaaS) program structures and privacy-related compliance considerations across sponsor banks, program managers, processors, consumer-facing partners, and other third parties.
- Draft, review, and negotiate privacy and data protection provisions in commercial and technology agreements, including data use, licensing, vendor, service provider, customer, and data transfer agreements.
- Lead partner and vendor negotiations on privacy matters and participate in client-facing discussions related to data use, compliance obligations, and contractual risk.
- Develop, maintain, and enhance privacy policies, notices, procedures, training materials, and governance tools that promote consistent operational practices.
- Monitor evolving privacy laws and regulations and translate legal requirements into practical guidance for internal stakeholders.
Qualifications
- 8+ years of legal experience focused on privacy, data protection, financial services regulation, or related legal counseling.
- Experience advising on U.S. financial privacy laws, including GLBA and state privacy requirements.
- Experience drafting, reviewing, and negotiating commercial, technology, vendor, customer, data use, and data protection agreements within financial services, banking, payments, fintech, or similarly regulated industries.
- Experience supporting banks, fintech companies, payment processors, card networks, or comparable law firm clients.
- Active license to practice law in at least one U.S. jurisdiction.
- Juris Doctor (JD), Master of Laws (LL.M.), or equivalent legal qualification.
Preferred Experience
- CIPP/US or another recognized privacy certification.
- Experience supporting embedded finance, Banking-as-a-Service, or other partner-driven financial products.
- Experience advising within complex, multi-party ecosystems involving sponsor banks, processors, fintech platforms, and consumer-facing technology companies.
- Familiarity with implementing privacy-by-design practices within product development and engineering environments.