EVERSANA

Privacy Counsel

EVERSANA$90K — $130K *
Legal & Accounting
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Juris Doctor (JD) from an accredited law school and active bar membership in at least one U.S. jurisdiction.
  • 2-4 years of experience in data privacy, cybersecurity, or healthcare regulatory matters, preferably in corporate or in-house settings.
  • Operational experience in data privacy programs with real-world implementations.
  • Proven ability to manage and respond to data privacy incidents, including risk assessment and cross-functional coordination.
  • Strong working knowledge of major privacy laws (GDPR, CCPA/CPRA, HIPAA) and their application.

Responsibilities

  • Advise on compliance with U.S. and international privacy laws relevant to health science services.
  • Draft and negotiate privacy-related agreements, including data processing and vendor agreements.
  • Develop and implement tailored privacy policies and internal governance frameworks.
  • Guide stakeholders through incident response and breach notification requirements.
  • Conduct privacy impact assessments for new products and services.
  • Monitor legislative developments in privacy trends and enforcement actions.
  • Collaborate with cross-functional teams to integrate privacy into business operations.

Benefits

  • Commitment to diversity, equity, and inclusion in the workplace.
  • Opportunities for continuous development and modeling inclusive behaviors.
  • Flexible working environment with a fully remote option.
  • Support in managing work-life balance within a fast-paced setting.
Full Job Description
Job Description

THE POSITION:

We are a forward-thinking, agile legal team dedicated to safeguarding the trust between people and the organizations that serve them. In a world where data is the new currency, we believe privacy is a fundamental right-not a privilege. Our mission is to help our internal clients and customers innovate responsibly, ensuring that personal information is handled with integrity, transparency, and compliance with evolving global regulations. As part of a health science services company, we support the responsible use of sensitive health, research, and business data in a manner that advances better outcomes while maintaining the highest standards of privacy, ethics, and compliance.

As Privacy Counsel, you will report into the Privacy Office and serve as a key member of our in-house legal team, helping shape how our company navigates the complex and rapidly changing privacy landscape. Your work will directly influence how our organization protects sensitive information, supports health science services, responds to data incidents, and designs privacy-first processes, products, and services. You won't just interpret the law-you'll help define and operationalize best practices that set the standard for ethical data use across our business.

ESSENTIAL DUTIES AND RESPONSIBILITIES:
Our employees are tasked with delivering excellent business results through the efforts of their teams. These results are achieved by:
  • Advise internal business teams on compliance with U.S. federal and state privacy laws (e.g., CCPA/CPRA, HIPAA, GLBA) and international frameworks (e.g., GDPR, UK GDPR), with a particular focus on laws and guidance relevant to health science services and sensitive health-related information.
  • Draft, review, and negotiate privacy-related agreements, including data processing addenda, vendor agreements, customer agreements, business associate agreements, and cross-border data transfer arrangements.
  • Develop and implement privacy policies, notices, consent management strategies, and internal governance frameworks tailored to a health science services environment.
  • Guide internal stakeholders through incident response, including breach notification requirements, escalation procedures, risk assessments, and regulatory reporting.
  • Conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, systems, and data uses.
  • Monitor legislative developments and advise on emerging privacy trends, technologies, and enforcement actions affecting the company's operations.
  • Collaborate closely with cross-functional teams-including IT, security, compliance, marketing, product, operations, and research-focused teams-to embed privacy into business operations.
  • Provide practical, risk-based legal advice to internal clients on the collection, use, sharing, retention, and de-identification of personal and health-related information.
  • Demonstrate a commitment to diversity, equity, and inclusion through continuous development, modeling inclusive behaviors, and proactively managing bias.
  • All other duties as assigned.

EXPECTATIONS OF THE JOB:
  • Travel (Less than 10%)
  • Hours (Monday-Friday, 40+ hours per week)

The above list reflects the general details necessary to describe the expectations of the position and shall not be construed as the only expectations that may be assigned for the position.

An individual in this position must be able to successfully perform the expectations listed above.

Qualifications

MINIMUM KNOWLEDGE, SKILLS AND ABILITIES:

The requirements listed below are representative of the experience, education, knowledge, skill and/or abilities required.
  • Juris Doctor (JD) from an accredited law school and active bar membership in at least one U.S. jurisdiction.
  • 2-4 years of experience practicing law with a focus on data privacy, cybersecurity, technology law, or healthcare regulatory matters, including Corporate experience (preferred) or prior in-house experience (a plus) or substantial experience advising corporate clients.
  • Demonstrated operational experience in data privacy programs, including direct involvement in real-world implementations and support of business operations
  • Proven ability to manage and respond to data privacy incidents (e.g., data breaches, unauthorized disclosures), including risk assessment, legal analysis, and coordination with cross-functional teams
  • Strong working knowledge of major privacy laws and regulatory frameworks (GDPR, CCPA/CPRA, HIPAA, and similar laws).
  • Experience drafting and negotiating privacy-related contractual provisions in a commercial setting.
  • Experience supporting privacy compliance in the healthcare, health technology, life sciences, or health science services sector.
  • Familiarity with privacy technologies, data governance tools (OneTrust TrustArc, Osano), and operational privacy compliance processes.
  • Data privacy certifications such as CIPM, CIPP/E, or AIGP are a plus.
  • Exceptional research, analytical, and communication skills-able to translate complex legal concepts into clear, actionable guidance for business stakeholders.
  • A proactive, solutions-oriented mindset with the ability to balance legal risk and business objectives in a fast-paced, fully remote environment.

PHYSICAL/MENTAL DEMANDS AND WORKING ENVIRONMENT:

The physical and mental requirements along with the work environment characteristics described here are representative of those an individual encounters while performing the essential functions of this position.

Office: While performing the essential functions of this job the employee is frequently required to reach, grasp, stand and/or sit for long periods of time (up to 90% of the shift), walk, talk and hear; occasionally required to lift and/or move up to 25 pounds. The noise level in the work environment is usually moderately quiet, with frequent interruptions and multiple demands.

Additional Information

Our team is aware of recent fraudulent job offers in the market, misrepresenting EVERSANA. Recruitment fraud is a sophisticated scam commonly perpetrated through online services using fake websites, unsolicited e-mails, or even text messages claiming to be a legitimate company. Some of these scams request personal information and even payment for training or job application fees. Please know EVERSANA would never require personal information nor payment of any kind during the employment process. We respect the personal rights of all candidates looking to explore careers at EVERSANA.

EVERSANA is committed to providing competitive salaries and benefits for all employees. If this job posting includes a base salary range, it represents the low and high end of the salary range for this position and is not applicable to locations outside of the U.S. Compensation will be determined based on relevant experience, other job-related qualifications/skills, and geographic location (to account for comparative cost of living). This role is eligible for hire in select U.S. locations based on business and operational considerations. For a full list of locations, visit eversana.com/careers. More information about EVERSANA's benefits package can be found at eversana.com/careers. EVERSANA reserves the right to modify this base salary range and benefits at any time.

From EVERSANA's inception, Diversity, Equity & Inclusion have always been key to our success. We are an Equal Opportunity Employer, and our employees are people with different strengths, experiences, and backgrounds who share a passion for improving the lives of patients and leading innovation within the healthcare industry. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion, and many other parts of one's identity. All of our employees' points of view are key to our success, and inclusion is everyone's responsibility.

Follow us on LinkedIn / Twitter

Similar Jobs

More Jobs at EVERSANA

More Legal & Accounting Jobs

Find similar Privacy Counsel jobs: