Privacy Counsel

Great American Insurance Group

$95K — $115K *
Legal & Accounting
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Juris Doctor degree from an accredited law school.
  • Active license in good standing in at least one U.S. jurisdiction.
  • Four to five years of relevant legal experience in privacy or cybersecurity.
  • Experience with insurance or financial services regulations preferred.
  • Privacy certification (CIPP/US) or comparable credential is a plus.

Responsibilities

  • Support development and implementation of the Company’s privacy program.
  • Assist in response to privacy and security incidents, including investigating and documenting.
  • Draft and negotiate privacy terms in commercial agreements, including data processing.
  • Ensure compliance with various privacy and data security laws and regulations.
  • Monitor legal developments and translate them into actionable recommendations.
  • Build trusted relationships and provide agile legal guidance to internal clients.

Benefits

  • Comprehensive medical, dental, and vision coverage for full-time employees.
  • Wellness plans, parental leave, and tuition reimbursement available to full-time employees.
  • Paid Time Off and paid holidays for full-time and eligible part-time employees.
  • 401(k) plan with company match offered.
  • Employee stock purchase plan and commuter benefits for eligible employees.
Full Job Description
This position is not eligible for employment visa sponsorship. Applicants must be authorized to work in the United States without the need for current or future sponsorship. Great American’s culture is built on connection, shared learning, and strong relationships. To support this, employees in this role are expected to be on-site four days a week, with the flexibility to work one day remotely. Core in‑office days are Tuesday–Thursday, with the fourth day determined by business needs. The Company is seeking a practical, collaborative Privacy Attorney to join its legal and compliance team and support a broad portfolio of privacy, data protection, cybersecurity, emerging technology/AI, and regulatory matters. The attorney will partner with business, technology, information security, compliance, procurement, and legal stakeholders across a complex insurance organization to translate evolving legal requirements into clear, defensible, and operationally workable solutions and support the organization’s privacy program. This role is well suited for an attorney with four to five years of relevant experience, who has a background in privacy and data protection frameworks and is ready to take on meaningful responsibility in an in-house environment. Essential Job Functions and Responsibilities • Support the development, implementation, and ongoing maturation of the Company’s privacy program, including policies, procedures, training, governance, and third-party contracting. • Support privacy and security incident response, including investigation, remediation, documentation, and individual and regulator notifications under applicable laws. • Draft, review, and negotiate privacy and data protection terms in commercial agreements, including data processing agreements, business associate agreements, and artificial intelligence provisions. • Support compliance with privacy and data security laws, such as the NYDFS Part 500, GLBA and related state insurance laws and regulations, CCPA/CPRA, HIPAA, GDPR, and other applicable regulatory frameworks. • Monitor legal and regulatory developments and translate them into practical recommendations, policies, controls, training, and implementation plans. • Develop trusted relationships with internal clients and deliver responsive, business-oriented legal guidance and workable compliance frameworks. Required Qualifications • Juris Doctor degree from an accredited law school. • Active license and good standing in at least one U.S. jurisdiction. • Generally, four to five years of relevant legal experience in privacy, health information, cybersecurity, technology, or related regulatory practice. Experience with HIPAA a plus.  Preferred Qualifications • Experience in a law firm, advising on a variety of privacy, cybersecurity, and emerging technology matters. • Experience with insurance or financial services regulations. • Experience supporting privacy or security incident response and breach-notification analyses. • Privacy certification, such as CIPP/US, or a comparable credential. Attributes for Success • Practical, curious, and comfortable learning complex business operations and technologies. • Collaborative, team oriented, and able to build credibility with legal, technical, operational, and executive stakeholders. • Clear and concise in communicating complex legal requirements to non-legal audiences. • Organized, responsive, and capable of advancing work independently while knowing when to escalate. • Committed to high-quality work, sound judgment, and continuous development in an evolving area of law. Business Unit: Property & Casualty Legal Benefits: We offer competitive benefits packages for full-time and part-time employees*. Full-time employees have access to medical, dental, and vision coverage, wellness plans, parental leave, adoption assistance, and tuition reimbursement. Full-time and eligible part-time employees also enjoy Paid Time Off and paid holidays, a 401(k) plan with company match, an employee stock purchase plan, and commuter benefits. Compensation varies by role, level, and location and is influenced by skills, experience, and business needs. Your recruiter will provide details about benefits and specific compensation ranges during the hiring process. Learn more at http://www.gaig.com/careers. *Excludes seasonal employees and interns.

Similar Jobs

More Jobs at Great American Insurance Group

More Legal & Accounting Jobs

Find similar Privacy Counsel jobs: