Position Summary
OSV is seeking a VP, Deputy General Counsel to lead legal strategy and day-to-day counsel across Privacy, Compliance, Product Legal, and Artificial Intelligence (AI). Reporting to the Chief Legal Officer, this attorney will serve as a trusted advisor to product, engineering, marketing, and business teams, and will own the company's legal approach to data protection, cybersecurity, and the responsible development and deployment of AI and data-driven products. The ideal candidate combines deep regulatory knowledge with pragmatic, business-focused judgment and is comfortable operating as both a hands-on advisor and a strategic leader.
Key Responsibilities
Product Legal Support
- Serve as the go-to legal advisor for day-to-day questions from the product and engineering teams on new features and builds that affect disclosures, data sharing, or the customer experience.
- Draft, review, and maintain consumer-facing agreements, online terms, and regulatory notices to reflect product updates and compliance/privacy initiatives and applicable regulation/law.
- Review marketing campaigns for legal compliance, including offer T&Cs, promotional disclosures, sweepstakes rules, and modifications to approved templates.
Regulatory Compliance and Risk Advisor
- Provide legal guidance on U.S. and global privacy and cybersecurity laws, regulations, and enforcement trends.
- Interpret evolving regulatory guidance and translate supervisory expectations into actionable legal advice.
- Monitor emerging issues including AI governance, data ethics, digital identity, and advanced cyber threats.
- Advise on privacy-by-design and security-by-design, data minimization and retention, cross-border data transfers, access controls, and other data-related issues.
Incident Response and Cyber Events
- Lead the legal response to privacy and cybersecurity incidents, including investigation, legal risk assessment, and regulatory and contractual analysis.
- Coordinate closely with internal stakeholders and external forensic firms, outside counsel, and crisis management advisors.
- Advise on notification obligations, litigation risk, and regulatory engagement arising from cyber events.
Commercial Transactions and Technology Enablement
- Advise on privacy and cybersecurity issues across commercial transactions, including vendor engagements, cloud services, SaaS platforms, fintech partnerships, strategic investments, and M&A.
- Draft, negotiate, and approve data protection and information security provisions in customer, vendor, and partner agreements.
Emerging Technology and Innovation
- Advise on privacy, data protection, and cybersecurity considerations related to the design, development, and deployment of artificial intelligence, advanced analytics, and other data-driven products and business models.
Education and Enablement
- Educate legal, technology, and business teams on privacy and cybersecurity requirements in a pragmatic, business-focused manner.
- Identify and support efforts to scale consistent, risk-based legal guidance across the enterprise.
Qualifications & Experience
- Experience: Minimum of 15 years of relevant legal experience, with substantial depth in privacy, data protection, cybersecurity, and technology/commercial law; in-house experience advising product and engineering teams strongly preferred.
- Education: Juris Doctor (JD) from an ABA-accredited U.S. law school.
- Licensure: Active license to practice law in good standing in the attorney's state of residence.
- Demonstrated knowledge of U.S. state and federal privacy and data protection laws (e.g., CCPA/CPRA and other state privacy statutes), and familiarity with global frameworks such as GDPR. CIPP and CISSP certifications are a plus.
- Working knowledge of emerging AI governance frameworks and the legal issues raised by AI-enabled products and analytics.
- Experience leading or supporting cybersecurity incident response, including coordination with forensic firms, outside counsel, and regulators.
- Strong track record negotiating data protection and security terms in commercial, vendor, and technology agreements.
- Excellent judgment, business acumen, and the ability to translate complex regulatory requirements into clear, actionable guidance for non-legal audiences.
- Exceptional written and verbal communication skills, with the ability to build trust across legal, product, engineering, marketing, and executive teams.