Jobs › Remote › Privacy Counsel
Privacy Counsel
HackerOne is hiring for the role of Privacy Counsel, Remote. This is a Privacy role in the governance, risk, and compliance field. Review the full details below and apply directly with HackerOne.
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises. Industry leaders, including Anthropic, Crypto.com , General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing and has been named a Most Loved Workplace for Young Professionals (2024). HackerOne is at a pivotal inflection point in the security industry. Offensive security is no longer optional – it is the standard for forward-thinking companies that want to build trust and resilience in a world where AI-driven innovation and adversaries are moving faster than ever. With the industry shifting, HackerOne stands apart: we combine the ingenuity of the largest security research community with a best-in-class AI-powered platform, trusted by the world’s top organizations. HackerOne Values HackerOne is dedicated to fostering a strong and inclusive culture. HackerOne is Customer Obsessed and prioritizes customer outcomes in our decisions and actions. We Default to Disclosure by operating with transparency and integrity, ensuring trust and accountability. Employees, researchers, customers, and partners Win Together by fostering empowerment, inclusion, respect, and accountability. Privacy Counsel Remote Location: United Kingdom or USA (Boston, Washington DC, Austin, SF Bay Area, Seattle) Position Summary HackerOne is seeking a Privacy Counsel to join our Privacy function to support the growing volume and complexity of global data protection, AI governance, and commercial contracting needs across the business. In this role, you will help accelerate product development, sales motions, internal procurement and cross-border data operations by providing thoughtful, practical, and globally relevant privacy support. In addition to our legal and privacy teams, you will work closely with colleagues in our Product, Security, Compliance, Engineering, and Sales to deliver clear guidance, supporting privacy assessments, and review customer and vendor agreements to help us move quickly and responsibly as we grow. This is an individual contributor role ideal for a privacy lawyer who enjoys hands-on work, cross-functional collaboration, and applying structured legal thinking to emerging technologies. What You Will Do Apply an AI-First approach by using AI tools responsibly to improve research quality, drafting efficiency, and privacy assessment workflows. Demonstrate Change Agility by adapting quickly to evolving global privacy and AI regulations, adjusting guidance as new risks, tools, or requirements emerge. Use First Principles Problem Solving to simplify complex privacy questions, clarify assumptions, and provide clear, structured recommendations. Leverage Data-Driven Decision Making during DPIAs,and related assessments by grounding evaluations in evidence, criteria, and regulatory expectations. Support the current Privacy function with global privacy assessments, including DPIAs, AI DPIAs, TIAs, LIAs, and other structured risk reviews. Review new and existing product features, AI capabilities, and data practices as part of privacy-by-design, identifying risks and opportunities early in development. Draft, review, and negotiate data processing agreements (DPAs), privacy terms, and commercial contracts to support global sales and procurement. Maintain and update privacy contractual documentation and internal templates and policies. Create and deliver internal training on privacy and AI governance. As part of the Privacy function, support internal and external privacy audits, coordinate with external advisors, and ensure alignment across business functions on assessment findings and remediation. Monitor evolving privacy laws, case law, AI governance frameworks, and regulatory trends, sharing key insights with stakeholders to maintain compliance and anticipate future requirements. Minimum Qualifications Qualified lawyer (UK or EU) with GDPR experience PQE 5+ years (mix of in-house or private practice experience). Years matter less to us than impact. If you have relevant specialist experience, apply even if you don’t quite hit the 5+ years. Strong knowledge of EU/UK GDPR and familiarity with global privacy laws (US, Middle East, Asia). Experience drafting and negotiating data processing agreements and handling privacy-related issues in a global business context. Proven ability to manage data breaches, regulatory notifications and privacy audits. Excellent communication skills with the ability to simplify complex legal concepts for non-legal audiences. Strong understanding of AI technologies, their ethical implications, and related legal frameworks. Excellent analytical, problem-solving, and decision-making skills with the ability to provide practical and strategic legal advice. Experience in using privacy management systems such as OneTrust is required. Ability to manage multiple priorities and work collaboratively across diverse teams. Comfortable working independently in a fast-paced, global environment Preferred Qualifications Certified Information Privacy Professional (CIPP), Artificial Intelligence Governance Professional (AIGP) and other relevant certifications, German language proficiency. Experience in cybersecurity, offensive security, or SaaS environments. Compensation Band UK Tier: £105K to £115K • Offers Equity US Tiers: Tier A (SF Bay Area): $180k to $215k •
Location and market context
This is a remote privacy role, so it draws from a national talent pool rather than a single metro. Remote governance and compliance roles reward candidates who can show they work effectively across time zones and distributed legal, security, and product teams. Confirm any residency, travel, or occasional-onsite expectations directly with HackerOne.
About privacy roles
Privacy roles protect personal data across its lifecycle, from data mapping and DPIAs to individual-rights handling. AI systems are widening the scope of what privacy teams must review. Roles like this one are typically evaluated against frameworks such as GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices.
How to position yourself for this privacy role
Strong candidates emphasize data mapping and inventories, privacy impact assessments, rights handling, and building privacy-by-design into products and AI systems. In your resume and outreach, tie your experience to how HackerOne would apply GDPR, CCPA and US state privacy laws, ISO/IEC 27701, and privacy-by-design practices, and lead with concrete outcomes rather than duties.
Similar GRC roles
- Senior Privacy Counsel · Abnormal Security · Remote
- Head of Privacy · Perk · United States
- Senior Privacy and AI Counsel · Abby Care · United States
- Product & Privacy Counsel · Brex · United States
- Privacy & AI Governance Counsel · Anaplan · Miami, FL
- Privacy Operations Program Manager · Stripe · Remote
- Software Engineer, Privacy Engineering · OpenAI · San Francisco
- Research Engineer, Privacy · OpenAI · San Francisco
Want to be next in a role like this?
Roles like Privacy Counsel (remote) open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.