At a Glance
- Tasks: Support global data protection and AI governance while collaborating across teams.
- Company: Join HackerOne, a leader in cybersecurity and privacy solutions.
- Benefits: Enjoy competitive salary, equity options, unlimited PTO, and flexible work arrangements.
- Other info: Be part of a diverse team committed to innovation and inclusion.
- Why this job: Make a real impact in the evolving world of privacy and AI technologies.
- Qualifications: Qualified lawyer with GDPR experience and strong knowledge of global privacy laws.
The predicted salary is between 68000 - 85000 € per year.
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to continuously discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems. Through solutions like bug bounty, vulnerability disclosure, agentic pentesting, AI red teaming, and code security, HackerOne delivers measurable, continuous reduction of cyber risk for enterprises.
Industry leaders, including Anthropic, Crypto.com, General Motors, Goldman Sachs, Lufthansa, Uber, UK Ministry of Defence, and the U.S. Department of Defense, trust HackerOne to safeguard their digital ecosystems. HackerOne was recognized in Gartner’s Emerging Tech Impact Radar: AI Cybersecurity Ecosystem report for its leadership in AI Security Testing and has been named a Most Loved Workplace for Young Professionals (2024).
HackerOne is at a pivotal inflection point in the security industry. Offensive security is no longer optional – it is the standard for forward-thinking companies that want to build trust and resilience in a world where AI-driven innovation and adversaries are moving faster than ever. With the industry shifting, HackerOne stands apart: we combine the ingenuity of the largest security research community with a best-in-class AI-powered platform, trusted by the world’s top organizations.
HackerOne Values
HackerOne is dedicated to fostering a strong and inclusive culture. HackerOne is Customer Obsessed and prioritises customer outcomes in our decisions and actions. We Default to Disclosure by operating with transparency and integrity, ensuring trust and accountability. Employees, researchers, customers, and partners Win Together by fostering empowerment, inclusion, respect, and accountability.
Position Summary
HackerOne is seeking a Privacy Counsel to join our Privacy function to support the growing volume and complexity of global data protection, AI governance, and commercial contracting needs across the business. In this role, you will help accelerate product development, sales motions, internal procurement and cross-border data operations by providing thoughtful, practical, and globally relevant privacy support. In addition to our legal and privacy teams, you will work closely with colleagues in our Product, Security, Compliance, Engineering, and Sales to deliver clear guidance, supporting privacy assessments, and review customer and vendor agreements to help us move quickly and responsibly as we grow. This is an individual contributor role ideal for a privacy lawyer who enjoys hands-on work, cross-functional collaboration, and applying structured legal thinking to emerging technologies.
What You Will Do
- Apply an AI-First approach by using AI tools responsibly to improve research quality, drafting efficiency, and privacy assessment workflows.
- Demonstrate Change Agility by adapting quickly to evolving global privacy and AI regulations, adjusting guidance as new risks, tools, or requirements emerge.
- Use First Principles Problem Solving to simplify complex privacy questions, clarify assumptions, and provide clear, structured recommendations.
- Leverage Data-Driven Decision Making during DPIAs, and related assessments by grounding evaluations in evidence, criteria, and regulatory expectations.
- Support the current Privacy function with global privacy assessments, including DPIAs, AI DPIAs, TIAs, LIAs, and other structured risk reviews.
- Review new and existing product features, AI capabilities, and data practices as part of privacy-by-design, identifying risks and opportunities early in development.
- Draft, review, and negotiate data processing agreements (DPAs), privacy terms, and commercial contracts to support global sales and procurement.
- Maintain and update privacy contractual documentation and internal templates and policies.
- Create and deliver internal training on privacy and AI governance.
- As part of the Privacy function, support internal and external privacy audits, coordinate with external advisors, and ensure alignment across business functions on assessment findings and remediation.
- Monitor evolving privacy laws, case law, AI governance frameworks, and regulatory trends, sharing key insights with stakeholders to maintain compliance and anticipate future requirements.
Minimum Qualifications
- Qualified lawyer (UK or EU) with GDPR experience PQE 5+ years (mix of in-house or private practice experience).
- Strong knowledge of EU/UK GDPR and familiarity with global privacy laws (US, Middle East, Asia).
- Experience drafting and negotiating data processing agreements and handling privacy-related issues in a global business context.
- Proven ability to manage data breaches, regulatory notifications and privacy audits.
- Excellent communication skills with the ability to simplify complex legal concepts for non-legal audiences.
- Strong understanding of AI technologies, their ethical implications, and related legal frameworks.
- Excellent analytical, problem-solving, and decision-making skills with the ability to provide practical and strategic legal advice.
- Experience in using privacy management systems such as OneTrust is required.
- Ability to manage multiple priorities and work collaboratively across diverse teams.
- Comfortable working independently in a fast-paced, global environment.
Preferred Qualifications
- Certified Information Privacy Professional (CIPP) Artificial Intelligence Governance Professional (AIGP) and other relevant certifications.
- German language proficiency.
- Experience in cybersecurity, offensive security, or SaaS environments.
Compensation Band
UK Tier: £80K – £100K Offers Equity
Job Benefits
- Health (medical, vision, dental), life, and disability insurance.
- Equity stock options.
- Retirement plans.
- Paid public holidays and unlimited PTO.
- Paid maternity and parental leave.
- Leaves of absence (including caregiver leave and leave under CO's Healthy Families and Workplaces Act).
- Employee Assistance Program.
- Flexible Work Stipend.
Company Statement
We're committed to building a global team! For certain roles outside the United States, India, the U.K., and the Netherlands, we partner with Remote.com as our Employer of Record (EOR). Visa/work permit sponsorship is not available.
EEO Statement
HackerOne is an Equal Opportunity Employer in the terms and conditions of employment for all employees and job applicants without regard to race, color, religion, sex, sexual orientation, age, gender identity or gender expression, national origin, pregnancy, disability or veteran status, or any other protected characteristic as outlined by international, federal, state, or local laws. This policy applies to all HackerOne employment practices, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. HackerOne makes hiring decisions based solely on qualifications, merit, and business needs at the time.
Privacy Counsel employer: HackerOne
HackerOne is an exceptional employer, offering a dynamic and inclusive work culture that prioritises employee growth and collaboration. As a leader in the cybersecurity industry, employees benefit from competitive compensation, comprehensive health benefits, and unlimited PTO, all while working remotely from the UK. The company fosters innovation through its AI-first approach, empowering Privacy Counsel to engage in meaningful work that shapes the future of data protection and AI governance.
StudySmarter Expert Advice🤫
We think this is how you could land Privacy Counsel
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, attend events, and connect with people on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Prepare for interviews by researching HackerOne and its values. Understand their approach to privacy and AI governance, and think about how your experience aligns with their mission. This will help you stand out as a candidate who truly gets what they’re about.
✨Tip Number 3
Practice your responses to common interview questions, especially those related to privacy law and data protection. Use real-life examples from your experience to demonstrate your skills and knowledge. Confidence is key!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in being part of the HackerOne team.
We think you need these skills to ace Privacy Counsel
Some tips for your application 🫡
Tailor Your Application:Make sure to customise your CV and cover letter for the Privacy Counsel role. Highlight your experience with GDPR and any relevant privacy laws, as well as your understanding of AI technologies. We want to see how your skills align with our needs!
Showcase Your Problem-Solving Skills:In your application, give examples of how you've simplified complex legal concepts or navigated tricky privacy issues in the past. We love seeing candidates who can think critically and provide practical solutions, especially in a fast-paced environment like ours.
Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language to explain your qualifications and experiences. Remember, we appreciate good communication skills, so make sure your writing reflects that!
Apply Through Our Website:We encourage you to submit your application directly through our website. It’s the best way to ensure it gets into the right hands. Plus, it shows us you're keen on joining our team at HackerOne!
How to prepare for a job interview at HackerOne
✨Know Your Privacy Laws
Make sure you brush up on your knowledge of GDPR and other global privacy laws. HackerOne is looking for someone who can simplify complex legal concepts, so be prepared to discuss how these regulations impact their operations and how you can help navigate them.
✨Showcase Your AI Understanding
Since the role involves working with AI technologies, demonstrate your understanding of their ethical implications and legal frameworks. Be ready to discuss how you would apply an AI-first approach in your work and provide examples of how you've done this in the past.
✨Prepare for Practical Scenarios
Think about real-world scenarios where you've had to manage data breaches or conduct privacy audits. Prepare to share specific examples that highlight your problem-solving skills and ability to provide strategic legal advice in a fast-paced environment.
✨Emphasise Collaboration Skills
HackerOne values cross-functional collaboration, so be ready to talk about your experience working with diverse teams. Highlight instances where you've successfully partnered with product, security, or compliance teams to achieve common goals.