About the Job
Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assess...
We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, c...
We’re looking for a practical, business-minded Product & Privacy Counsel to join our Legal team and serve as a key legal partner across Horizon3.
Key Responsibilities
We’re looking for a practical, business-minded Product & Privacy Counsel to join our Legal team and serve as a key legal partner across Horizon3.
This role will have a balanced focus across product counseling and privacy, with meaningful ownership in both areas. You will partner closely with Product and Engineering throughout the product lifecycle, advising on new products, features, technologies, and regulatory requirements, while also helping operate and scale Horizon3’s global privacy program.
You will work cross-functionally with Product, Engineering, Security, Compliance, GTM, and Operations to translate complex legal and regulatory requirements into practical, scalable solutions that protect the business without creating unnecessary friction.
This role is ideal for an attorney who enjoys working directly with technical and business teams, can independently own matters, and is comfortable making practical, risk-based recommendations in a fast-moving cybersecurity environment.
Serve as a day-to-day legal partner to Product and Engineering on new products, features, integrations, and product changes.
Provide legal guidance throughout the product lifecycle, from early design and development through launch and ongoing operation.
Identify and advise on legal and regulatory considerations involving product functionality, data use, telemetry, logging, APIs, integrations, and emerging technologies.
Conduct legal reviews of new products and features and develop practical approaches to mitigate identified risks.
Advise on product terms, disclosures, customer-facing documentation, and other legal requirements associated with product launches.
Partner with Product, Engineering, Security, and Compliance to translate legal requirements into practical and scalable product controls.
Advise on the development, deployment, and use of AI and other emerging technologies, including applicable AI and technology regulation.
Develop scalable playbooks, guidance, and processes that help teams identify and address legal requirements earlier in the product development lifecycle.
Help operate and scale Horizon3's global privacy program.
Advise on global privacy and data protection requirements, including GDPR, UK GDPR, CCPA/CPRA, U.S. state privacy laws, and other emerging privacy regulations.
Embed privacy-by-design principles into products, systems, and business processes, including conducting and maintaining PIAs, DPIAs, and related assessments.
Advise on controller, processor, and subprocessor obligations and new or changing data processing activities.
Manage and advise on cross-border data transfer requirements, including Standard Contractual Clauses (SCCs), transfer impact assessments, the Data Privacy Framework, and other applicable transfer mechanisms.
Advise on data subject rights, retention and deletion, subprocessors, privacy notices, and related privacy operations.
Draft, review, negotiate, and maintain Data Processing Agreements (DPAs) and other privacy and data protection terms.
Maintain and enhance privacy policies, notices, internal guidance, and customer-facing privacy resources.
Partner with Security and Compliance on privacy incidents, regulatory requirements, audits, and customer diligence.
Monitor developments in global privacy law and translate changes into practical requirements for the business.
Partner with Legal, Product, Engineering, Security, Compliance, GTM, and Operations to resolve product and privacy matters efficiently.
Support enterprise customer negotiations and diligence involving product, privacy, data protection, and emerging technology issues.
Develop templates, playbooks, guidance, and self-service resources that allow the business to operate efficiently while maintaining appropriate legal guardrails.
Provide clear, practical advice that balances legal and regulatory requirements with product objectives, customer expectations, and business priorities.
Success in this role means becoming a trusted partner across both Product and Privacy—helping Product and Engineering identify and address legal requirements early, independently owning core elements of Horizon3.ai’s global privacy program, and providing practical solutions that allow the company to innovate and scale responsibly.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities, and activities may change at any time with or without notice.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Required Skills & Abilities
J.D. from an accredited law school and active membership in good standing with at least one U.S. state bar.
4+ years of relevant legal experience, with meaningful experience in both product/technology counseling and privacy or data protection
Experience advising SaaS, cybersecurity, software, or other technology businesses.
Strong working knowledge of:
GDPR and UK GDPR
CCPA/CPRA and U.S. state privacy laws
DPAs, SCCs, and cross-border data transfer mechanisms
Privacy-by-design principles and product privacy reviews
Experience partnering directly with Product and Engineering teams.
Ability to understand technical products, data flows, software architecture, APIs, and cloud-based services sufficiently to identify and advise on legal and privacy risks.
Strong legal judgment and the ability to provide practical, risk-based recommendations.
Strong drafting, written and verbal communication, and project-management skills.
Proven ability to independently manage multiple priorities in a fast-paced, high-growth environment.
In-house experience at a SaaS, cybersecurity, AI, cloud, or other high-growth technology company.
Experience advising on AI, machine learning, or emerging technology regulation.
Familiarity with the EU AI Act, EU Data Act, or cybersecurity regulatory frameworks.
Experience conducting PIAs, DPIAs, TIAs, or similar privacy and data protection assessments.
Familiarity with SOC 2, ISO 27001, or similar security and compliance frameworks.
Experience supporting enterprise customer privacy and technology negotiations.
CIPP/US, CIPP/E, CIPM, or similar privacy certification.
Qualifications
Experience:
4 years experience