Counsel - Privacy, Security & AI Office Job at Harness, Kingdom of Spain

N09SR2ZNazYxQm5HbC9pWWNHYmhDanFkRmc9PQ==
  • Harness
  • Kingdom of Spain

Job Description

Harness is a high-growth company that is disrupting the software delivery market. Our mission is to enable the 30 million software developers in the world to deliver code to their users reliably, efficiently, securely and quickly, increasing customers’ pace of innovation while improving the developer experience. We offer solutions for every step of the software delivery lifecycle to build, test, secure, deploy and manage reliability, feature flags and cloud costs. The Harness Software Delivery Platform includes modules for CI, CD, Cloud Cost Management, Feature Flags, Service Reliability Management, Security Testing Orchestration, Chaos Engineering, Software Engineering Insights and continues to expand at an incredibly fast pace.

Harness is led by technologist and entrepreneur Jyoti Bansal, who founded AppDynamics and sold it to Cisco for $3.7B. We’re backed with $425M in venture financing from top-tier VC and strategic firms, including J.P. Morgan, Capital One Ventures, Citi Ventures, ServiceNow, Splunk Ventures, Norwest Venture Partners, Adage Capital Partners, Balyasny Asset Management, Gaingels, Harmonic Growth Partners, Menlo Ventures, IVP, Unusual Ventures, GV (formerly Google Ventures), Alkeon Capital, Battery Ventures, Sorenson Capital, Thomvest Ventures and Silicon Valley Bank.

About the Role

We are seeking an experienced and strategic Counsel to join our Privacy, Security & AI (“PSAI”) Office . In this -l role, you will play a critical part in guiding our product and AI compliance, supporting global privacy and data protection strategy, and helping shape the company’s approach to responsible and ethical data use.

You’ll advise senior leadership, collaborate with cross-functional stakeholders, and help ensure that our data practices are aligned with global legal and regulatory obligations, including those emerging around AI governance and advanced technologies.

Key Responsibilities

AI

  • Support the development and implementation of the AI Governance Program
  • Draft and implement AI policies, procedures, and best practices for both internal use of AI and product development
  • Lead internal awareness campaigns to foster a culture of responsible AI across the organization.
  • Support AI Use Case Intake Assessments
  • Provide AI advice to key stakeholders (product, procurement)
  • Support customers queries and questionnaires

Product Compliance

  • Collaborate closely with product and engineering teams to evaluate and mitigate privacy and AI compliance risks during development and deployment.
  • Review and assess AI/ML use cases for compliance with legal and ethical standards, including EU AI Act , OECD AI Principles , and NIST AI RMF .
  • Contribute to development of governance frameworks for responsible AI , including fairness, explainability, and accountability controls.

Privacy & Data Protection Legal Strategy

  • Lead complex legal analysis and provide strategic privacy advice on global data protection laws (e.g., GDPR , CCPA/CPRA , LGPD , PIPEDA , APPI ), with a main focus on US federal and state privacy and EU GDPR
  • Guide business and technical teams on lawful bases for processing , purpose limitation, transparency, and data minimization.
  • Evaluate and advise on complex personal data use cases , including sensitive data, automated decision-making, and biometric processing.
  • Implement best practices around privacy to ensure the competitive edge of the company
  • Draft and review breach-related communications, including regulator and data subject notices.
  • Conduct privacy reviews for third-party vendors and tools to ensure alignment with internal standards and legal requirements.
  • Drive the development, maintenance, and enhancement of the company’s privacy compliance program .
  • Maintain and oversee updates to the Records of Processing Activities (ROPA) , and ensure accountability documentation is current and complete.
  • Partner with security, compliance, and product teams to integrate privacy by design into internal processes and external-facing technologies.
  • Lead and advise on complex Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs) .
  • Oversee and conduct Transfer Impact Assessments (TIAs) to assess and document data transfer risks.
  • Manage Legitimate Interests Assessments (LIAs) and ensure robust justification and safeguards are in place.
  • Identify privacy and AI-related risks and recommend scalable mitigation strategies across the organization.

Audits, Monitoring & Regulatory Readiness

  • Support or lead the legal function in responding to privacy audits, regulator inquiries, and due diligence requests .
  • Prepare documentation, gap analyses, and remediation plans to ensure audit readiness.
  • Track and interpret global privacy and AI regulatory developments , and support internal implementation efforts.

Qualifications

Required:

  • Qualified lawyer (active bar membership in at least one jurisdiction).
  • 6–10+ years of legal experience, with a focus on privacy, data protection, and technology law .
  • Deep understanding of GDPR, CCPA/CPRA, and global privacy frameworks.
  • Preferred experience with FedRamp, PCI DSS and ISO frameworks
  • Extensive experience with PIAs/DPIAs, TIAs, LIAs, and cross-border data transfer mechanisms.
  • Strong understanding of privacy issues in product development, data science, and AI applications.

Preferred:

  • CIPP/E, CIPP/US and AIGP
  • Direct experience working with or interpreting AI legal and regulatory frameworks (e.g., EU AI Act).
  • Strong negotiation skills, particularly in data protection clauses and international data transfer agreements.

Harness in the news:

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex or national origin.

Note on Fraudulent Recruiting/Offers

We have become aware that there may be fraudulent recruiting attempts being made by people posing as representatives of Harness. These scams may involve fake job postings, unsolicited emails, or messages claiming to be from our recruiters or hiring managers.

Please note, we do not ask for sensitive or financial information via chat, text, or social media, and any email communications will come from the domain @harness.io. Additionally, Harness will never ask for any payment, fee to be paid, or purchases to be made by a job applicant. All applicants are encouraged to apply directly to our open jobs via our website. Interviews are generally conducted via Zoom video conference unless the candidate requests other accommodations.

If you believe that you have been the target of an interview/offer scam by someone posing as a representative of Harness, please do not provide any personal or financial information and contact us immediately at [email protected] . You can also find additional information about this type of scam and report any fraudulent employment offers via the Federal Trade Commission’s website ( , or you can contact your local law enforcement agency.

Job Tags

Work at office, Local area, Immediate start,

Similar Jobs

Nordstrom

Part-Time Beauty Sales - MAC - Pentagon City Job at Nordstrom

Part-Time Beauty Sales - MAC - Pentagon CityJob DescriptionJob DescriptionIn the Nordstrom Beauty Department, we strive to make our customers feel their best. As a member of the Nordstrom Beauty community, you'll create personalized beauty experiences for customers and... 

Compass Group

UNITED CLUB ATTENDANT O'HARE (FULL TIME) Job at Compass Group

 ...Person Hiring Event with On-the-spot offers! Date & Time: July 30, 2025 from 9:00 AM - 2:00 PM Location: O'Hare Airport, United Airlines Terminal 2 Baggage Claim. (The main parking garage and CTA blue line will leave you directly terminal 2 baggage claim.)... 

Peraton

Cyber Security Engineer Job at Peraton

 ...other elements or systems to perform a function as part of a larger, more complex system. The GCC operates, monitors, sustains, and secures Enterprise directed systems throughout the GCC AOR and internal services. Sensor Operation and Management. The GCC uses network... 

Autodesk

Software Engineer - New Grad 2025 Job at Autodesk

 ...Position Overview**Autodesk's Platform team is looking for a Software Engineer to join our organization that comprises of cloud services and...  ...**Preferred Qualifications**+ Willing to continuously learn new technologies and driven to adopt best practices+ Experience with... 

CRH

Ready Mix Concrete Truck Driver Job at CRH

 ...largest aggregates producer, and one of the top 5 ready mixed concrete producers in the United States. CRH Americas operates with...  ...of a large enterprise. SUMMARY The Mixer Driver will drive a truck equipped with an auxiliary concrete mixer and deliver concrete...