Principal Attorney, Regulatory Compliance

CB&IThe Woodlands, TX
Onsite

About The Position

The Principal Regulatory Compliance Attorney is responsible for designing and implementing a comprehensive risk-based compliance framework; managing regulatory strategy and examinations; protecting data and privacy; and mitigating regulatory and compliance risk across our global organization. This position is an Individual Contributor role and is required to be in the office. The role directly reports to the Director, Legal – Litigation, Ethics, and Compliance.

Requirements

  • J.D., LL.M., or LL.B.
  • Licensed attorney in good standing in Texas or who qualifies to work as in-house counsel under Texas rules
  • 8-10 years of building and overseeing compliance programs and frameworks (preferably multi-jurisdictional experience)
  • 3-5 years of EU and UK regulatory compliance experience, including GDPR and EU data governance, data protection, and privacy
  • 3-5 years defending against regulatory inquiries, investigations, and enforcement and interacting with regulators and supervisory authorities (EU or UK experience preferred)
  • Strong functional knowledge and proven experience building and maintaining compliance frameworks and handling regulatory matters for a global or multijurisdictional organization or across multiple jurisdictions and borders
  • Functional knowledge and proven experience designing and maintaining EU/UK and GDPR compliance
  • Subject matter expertise on U.S., EU, and GDPR regulatory, compliance, privacy, and data protection regulations
  • Practical approach to regulatory compliance in operational environments
  • Ability to work autonomously and proactively without frequent supervision
  • Strategic thinker with strong analytical and problem-solving skills
  • Business presence, polish, and credibility with regulators, leadership, and colleagues
  • High emotional intelligence and interpersonal skills
  • Strong written and verbal communication and presentation skills
  • Fluent in English (speaking and writing).

Nice To Haves

  • Certified Information Privacy Professional (CIPP), Certified Compliance and Ethics Professional (CCEP), or Certified Regulatory Compliance Manager (CRCM)
  • Demonstrated experience supporting global companies with EU and GDPR compliance needs and handling complex regulatory compliance matters across multiple jurisdictions
  • Familiarity with ISO 27001, 27701, and NIST Privacy Framework
  • Experience with litigation and employment law
  • Spanish is a plus but not required.

Responsibilities

  • Help design, implement, and improve CB&I’s enterprise compliance program across multiple jurisdictions. This includes various responsibilities, such as: Create policies, procedures, and controls to confirm alignment with applicable laws, regulations, and industry standards; Provide oversight and collaboration on compliance matters intersecting with export controls, trade compliance, cross-border regulatory requirements, and third-party due diligence; and Conduct risk assessments, identify root causes, develop mitigation strategies, implement and manage correction actions; and track compliance and remediation efforts Support and help lead supply chain and trade and export compliance
  • Support and conduct confidential internal investigations. Draft investigation reports. Help manage the employee whistleblower hotline and metric reporting.
  • Serve as a primary contact for regulator, inspector, or supervisory communications. Help coordinate or lead productions, submissions, and responses to regulatory exams, audits, inquiries, remediation plans, incidents, or breaches.
  • Take responsibility for statutory updates and submissions.
  • Ensure alignment between regulatory requirements and internal policies and programs. Provide guidance on aligning operational controls and initiatives with regulatory requirements.
  • Help design, implement, and improve the company’s privacy framework and data protection program, ensuring alignment with GDPR principles, accountability requirements, and supervisory authority expectations.
  • Help draft and maintain GDPR-compliant privacy notices, polices, and procedures and conduct or assist with conducting periodic privacy monitoring and audits.
  • Advise on and potentially lead data protection impact assessments, privacy risk assessments, and privacy-related incident response, including breach assessments, notification obligations, and coordination with regulators and external counsel, as needed.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service