Product & Privacy Counsel

Horizon3
$139,000 - $163,000Remote

About The Position

Horizon3 is a fast-growing, remote cybersecurity company dedicated to the mission of enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. Our flagship product, the NodeZeroTM platform, delivers production-safe autonomous pentests and other key assessment operations that scale across the largest internal, external, cloud, and hybrid cloud environments. NodeZero has been adopted by organizations of all sizes, from small educational institutions to government agencies and Global 100 enterprises. It is used by ITOps/SecOps teams, consulting pentesters, and MSSPs and MSPs. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants. Collectively, we are a team of learn it alls, committed to a culture of respect, collaboration, ownership, and results. We’re looking for a practical, business-minded Product & Privacy Counsel to join our Legal team and serve as a key legal partner across Horizon3. This role will have a balanced focus across product counseling and privacy, with meaningful ownership in both areas. You will partner closely with Product and Engineering throughout the product lifecycle, advising on new products, features, technologies, and regulatory requirements, while also helping operate and scale Horizon3’s global privacy program. You will work cross-functionally with Product, Engineering, Security, Compliance, GTM, and Operations to translate complex legal and regulatory requirements into practical, scalable solutions that protect the business without creating unnecessary friction. This role is ideal for an attorney who enjoys working directly with technical and business teams, can independently own matters, and is comfortable making practical, risk-based recommendations in a fast-moving cybersecurity environment.

Requirements

  • J.D. from an accredited law school and active membership in good standing with at least one U.S. state bar.
  • 4+ years of relevant legal experience, with meaningful experience in both product/technology counseling and privacy or data protection
  • Experience advising SaaS, cybersecurity, software, or other technology businesses.
  • Strong working knowledge of: GDPR and UK GDPR
  • CCPA/CPRA and U.S. state privacy laws
  • DPAs, SCCs, and cross-border data transfer mechanisms
  • Privacy-by-design principles and product privacy reviews
  • Experience partnering directly with Product and Engineering teams.
  • Ability to understand technical products, data flows, software architecture, APIs, and cloud-based services sufficiently to identify and advise on legal and privacy risks.
  • Strong legal judgment and the ability to provide practical, risk-based recommendations.
  • Strong drafting, written and verbal communication, and project-management skills.
  • Proven ability to independently manage multiple priorities in a fast-paced, high-growth environment.

Nice To Haves

  • In-house experience at a SaaS, cybersecurity, AI, cloud, or other high-growth technology company.
  • Experience advising on AI, machine learning, or emerging technology regulation.
  • Familiarity with the EU AI Act, EU Data Act, or cybersecurity regulatory frameworks.
  • Experience conducting PIAs, DPIAs, TIAs, or similar privacy and data protection assessments.
  • Familiarity with SOC 2, ISO 27001, or similar security and compliance frameworks.
  • Experience supporting enterprise customer privacy and technology negotiations.
  • CIPP/US, CIPP/E, CIPM, or similar privacy certification.

Responsibilities

  • Serve as a day-to-day legal partner to Product and Engineering on new products, features, integrations, and product changes.
  • Provide legal guidance throughout the product lifecycle, from early design and development through launch and ongoing operation.
  • Identify and advise on legal and regulatory considerations involving product functionality, data use, telemetry, logging, APIs, integrations, and emerging technologies.
  • Conduct legal reviews of new products and features and develop practical approaches to mitigate identified risks.
  • Advise on product terms, disclosures, customer-facing documentation, and other legal requirements associated with product launches.
  • Partner with Product, Engineering, Security, and Compliance to translate legal requirements into practical and scalable product controls.
  • Advise on the development, deployment, and use of AI and other emerging technologies, including applicable AI and technology regulation.
  • Develop scalable playbooks, guidance, and processes that help teams identify and address legal requirements earlier in the product development lifecycle.
  • Help operate and scale Horizon3's global privacy program.
  • Advise on global privacy and data protection requirements, including GDPR, UK GDPR, CCPA/CPRA, U.S. state privacy laws, and other emerging privacy regulations.
  • Embed privacy-by-design principles into products, systems, and business processes, including conducting and maintaining PIAs, DPIAs, and related assessments.
  • Advise on controller, processor, and subprocessor obligations and new or changing data processing activities.
  • Manage and advise on cross-border data transfer requirements, including Standard Contractual Clauses (SCCs), transfer impact assessments, the Data Privacy Framework, and other applicable transfer mechanisms.
  • Advise on data subject rights, retention and deletion, subprocessors, privacy notices, and related privacy operations.
  • Draft, review, negotiate, and maintain Data Processing Agreements (DPAs) and other privacy and data protection terms.
  • Maintain and enhance privacy policies, notices, internal guidance, and customer-facing privacy resources.
  • Partner with Security and Compliance on privacy incidents, regulatory requirements, audits, and customer diligence.
  • Monitor developments in global privacy law and translate changes into practical requirements for the business.
  • Partner with Legal, Product, Engineering, Security, Compliance, GTM, and Operations to resolve product and privacy matters efficiently.
  • Support enterprise customer negotiations and diligence involving product, privacy, data protection, and emerging technology issues.
  • Develop templates, playbooks, guidance, and self-service resources that allow the business to operate efficiently while maintaining appropriate legal guardrails.
  • Provide clear, practical advice that balances legal and regulatory requirements with product objectives, customer expectations, and business priorities.

Benefits

  • health, vision & dental insurance for you and your family
  • a flexible vacation policy
  • generous parental leave
  • competitive salary, equity and benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service