Privacy Counsel

EVERSANA - Chicago, IL

Hiring: Privacy Counsel Company: EVERSANA Location: Chicago, IL Job Posted Time: 2026-09-10 14:08:02 Employment Type: Remote Target Skills & Keywords : Agile, GDPR, HIPAA About the job Experience: •2-4 years of experience practicing law with a focus on data privacy, cybersecurity, technology law, or healthcare regulatory matters, including Corporate experience (preferred) or prior in-house experience (a plus) or substantial experience advising corporate clients. •4 years of experience practicing law with a focus on data privacy, cybersecurity, technology law, or healthcare regulatory matters, including Corporate experience (preferred) or prior in-house experience (a plus) or substantial experience advising corporate clients. Required Skills: •Advise internal business teams on compliance with U.S. federal and state privacy laws (e.g., CCPA/CPRA, HIPAA, GLBA) and international frameworks (e.g., GDPR, UK GDPR), with a particular focus on laws and guidance relevant to health science services and sensitive health-related information. •Draft, review, and negotiate privacy-related agreements, including data processing addenda, vendor agreements, customer agreements, business associate agreements, and cross-border data transfer arrangements. •Develop and implement privacy policies, notices, consent management strategies, and internal governance frameworks tailored to a health science services environment. •Guide internal stakeholders through incident response, including breach notification requirements, escalation procedures, risk assessments, and regulatory reporting. •Conduct privacy impact assessments (PIAs) and data protection impact assessments (DPIAs) for new products, services, systems, and data uses. •Monitor legislative developments and advise on emerging privacy trends, technologies, and enforcement actions affecting the company’s operations. •Collaborate closely with cross-functional teams—including IT, security, compliance, marketing, product, operations, and research-focused teams—to embed privacy into business operations. •Provide practical, risk-based legal advice to internal clients on the collection, use, sharing, retention, and de-identification of personal and health-related information. Qualifications: •The requirements listed below are representative of the experience, education, knowledge, skill and/or abilities required. •Juris Doctor (JD) from an accredited law school and active bar membership in at least one U.S. jurisdiction. •Demonstrated operational experience in data privacy programs, including direct involvement in real-world implementations and support of business operations •Proven ability to manage and respond to data privacy incidents (e.g., data breaches, unauthorized disclosures), including risk assessment, legal analysis, and coordination with cross-functional teams •Strong working knowledge of major privacy laws and regulatory frameworks (GDPR, CCPA/CPRA, HIPAA, and similar laws). •Operational familiarity with privacy technologies, data governance tools (OneTrust TrustArc, Osano), and operational privacy compliance processes. •Data privacy certifications such as CIPM, CIPP/E, or AIGP are a plus. •Exceptional research, analytical, and communication skills—able to translate complex legal concepts into clear, actionable guidance for business stakeholders. •A proactive, solutions-oriented mindset with the ability to balance legal risk and business objectives in a fast-paced, fully remote environment. •Physical/Mental Demands And Working Environment Compensation: •$103,515 - $145,230 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!