Compliance & Regulatory Counsel
Position Summary
The Compliance and Regulatory Counsel will act as a key legal partner to deliver and scale critical legal support to a growing global hi-tech SaaS company serving customers that include multi-national enterprises and public sector entities. This role will support the compliance and regulatory function at ExtraHop, advising on laws and regulations directly impacting our business as a SaaS provider, as well as the frameworks governing our enterprise customers. This role supports the corporate and sales compliance function by ensuring accurate and timely filings of various business and regulatory registrations for all jurisdictions in which ExtraHop operates, maintaining the internal database of such filings, staying ahead of legal and regulatory changes and updates and developing internal project roadmaps to ensure timely compliance, and administering compliance programs across multiple legal and risk frameworks.
This role partners with Information Security, Privacy, IT, HR, Finance, Product, and other subject matter experts to develop best practices to understand and advise the business on the legal and regulatory risk technical, security, privacy, and operational information into clear, customer-facing responses.
This is an excellent opportunity for a junior- to mid-level attorney with at least 5 years of experience to gain deep, cross-functional exposure to international technology regulations, product/hardware compliance, and cutting-edge AI and privacy governance under the supervision of the Deputy General Counsel and senior legal leadership.
The ideal candidate combines strong project and stakeholder management skills with a working knowledge of cybersecurity, privacy, compliance frameworks, and enterprise SaaS environments. This role requires the ability to manage competing priorities, exercise sound judgment on complex requests, identify appropriate resources, and continuously improve the processes, tools, and knowledge resources that support the sales organization.
Key Responsibilities
Regulatory Guidance & Cross-Functional Partnership
Research and advise on complex global regulatory and compliance frameworks affecting ExtraHop as a B2B SaaS provider to enterprise clients.
Guide responses for security questionnaires, TPRM assessments, RFIs, RFPs, and high-priority customer due diligence requests.
Translate complex technical, security, and legal information into clear, customer-facing documentation.
Data Privacy & AI Governance
Partner closely with Sales, Finance, Procurement, and InfoSec teams to manage regulatory, privacy (GDPR/CCPA), and AI data protection risks.
Draft and update critical data privacy agreements (DPAs) and standard contractual clauses (SCCs).
Support AI Governance initiatives to ensure ethical and legally sound product deployment.
Coordinate and execute corporate governance programs, including facilitating annual Employment/EE compliance training and collecting data for global ESG annual reporting.
Serve as a legal stakeholder for independent audits, assisting with readiness and documentation gathering for annual SOC 2 audits, supporting the preparation and distribution of compliance documentation, certifications, attestations, policies, and other customer-facing materials.
Maintain and oversee standardized responses and supporting documentation for common privacy, and compliance requirements.
Draft and update critical data protection documentation, including Data Privacy Agreements (DPAs) and standard contractual clauses (SCCs).
Support hardware compliance efforts, including the company’s export control framework and the tracking of and regulatory reporting for environmental supply chain standards.
Identify inconsistencies, gaps, or outdated information in customer-facing compliance materials and coordinate updates with the appropriate subject matter experts.
Support the implementation of AI Governance frameworks to ensure the ethical, compliant, and legally sound deployment of artificial intelligence capabilities within our products.
Compliance, Audit & Legal Operations
Serve as primary legal contact for independent audits, including SOC 2 readiness, policy drafting, and evidence collection.
Manage corporate governance tasks, including annual compliance training, global ESG data collection, and export/hardware compliance reporting.
Maintain knowledge bases, response libraries, templates, and documentation repositories to increase self-service and improve response efficiency.
Support annual corporate insurance review and renewal process, gathering underwriting data across departments (Cyber, D&O, General Liability).
Provide ad hoc support on commercial litigation matters, managing document holds, discovery requests, and coordinating logistics with external counsel.
Assist with commercial litigation needs, including discovery requests and legal holds.
Key Qualifications
Required:
Education & Bar: J.D. or LL.M. with active US state bar membership in good standing.
Experience: 5+ years of legal practice with expertise in regulatory compliance, data privacy, cloud/SaaS transactions, and third-party risk management.
Regulatory Knowledge: Working knowledge of foundational tech and privacy regulations (e.g., GLBA, FERPA, GDPR/US privacy laws) and a strong interest in emerging frameworks like the EU AI Act and DORA.
Project Management: Proven ability to manage multi-stakeholder workflows, prioritize high-volume deliverables, and operate effectively under tight deadlines.
Preferred:
Experience supporting B2B SaaS, cybersecurity, or technology organizations.
Professional Privacy Certification (e.g., CIPP/US or CIPP/E).
Experience with third-party risk management platforms (TPRM) and regulatory filing platforms such as SAM.gov.
Core Competencies
Compliance & Security Acumen – Applies practical knowledge of security, privacy, compliance, and risk requirements to business situations.
Cross-Functional Collaboration – Coordinates diverse stakeholders and creates accountability for timely and accurate project milestones.
Judgment & Prioritization – Distinguishes routine requests from complex or high-risk matters and engages the appropriate subject matter experts.
Process & Operational Excellence – Builds scalable processes, improves workflows, and identifies opportunities for automation and self-service legal processes.
The salary for this role is between $150,000 - $163,000 per year + bonus