United States of America Remote (Country)

Airwallex is hiring a Lead Counsel, Data Privacy

Lead Counsel, Data Privacy will serve as the principal legal advisor for data protection, privacy, AI governance, and cybersecurity across the Americas. This position plays a central role in shaping and executing privacy strategy within a high-growth fintech environment, ensuring compliance with evolving financial and data privacy laws while enabling responsible innovation.

Key Responsibilities

  • Act as primary legal contact for data privacy and protection matters in the US, Canada, and South America, delivering practical, risk-informed guidance on cross-border data access, national security implications, and compliance with global frameworks.
  • Lead the development and implementation of AI governance policies, including risk assessments, accountability structures, and privacy-preserving measures aligned with emerging US and international standards.
  • Design and support execution of data privacy compliance programs across the Americas, with focus on US federal and state laws such as GLBA, FCRA, CalFIPA, Executive Order 14117, and state-level privacy regimes.
  • Collaborate with Product, Engineering, and Information Security teams to integrate privacy and security principles into product design, technical architecture, and customer experiences, including leading data protection impact assessments and AI risk evaluations.
  • Review and negotiate data-sharing agreements, data processing terms, and AI-related contractual provisions with third parties, including financial institutions, vendors, and enterprise clients.
  • Manage cross-border data transfer mechanisms, ensuring appropriate legal safeguards such as SCCs and equivalent instruments, and support data localization and access control initiatives.
  • Co-lead incident response for data or privacy breaches affecting the Americas, coordinating with security and compliance teams on investigation, regulatory reporting, customer notification, and remediation.
  • Advise on novel data processing activities, including advanced analytics, embedded finance models, and AI-driven features, to ensure appropriate safeguards and documentation.
  • Support engagements with US and regional regulators on privacy, data access, and cybersecurity topics in coordination with regulatory and compliance teams.
  • Develop and refine internal tools and workflows for privacy operations, including intake systems, risk assessments, record of processing activities, and data subject request management, using technology to improve efficiency and compliance tracking.
  • Deliver training and guidance to non-legal teams on privacy, data use, and AI risk, enabling teams to build compliance into everyday workflows.

Qualifications

  • Admitted to practice law in a US jurisdiction, with at least 8 years of legal experience in privacy, data protection, and technology law, either in private practice or in-house.
  • Deep understanding of US federal and state privacy laws—including CCPA/CPRA, GLBA, Reg P—and their application in financial services and payments, with working knowledge of GDPR, Canadian PIPEDA, and South American regimes such as Brazil’s LGPD.
  • Experience advising on consent management, adtech compliance, and operationalizing privacy controls under varying US state frameworks.
  • Proven ability to work with technical teams to translate legal requirements into product and system designs, controls, and processes.
  • Direct experience with AI-related legal and governance challenges, including vendor assessments, model deployment, and risk mitigation from a data protection standpoint.
  • Background supporting incident response, including breach assessment, notification obligations, and remediation planning.
  • Strong communication skills, with the ability to explain complex legal issues clearly to technical and executive audiences and drive decisions under pressure.
  • Demonstrated ownership, adaptability, and practical judgment in fast-moving environments, particularly within fintech or scalable technology organizations.

Preferred Experience

  • Legal support in financial services, payments, or fintech, particularly involving US financial privacy rules and data access policies with national security implications.
  • Interaction with regulators on privacy, cybersecurity, or AI matters, including examinations, enforcement, or policy discussions.
  • Contribution to global privacy programs, including DPO-like responsibilities or development of regional compliance playbooks.
  • Privacy or AI certifications such as CIPP/US, CIPP/E, CIPM, or AIGP, or equivalent experience in global compliance program design.
  • Experience in a high-growth tech or fintech company with distributed teams across time zones.
Required Skills
Cross-functional Collaboration
About company
Airwallex
Airwallex is a unified payments and financial platform for global businesses, offering integrated solutions for business accounts, payments, spend management, treasury, and embedded finance. It supports over 200,000 businesses worldwide using proprietary infrastructure and software.
All jobs at Airwallex Visit website
Job Details
Category other
Posted 3 months ago