Postman07/07/2026

Специалист по коммерческому и правовому регулированию защиты данных

Salary not specified
San Francisco

Responsibilities

  • 01Serve as the primary legal resource for privacy questions arising in commercial transactions
  • 02Draft, review, and negotiate data processing agreements (DPAs), data protection addenda, and related privacy terms on both Postman paper and counterparty paper
  • 03Manage a high volume of customer and prospect privacy questionnaires, security questionnaires, and due diligence requests
  • 04Advise Sales, Deal Operations, and Partner teams on privacy-related deal issues
  • 05Monitor and interpret developments in global privacy law (GDPR, UK GDPR, CCPA/CPRA, and emerging frameworks)
  • 06Advise on Postman’s established international data transfer mechanisms
  • 07Maintain and update Postman's DPA templates, privacy-related contract clauses, and negotiation playbooks
  • 08Partner with Sr. Privacy Counsel, Product Counsel, and AI & Security Counsel to translate the privacy components of new products, features, and services into commercial terms and customer-facing documentation
  • 09Develop and maintain privacy-related FAQs, decision trees, and self-serve resources
  • 10Support enterprise and mid-market commercial transactions beyond privacy as capacity allows
  • 11Provide practical, commercially-minded counsel to internal stakeholders
  • 12Contribute to broader Legal team initiatives
  • 13Work daily with the Commercial Legal team on deal flow, escalations, and contracting strategy
  • 14Collaborate with the Compliance Legal team on privacy program matters that affect commercial terms

Requirements

  • 01J.D. from an accredited U.S. law school and admitted to the bar in at least one U.S. jurisdiction
  • 025-8 years of legal experience with a meaningful focus on data privacy and commercial transactions, including substantial in-house experience at a technology company
  • 03Deep working knowledge of GDPR, UK GDPR, CCPA/CPRA, and international data transfer mechanisms (SCCs, UK Addendum, transfer risk assessments)
  • 04Hands-on experience drafting and negotiating DPAs and data protection terms in the context of enterprise SaaS transactions
  • 05Experience managing high volumes of customer and prospect privacy questionnaires, security questionnaires, and due diligence requests