AI Governance & Data Privacy General Counsel

Honeywell Honeywell · Industrial · Charlotte, NC +1

Seeking an experienced General Counsel to lead AI governance and data privacy strategy, providing regulatory guidance for AI products and operations within a highly regulated environment. This role involves shaping policies, advising on compliance, managing risk, and partnering with various teams to enable responsible AI adoption.

What you'd actually do

  1. Lead and execute Honeywell’s AI governance and legal strategy, maintaining and operationalizing Honeywell’s scalable Responsible AI Governance Framework to enable growth and innovation while managing risk.
  2. Develop, maintain, and advise on the implementation of AI governance policies, standards, and processes under applicable regulations, including algorithmic accountability, model validation, bias testing, human-in/on-the-loop requirements, monitoring, testing, inventory management, and decommissioning of AI systems.
  3. Serve as the primary legal advisor for global privacy and data protection for one or more Honeywell business units, including interpretation and implementation of applicable laws and frameworks (e.g., GDPR, CCPA/CPRA, LGPD, PIPL, cross-border transfer laws, sectoral and state privacy laws).
  4. Lead and advise on Data Protection Impact Assessments (DPIAs), risk assessments, and other privacy reviews for new products, AI use cases, and third-party tools; drive remediation plans and document risk acceptance where appropriate.
  5. Provide legal oversight of AI marketing and external capability claims to ensure accuracy, consistency, and avoidance of misleading statements or “AI washing.”

Skills

Required

  • 10+ years of relevant legal experience, including significant experience advising on AI, privacy/data protection, and technology matters.
  • J.D. (or equivalent) and admitted to practice law in a jurisdiction in the United States.
  • Established thought leader on AI law and governance, data privacy, and complex technology regulatory risk areas, with a demonstrated ability to influence at the senior leadership level.
  • Deep working knowledge of global AI, data privacy, and data protection regulations.
  • Proficiency partnering with technical teams on security and resilience, accuracy and robustness evaluation, bias and fairness assessment, explainability and transparency practices, and appropriate governance processes and artifacts.
  • Ability to define success criteria using KPIs, dashboards, and risk heat maps to assess risk and propose effective mitigation strategies.
  • Strong contracting capability for AI and data, including drafting and negotiating AI- and privacy-specific terms (data use restrictions, audit rights, security requirements, IP, and allocation of AI-related risk).
  • Incident response and regulatory engagement experience for AI- and privacy-related events, including investigations, audits, and interactions with regulators globally.

Nice to have

  • AI literacy initiatives
  • enterprise-wide and function-specific training and awareness campaigns
  • Support AI-related incident response and escalation, coordinating with legal, cybersecurity, engineering, HR, and communications teams.
  • Support litigation involving AI technologies.
  • Serve as Honeywell’s principal legal representative in external forums, including engagement with industry groups and standards bodies.
  • Partner with cybersecurity and incident response teams on privacy incidents and data breaches, including regulatory notification analysis, communications strategy, and post-incident corrective actions.
  • Oversee privacy compliance for marketing, digital analytics, and customer engagement activities (e.g., cookies/trackers, consent management, targeted advertising considerations, and privacy notices).
  • Advise on data subject rights workflows and internal operating procedures; support audits and regulator inquiries; and manage outside counsel as needed.
  • Develop and deliver privacy training and awareness for business and technical stakeholders; help embed privacy requirements into product lifecycle and procurement processes.

What the JD emphasized

  • AI Governance
  • Data Privacy
  • regulatory risk
  • highly regulated environments
  • global practical risk-based guidance
  • AI governance policies
  • algorithmic accountability
  • model validation
  • bias testing
  • human-in/on-the-loop requirements
  • data governance for AI/ML systems
  • privacy-enhancing techniques
  • AI contracting
  • third-party diligence
  • AI risk considerations
  • AI-related incident response
  • global privacy and data protection
  • GDPR
  • CCPA/CPRA
  • LGPD
  • PIPL
  • cross-border transfer laws
  • Data Protection Impact Assessments (DPIAs)
  • privacy incidents
  • data breaches
  • AI law and governance
  • data privacy
  • complex technology regulatory risk
  • bias and fairness assessment
  • explainability and transparency practices
  • AI- and privacy-specific terms
  • AI- and privacy-related events