Senior Corporate Counsel, Privacy (hybrid, Seattle)

Nordstrom Nordstrom · Retail · Seattle, WA

Senior Corporate Counsel specializing in U.S. data privacy law, AI governance, and data security for a major retailer. Advises on AI legislation, develops AI governance frameworks, and ensures compliance with privacy and data security regulations.

What you'd actually do

  1. Serve as the primary legal advisor on U.S. state privacy laws, including CCPA/CPRA, and the growing patchwork of state comprehensive privacy statutes (Virginia, Texas, Colorado, etc.)
  2. Lead and maintain the company's U.S. privacy compliance program, including privacy notices, consent mechanisms, opt-out frameworks, and data subject rights processes
  3. Monitor and assess emerging AI legislation, regulatory guidance, and enforcement trends across federal, state, and international jurisdictions, and advise on their practical implications for Nordstrom’s use of AI and automated decision-making
  4. Develop and implement the company's AI governance framework, including policies for responsible AI use, vendor AI due diligence, and internal AI deployment standards
  5. Provide legal support for the company's data security program, including review of security policies, vendor contracts, and data processing agreements

Skills

Required

  • J.D. with a license to practice law in Washington State
  • 7-10 years of legal experience with a meaningful focus on U.S. privacy law
  • Experience in privacy law, including working with CAN-SPAM, TCPA, behavioral advertising, GLBA, HIPAA, PIPEDA, comprehensive U.S. state privacy laws such as CCPA/CPRA
  • Familiarity with AI governance frameworks and applicable AI laws and regulations, including state automated decision-making laws, the EU AI Act, and FTC guidance on algorithmic transparency and fairness
  • Experience advising on data security incidents and breach notification obligations
  • Proven ability to translate complex legal requirements into practical, business-friendly guidance
  • Strong drafting skills for policies, contracts, and legal summaries
  • Ability to successfully navigate quickly changing priorities, ambiguity, and the unexpected with a positive attitude
  • Comfort operating in a rapidly evolving AI regulatory landscape, with the ability to provide timely, practical guidance as new laws and enforcement priorities emerge
  • IAPP Certified Information Privacy Professional / United States (CIPP/US)

Nice to have

  • Familiarity with emerging state-level and GDPR privacy laws strongly preferred, including the Washington My Health My Data Act and similar consumer health data legislation
  • IAPP AI Governance Professional (AIGP) certification or equivalent
  • Prior in-house experience at a retailer, e-commerce company, or consumer-facing enterprise
  • Familiarity with adtech, loyalty program data practices, and consumer data monetization
  • Experience with AI vendor due diligence and negotiating AI-specific contract provisions
  • Exposure to FTC enforcement actions, state AG investigations, or privacy litigation

What the JD emphasized

  • U.S. data privacy law
  • artificial intelligence governance
  • data security
  • AI governance frameworks
  • applicable AI laws and regulations
  • AI regulatory landscape