Senior Director, Privacy, Security & Data Compliance

Snowflake Snowflake · Data AI · CA-Menlo Park, United States · Legal

This role leads the privacy, security, and data compliance teams, focusing on AI governance and compliance with global regulations like GDPR, CCPA, and the EU AI Act. It involves advising on AI/ML data usage, managing compliance frameworks (SOC 1/2, ISO 27001, ISO 42001, HIPAA, HITRUST, FedRAMP), and supporting public sector security programs. The role requires expert knowledge of regulatory frameworks and strategic risk management in AI.

What you'd actually do

  1. Oversee the operation of our global privacy program, which covers compliance with GDPR, CCPA/CPRA, China’s PIPL/DSL, and other global privacy laws.
  2. Work with the Product Legal, Product, Engineering, and Compliance teams to ensure data compliance requirements are baked into the development lifecycle.
  3. Manage a team of privacy and security negotiating specialists, who provide enablement to the broader Commercial Legal and Procurement teams and act as direct negotiators for complex deals.
  4. Lead the legal response to security incidents, vulnerabilities, and customer-impacting product bugs.
  5. Ensure team is functioning as the subject matter experts for evolving AI, security, privacy, and other data laws and provide practical advice to both product and corporate execution teams.

Skills

Required

  • Privacy law
  • Security law
  • Data compliance
  • Legal leadership
  • SaaS/Cloud Infrastructure legal experience
  • Regulatory expertise (GDPR, EU AI Act, NIST AI RMF)
  • Risk management
  • Cross-functional collaboration
  • Legal counseling on AI/ML data usage
  • Public sector compliance
  • Incident response

Nice to have

  • Experience in a global, high-growth enterprise SaaS or Cloud Infrastructure environment
  • Experience leading "AI Task Forces" or "Ethics Boards"

What the JD emphasized

  • Expert-level knowledge of key regulatory frameworks including GDPR, the EU AI Act, and NIST AI Risk Management Framework.
  • Ability to provide clear-eyed legal guidance on the "gray areas" of AI, such as copyright in training data, deepfake prevention, and automated profiling.