Compliance & Regulatory Counsel

Posted 13 Hours Ago
Be an Early Applicant
Hiring Remotely in USA
Remote or Hybrid
150K-163K Annually
Senior level
Big Data • Cloud • Security • Software • Cybersecurity
ExtraHop provides cybersecurity for hybrid and cloud businesses.
The Role
Provides legal guidance on global regulatory compliance, privacy, AI governance, cybersecurity, SaaS transactions, third-party risk, audits, export controls, and corporate governance. Advises cross-functional teams, supports customer security and privacy due diligence, drafts DPAs and SCCs, manages compliance documentation and regulatory filings, assists with SOC 2 readiness, and supports litigation discovery and legal holds.
Summary Generated by Built In

At ExtraHop, we’re on a mission to protect and empower the connected enterprise. We reveal what is happening in the very infrastructure that sustains businesses, lives, and communities, and ensure the integrity of networks, data, systems, and processes. Organizations rely on ExtraHop to provide visibility into the cyber threats, vulnerabilities, and network performance issues that evade their existing security and IT tools. With this insight, organizations can investigate smarter, stop threats faster, and keep operations running.

Our mission is fueled by a profound social and moral responsibility to be the best at what we do, ensuring a secure world where everyone can thrive. If this sounds like a place you’d like to spend the next chapter of your career, we’d love to hear from you. 

Position Summary

The  Compliance and Regulatory Counsel will act as a key legal partner to deliver and scale critical legal support to a growing global hi-tech SaaS company serving customers that include multi-national enterprises and public sector entities.  This role will support the compliance and regulatory function at ExtraHop,  advising on laws and regulations directly impacting our business as a SaaS provider, as well as the frameworks governing our enterprise customers. This role  supports the corporate and sales compliance function by ensuring accurate and timely filings of various business and regulatory registrations for all jurisdictions in which ExtraHop operates, maintaining the internal database of such filings, staying ahead of legal and regulatory changes and updates and developing internal project roadmaps to ensure timely compliance, and administering compliance programs across multiple legal and risk frameworks.

This role partners with Information Security, Privacy, IT, HR, Finance, Product, and other subject matter experts to develop best practices to understand and advise the business on the legal and regulatory risk   technical, security, privacy, and operational information into clear, customer-facing responses.

This is an excellent opportunity for a junior- to mid-level attorney with at least 5 years of experience to gain deep, cross-functional exposure to international technology regulations, product/hardware compliance, and cutting-edge AI and privacy governance under the supervision of the Deputy General Counsel and senior legal leadership.

The ideal candidate combines strong project and stakeholder management skills with a working knowledge of cybersecurity, privacy, compliance frameworks, and enterprise SaaS environments. This role requires the ability to manage competing priorities, exercise sound judgment on complex requests, identify appropriate resources, and continuously improve the processes, tools, and knowledge resources that support the sales organization.


Key Responsibilities


Regulatory Guidance & Cross-Functional Partnership

  • Research and advise on complex global regulatory and compliance frameworks affecting ExtraHop as a B2B SaaS provider to enterprise clients.
  • Guide responses for security questionnaires, TPRM assessments, RFIs, RFPs, and high-priority customer due diligence requests.
  • Translate complex technical, security, and legal information into clear, customer-facing documentation.

 

Data Privacy & AI Governance 

  • Partner closely with Sales, Finance, Procurement, and InfoSec teams to manage regulatory, privacy (GDPR/CCPA), and AI data protection risks.
  • Draft and update critical data privacy agreements (DPAs) and standard contractual clauses (SCCs).
  • Support AI Governance initiatives to ensure ethical and legally sound product deployment.
  • Coordinate and execute corporate governance programs, including facilitating annual Employment/EE compliance training and collecting data for global ESG annual reporting.
  • Serve as a legal stakeholder for independent audits, assisting with readiness and documentation gathering for annual SOC 2 audits, supporting the preparation and distribution of compliance documentation, certifications, attestations, policies, and other customer-facing materials.
  • Maintain and oversee standardized responses and supporting documentation for common privacy, and compliance requirements.
  • Draft and update critical data protection documentation, including Data Privacy Agreements (DPAs) and standard contractual clauses (SCCs).
  • Support  hardware compliance efforts, including the company’s export control framework and the tracking of and regulatory reporting for environmental supply chain standards.
  • Identify inconsistencies, gaps, or outdated information in customer-facing compliance materials and coordinate updates with the appropriate subject matter experts.
  • Support the implementation of AI Governance frameworks to ensure the ethical, compliant, and legally sound deployment of artificial intelligence capabilities within our products.

 

Compliance, Audit & Legal Operations

  • Serve as primary legal contact for independent audits, including SOC 2 readiness, policy drafting, and evidence collection.
  • Manage corporate governance tasks, including annual compliance training, global ESG data collection, and export/hardware compliance reporting.
  • Maintain knowledge bases, response libraries, templates, and documentation repositories to increase self-service and improve response efficiency.
  • Support annual corporate insurance review and renewal process, gathering underwriting data across departments (Cyber, D&O, General Liability). 
  • Provide ad hoc support on commercial litigation matters, managing document holds, discovery requests, and coordinating logistics with external counsel.
  • Assist with commercial litigation needs, including discovery requests and legal holds.

 

Key Qualifications

 

Required:

  • Education & Bar: J.D. or LL.M. with active US state bar membership in good standing.
  • Experience: 5+ years of legal practice with expertise in regulatory compliance, data privacy, cloud/SaaS transactions, and third-party risk management.
  • Regulatory Knowledge: Working knowledge of foundational tech and privacy regulations (e.g., GLBA, FERPA, GDPR/US privacy laws) and a strong interest in emerging frameworks like the EU AI Act and DORA.
  • Project Management: Proven ability to manage multi-stakeholder workflows, prioritize high-volume deliverables, and operate effectively under tight deadlines.

 

Preferred:

  • Experience supporting B2B SaaS, cybersecurity, or technology organizations.
  • Professional Privacy Certification (e.g., CIPP/US or CIPP/E).
  • Experience with third-party risk management platforms (TPRM) and regulatory filing platforms such as SAM.gov.

 

Core Competencies 

  • Compliance & Security Acumen – Applies practical knowledge of security, privacy, compliance, and risk requirements to business situations.
  • Cross-Functional Collaboration – Coordinates diverse stakeholders and creates accountability for timely and accurate project milestones.
  • Judgment & Prioritization – Distinguishes routine requests from complex or high-risk matters and engages the appropriate subject matter experts.
  • Process & Operational Excellence – Builds scalable processes, improves workflows, and identifies opportunities for automation and self-service legal processes.

The salary for this role is between $150,000 - $163,000 per year + bonus

ABOUT EXTRAHOP

ExtraHop is reinventing Network Detection and Response (NDR) to offer enterprises unparalleled visibility, context, and control against emerging threats. The platform integrates NDR with Network Performance Management (NPM), Intrusion Detection Systems (IDS), and forensics, providing a single, comprehensive solution. By decrypting and analyzing complete packet-level data at wire speed and leveraging cloud-scale machine learning, ExtraHop empowers Security Operations Centers (SOCs) to detect, investigate, and remediate modern cyber risks in real time across their entire hybrid infrastructure, including data center, cloud, and SASE environments.

This comprehensive approach and market innovation have earned ExtraHop unique recognition as the only NDR vendor acknowledged as a leader by all major analyst firms, including the 2025 Gartner® Magic Quadrant for Network Detection and Response™, the 2025 Forrester® Wave for Network Analysis and Visibility, the 2024 IDC® Marketscape for NDR, and the 2025 Gigamon® Radar Report for Network Detection and Response. Since 2007, ExtraHop has consistently helped organizations worldwide extract in-depth network telemetry and contextual insights, affirming its commitment to protecting and empowering the connected enterprise.

OUR VALUES

Our culture is rooted in our five Values. These set the expectations for how we work individually and collectively as a team. 

Lead with Purpose: We are driven to deliver results that create a positive impact for our customers, partners, and colleagues.

Act with Integrity: We operate with transparency, authenticity, and always in the best interest of the company. 

Find a Way: We are resourceful, tackle hard problems with a sense of urgency and ownership, and do what it takes to get the job done.

Innovate: We listen to customers, partners, and the market, and respectfully push boundaries and challenge the status quo.

Share Success: We run together, we win together. We value diverse perspectives, hold space for all voices, and achieve the best results as a team. 

BENEFITS

Employees' wellbeing is top of mind for the ExtraHop team. Employees and their families will have the option to participate in the following benefits:

  • Health, Dental, and Vision Benefits
  • Flexible PTO, Sick Time Prorated Based on Date of Hire, and All Federal Holidays (US Only) + 3 Days of Paid Volunteer Time
  • Non-Commissioned Positions may be eligible to participate in the Annual Discretionary Bonus Plan
  • FSA and Dependent Care Accounts + EAP, where applicable
  • Educational Reimbursement
  • 401k with Employer Match or Pension where applicable
  • Pet Insurance (US Only)
  • Parental Leave (US Only)
  • Hybrid and Remote Work Model

Our people are our most important competitive advantage, leading the charge against cyber criminals. Join the fight today!  

To learn more, visit our website or follow us on LinkedIn. 

Create a Job Alert

Interested in building your career at ExtraHop? Get future opportunities sent straight to your email.

Skills Required

  • J.D. or LL.M. degree
  • Active U.S. state bar membership in good standing
  • At least 5 years of legal practice experience
  • Expertise in regulatory compliance, data privacy, cloud or SaaS transactions, and third-party risk management
  • Working knowledge of GLBA, FERPA, GDPR, and U.S. privacy laws
  • Strong interest in emerging frameworks such as the EU AI Act and DORA
  • Ability to manage multi-stakeholder workflows and high-volume deliverables under tight deadlines
  • Experience supporting B2B SaaS, cybersecurity, or technology organizations
  • Professional privacy certification such as CIPP/US or CIPP/E
  • Experience with third-party risk management platforms
  • Experience with regulatory filing platforms such as SAM.gov
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Seattle, WA
613 Employees
Year Founded: 2007

What We Do

ExtraHop secures the hybrid enterprise through network detection and response. ExtraHop provides cloud-native network detection and response for the hybrid enterprise. Our breakthrough approach analyzes all network interactions and applies cloud-scale machine learning for complete visibility, real-time detection, and intelligent response.

Why Work With Us

We are ExtraHoppers. We like what we do and the people we do it with. We don't just solve problems for our customers, we help them rise above the noise of threats, alerts, and corporate gridlock to realize true security and exceptional performance.

Gallery

Gallery

Similar Jobs

Circle Logo Circle

Staff Software Engineer

Blockchain • Fintech • Payments • Financial Services • Cryptocurrency • Web3
In-Office or Remote
12 Locations
1050 Employees
195K-258K Annually

Ericsson Logo Ericsson

Architect

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office or Remote
2 Locations
88000 Employees

Toast Logo Toast

Senior Manager, Customer Training

Cloud • Fintech • Food • Information Technology • Software • Hospitality
Remote
United States
5000 Employees
149K-238K Annually

Wipfli Logo Wipfli

Tax Senior Manager - Real Estate

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
Minneapolis, MN, USA
2900 Employees
145K-195K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
70 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account