Legal Counsel - Privacy

Blockchain intelligence company providing tools to detect, investigate, and manage crypto-related fraud, financial crime, and compliance for institutions and government agencies.

Maintainer signals as of 9/25/2026

450 Townsend Street, San Francisco, CA 94107, United States
About TRM Labs

TRM Labs provides blockchain intelligence for investigations and compliance, offering products such as forensics, wallet screening, entity screening, transaction monitoring, and APIs. It serves financial institutions, crypto businesses, and public sector agencies to trace funds, assess risk, and build cases across digital assets.

View jobs by TRM Labs

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Own privacy and data-protection compliance for Orion globally by advising Product and Engineering, leading data-subject rights processes, creating privacy-program artifacts, reviewing processing agreements, designing cross-border transfer mechanisms, and providing guidance on privacy risk.

Requirements

  • 4+ years of privacy and data-protection legal experience.
  • Hands-on experience applying GDPR and US state privacy laws to a technology product.
  • Active US bar admission.
  • JD from an ABA-accredited law school.
  • Experience using AI tools in daily legal workflows.
  • Experience counseling Product and Engineering teams on privacy-by-design, DPIAs, and data flows.
  • Familiarity with SCCs, transfer impact assessments, and adequacy analysis.
  • Collaborative, business-minded approach and comfort operating with ownership and limited oversight.

Responsibilities

  • Determine whether Orion can launch in new jurisdictions through end-to-end privacy analysis.
  • Conduct privacy analyses, DPIAs, and transfer assessments.
  • Embed privacy-by-design into Orion's development lifecycle.
  • Advise Engineering on data flows and retention.
  • Lead and respond to data-subject rights requests.
  • Build records of processing, DPIA templates, and breach-response playbooks.
  • Review and finalize data-processing agreements.
  • Design cross-border data-transfer mechanisms.
  • Create a self-service privacy-review intake.
  • Advise leadership on privacy risk.