Compliance & Regulatory Counsel at ExtraHop #cybersecurity #TechJobs #Careers


Job Description

At ExtraHop, we’re on a mission to protect and empower the connected enterprise. We reveal what is happening in the very infrastructure that sustains businesses, lives, and communities, and ensure the integrity of networks, data, systems, and processes. Organizations rely on ExtraHop to provide visibility into the cyber threats, vulnerabilities, and network performance issues that evade their existing security and IT tools. With this insight, organizations can investigate smarter, stop threats faster, and keep operations running.

Our mission is fueled by a profound social and moral responsibility to be the best at what we do, ensuring a secure world where everyone can thrive. If this sounds like a place you’d like to spend the next chapter of your career, we’d love to hear from you.

Position Summary

The  Compliance and Regulatory Counsel will act as a key legal partner to deliver and scale critical legal support to a growing global hi-tech SaaS company serving customers that include multi-national enterprises and public sector entities.  This role will support the compliance and regulatory function at ExtraHop,  advising on laws and regulations directly impacting our business as a SaaS provider, as well as the frameworks governing our enterprise customers. This role  supports the corporate and sales compliance function by ensuring accurate and timely filings of various business and regulatory registrations for all jurisdictions in which ExtraHop operates, maintaining the internal database of such filings, staying ahead of legal and regulatory changes and updates and developing internal project roadmaps to ensure timely compliance, and administering compliance programs across multiple legal and risk frameworks.

This role partners with Information Security, Privacy, IT, HR, Finance, Product, and other subject matter experts to develop best practices to understand and advise the business on the legal and regulatory risk   technical, security, privacy, and operational information into clear, customer-facing responses.

This is an excellent opportunity for a junior- to mid-level attorney with at least 5 years of experience to gain deep, cross-functional exposure to international technology regulations, product/hardware compliance, and cutting-edge AI and privacy governance under the supervision of the Deputy General Counsel and senior legal leadership.

The ideal candidate combines strong project and stakeholder management skills with a working knowledge of cybersecurity, privacy, compliance frameworks, and enterprise SaaS environments. This role requires the ability to manage competing priorities, exercise sound judgment on complex requests, identify appropriate resources, and continuously improve the processes, tools, and knowledge resources that support the sales organization.

Key Responsibilities

Regulatory Guidance & Cross-Functional Partnership

  • Research and advise on complex global regulatory and compliance frameworks affecting ExtraHop as a B2B SaaS provider to enterprise clients.
  • Guide responses for security questionnaires, TPRM assessments, RFIs, RFPs, and high-priority customer due diligence requests.
  • Translate complex technical, security, and legal information into clear, customer-facing documentation.

Data Privacy & AI Governance

  • Partner closely with Sales, Finance, Procurement, and InfoSec teams to manage regulatory, privacy (GDPR/CCPA), and AI data protection risks.
  • Draft and update critical data privacy agreements (DPAs) and standard contractual clauses (SCCs).
  • Support AI Governance initiatives to ensure ethical and legally sound product deployment.
  • Coordinate and execute corporate governance programs, including facilitating annual Employment/EE compliance training and collecting data for global ESG annual reporting.
  • Serve as a legal stakeholder for independent audits, assisting with readiness and documentation gathering for annual SOC 2 audits, supporting the preparation and distribution of compliance documentation, certifications, attestations, policies, and other customer-facing materials.
  • Maintain and oversee standardized responses and supporting documentation for common privacy, and compliance requirements.
  • Draft and update critical data protection documentation, including Data Privacy Agreements (DPAs) and standard contractual clauses (SCCs).
  • Support  hardware compliance efforts, including the company’s export control framework and the tracking of and regulatory reporting for environmental supply chain standards.
  • Identify inconsistencies, gaps, or outdated information in customer-facing compliance materials and coordinate updates with the appropriate subject matter experts.
  • Support the implementation of AI Governance frameworks to ensure the ethical, compliant, and legally sound deployment of artificial intelligence capabilities within our products.

Compliance, Audit & Legal Operations

  • Serve as primary legal contact for independent audits, including SOC 2 readiness, policy drafting, and evidence collection.
  • Manage corporate governance tasks, including annual compliance training, global ESG data collection, and export/hardware compliance reporting.
  • Maintain knowledge bases, response libraries, templates, and documentation repositories to increase self-service and improve response efficiency.
  • Support annual corporate insurance review and renewal process, gathering underwriting data across departments (Cyber, D&O, General Liability).
  • Provide ad hoc support on commercial litigation matters, managing document holds, discovery requests, and coordinating logistics with external counsel.
  • Assist with commercial litigation needs, including discovery requests and legal holds.

Key Qualifications

Required:

  • Education & Bar: J.D. or LL.M. with active US state bar membership in good standing.
  • Experience: 5+ years of legal practice with expertise in regulatory compliance, data privacy, cloud/SaaS transactions, and third-party risk management.
  • Regulatory Knowledge: Working knowledge of foundational tech and privacy regulations (e.g., GLBA, FERPA, GDPR/US privacy laws) and a strong interest in emerging frameworks like the EU AI Act and DORA.
  • Project Management: Proven ability to manage multi-stakeholder workflows, prioritize high-volume deliverables, and operate effectively under tight deadlines.

Preferred:

  • Experience supporting B2B SaaS, cybersecurity, or technology organizations.
  • Professional Privacy Certification (e.g., CIPP/US or CIPP/E).
  • Experience with third-party risk management platforms (TPRM) and regulatory filing platforms such as SAM.gov.

Core Competencies

  • Compliance & Security Acumen – Applies practical knowledge of security, privacy, compliance, and risk requirements to business situations.
  • Cross-Functional Collaboration – Coordinates diverse stakeholders and creates accountability for timely and accurate project milestones.
  • Judgment & Prioritization – Distinguishes routine requests from complex or high-risk matters and engages the appropriate subject matter experts.
  • Process & Operational Excellence – Builds scalable processes, improves workflows, and identifies opportunities for automation and self-service legal processes.

The salary for this role is between $150,000 – $163,000 per year + bonus

ABOUT EXTRAHOP

ExtraHop is reinventing Network Detection and Response (NDR) to offer enterprises unparalleled visibility, context, and control against emerging threats. The platform integrates NDR with Network Performance Management (NPM), Intrusion Detection Systems (IDS), and forensics, providing a single, comprehensive solution. By decrypting and analyzing complete packet-level data at wire speed and leveraging cloud-scale machine learning, ExtraHop empowers Security Operations Centers (SOCs) to detect, investigate, and remediate modern cyber risks in real time across their entire hybrid infrastructure, including data center, cloud, and SASE environments.

This comprehensive approach and market innovation have earned ExtraHop unique recognition as the only NDR vendor acknowledged as a leader by all major analyst firms, including the 2025 Gartner® Magic Quadrant for Network Detection and Response™, the 2025 Forrester® Wave for Network Analysis and Visibility, the 2024 IDC® Marketscape for NDR, and the 2025 Gigamon® Radar Report for Network Detection and Response. Since 2007, ExtraHop has consistently helped organizations worldwide extract in-depth network telemetry and contextual insights, affirming its commitment to protecting and empowering the connected enterprise.

OUR VALUES

Our culture is rooted in our five Values. These set the expectations for how we work individually and collectively as a team.

Lead with Purpose: We are driven to deliver results that create a positive impact for our customers, partners, and colleagues.

Act with Integrity: We operate with transparency, authenticity, and always in the best interest of the company.

Find a Way: We are resourceful, tackle hard problems with a sense of urgency and ownership, and do what it takes to get the job done.

Innovate: We listen to customers, partners, and the market, and respectfully push boundaries and challenge the status quo.

Share Success: We run together, we win together. We value diverse perspectives, hold space for all voices, and achieve the best results as a team.

BENEFITS

Employees’ wellbeing is top of mind for the ExtraHop team. Employees and their families will have the option to participate in the following benefits:

  • Health, Dental, and Vision Benefits
  • Flexible PTO, Sick Time Prorated Based on Date of Hire, and All Federal Holidays (US Only) + 3 Days of Paid Volunteer Time
  • Non-Commissioned Positions may be eligible to participate in the Annual Discretionary Bonus Plan
  • FSA and Dependent Care Accounts + EAP, where applicable
  • Educational Reimbursement
  • 401k with Employer Match or Pension where applicable
  • Pet Insurance (US Only)
  • Parental Leave (US Only)
  • Hybrid and Remote Work Model

Our people are our most important competitive advantage, leading the charge against cyber criminals. Join the fight today!

To learn more, visit our website or follow us on LinkedIn .

Create a Job Alert

Interested in building your career at ExtraHop? Get future opportunities sent straight to your email.



Source link

...........