About this role
What You'll Do:
- Serve as a day-to-day legal resource for the Security and IT teams on privacy, data protection, and cybersecurity questions.
- Help maintain and improve our privacy policies, data governance documentation, and internal security policies so they reflect current law and practice.
- Track and flag changes in U.S. telecom and privacy regulations (e.g., FCC CPNI rules, TCPA, state privacy laws such as the CCPA/CPRA) that affect US Mobile.
- Support incident response: help assess, document, and respond to security incidents, including drafting breach notifications when needed.
- Review and help negotiate privacy and security terms in vendor, technology, and partner contracts.
- Assist with legal review of new products, features, and vendor tools from a data privacy and security standpoint, including emerging AI and cloud tools.
- Partner with the General Counsel and outside counsel on larger cybersecurity or regulatory matters as they arise.
- Help build simple, practical training and reference materials so non-legal teams understand key privacy and security obligations.
What You'll Bring:
- J.D. and active license to practice law in at least one U.S. jurisdiction, in good standing.
- Bachelor’s Degree in Computer Science or related field
- 4-6 years of relevant legal experience, whether at a law firm or in-house, with meaningful exposure to privacy, data protection, or cybersecurity matters.
- Working knowledge of U.S. data privacy and telecom regulatory frameworks (e.g., CCPA/CPRA or similar state privacy laws, FCC/CPNI rules, TCPA, breach notification requirements)
- Experience reviewing or negotiating commercial or technology contracts, especially data protection or security terms.
- Comfort working independently and prioritizing your own workload in a fast-moving, resource-lean startup environment.
- Clear, practical written and verbal communication — you can explain legal risk to non-lawyers without the jargon.
- Genuine curiosity about technology, telecom, and how security and privacy actually work in practice.
Nice to Have:
- Prior experience in telecom, wireless, or another regulated consumer tech industry.
- Familiarity with incident response processes or having supported a live security incident.
- Exposure to AI governance or emerging-technology legal issues.
Schedule & Logistics:
- This role is part-time at approximately 24 hours per week, ideally in our NYC HQ Monday, Tuesday and Wednesday.