Jobs and Careers
GO

Director, Legal - Privacy, Cybersecurity and AI Governance

GoFundMe
San Francisco, United StatesRemotefull_timeVerifiedPosted 1 Apr 2025
💰 $327,500/yr($218,500/yr$327,500/yr)

About the role

Want to help us help others? We’re hiring! 

GoFundMe is a global community of over 150 million people who come together every day with the common purpose of helping one another. Our mission is to help people help each other through our best in class technology. In 2022, GoFundMe joined together with Classy, a leading nonprofit fundraising software company that enables nonprofits to connect supporters with the causes they care about. Together, we have empowered people and organizations to raise more than $30 billion since 2010. Our vision is to become the most helpful place in the world.

Join us! GoFundMe is seeking a Director Legal, Privacy, Cybersecurity and AI Governance to manage and scale our privacy and AI governance programs and support our security team. This role will oversee the continued development of AI governance, ensure compliance with global privacy regulations, support product teams on privacy matters, support the security team on all incident response matters and provide strategic guidance on privacy and AI-related contractual issues. The ideal candidate will have deep expertise in privacy and cybersecurity law, AI governance, and data protection, as well as strong leadership skills to mentor and manage a team. 

The Job…

  • Leadership & Strategy:
    • Lead and develop a team of three privacy professionals, ensuring strong execution of privacy and AI governance initiatives.
    • Lead communication and collaboration with product, engineering, security, and marketing teams to operationalize privacy and AI governance policies.
    • Report out to leadership regularly on progress of key privacy, cybersecurity, and AI governance risks, developments, and compliance initiatives. 
  • Privacy & Data Protection Compliance:
    • Support the Product team by advising on privacy-by-design strategies, data protection impact assessments (DPIAs), records of processing activities (ROPAs), and other compliance matters.
    • Oversee privacy-related policies, including Data Subject Requests, vendor diligence, and marketing consent management.
    • Work with engineering and security teams on data protection by design, cookie compliance, and incident response.
  • AI Governance & Responsible AI Strategy:
    • Manage GoFundMe’s AI governance program, ensuring compliance with emerging AI regulations and responsible AI principles.
    • Partner with technical teams to evaluate AI models for fairness, transparency, and accountability.
    • Stay ahead and keep legal team and AI Governance Committee informed of regulatory changes, including the EU AI Act, U.S. AI regulatory developments, and industry frameworks.
  • Data Breach & Incident Management:
    • Lead GoFundMe’s legal response to security incidents and data breaches, collaborating with security, engineering, customer care and communications teams.
    • Ensure compliance with global data breach notification laws, including GDPR, CCPA/CPRA, and other regulatory frameworks.
    • Develop and refine incident response playbooks, including escalation protocols, regulatory reporting, and customer communications.
    • Provide legal guidance on forensic investigations, mitigation strategies, and post-breach assessments to enhance future resilience.
  • Contracting & Vendor Support:
    • Support the contracts team by reviewing and negotiating privacy and AI-related provisions in vendor and commercial agreements, including data processing agreements (DPAs) and AI-related terms.
    • Provide guidance on third-party AI tools and vendors, ensuring compliance with GoFundMe’s privacy and AI governance standards.
  • Cross-functional Collaboration & Training:
    • Serve as a key legal advisor on privacy and AI risks across the company.
    • Ensure we stay abreast of key regulatory trends in order to guide sound decision-making and support of our compliance strategies. 
    • Provide training and guidance to internal teams on privacy, AI governance, and data protection best practices.
    • Engage with leadership and stakeholders to drive privacy and AI governance awareness and adherence.

You… 

  • 12+ years of legal experience, with a strong focus on privacy, data governance, and 1+ years of AI governance.
  • Expertise in Global privacy regulations (GDPR, CCPA/CPRA, etc.) and AI laws (EU AI Act, emerging U.S. AI regulations).
  • E

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

GoFundMe

View company profile →