Description:
Job Overview:As the Head of Legal and Compliance, you will establish and lead our legal and compliance function from the ground up. This role will report directly to the CEO, and will play a critical role in ensuring Athena operates with the highest standards of trust, security, and regulatory alignment.
The Head of Legal & Compliance will be responsible for overseeing compliance certifications, managing enterprise contracts, mitigating risk, and serving as a trusted advisor across the organization.
Core Responsibilities:
- Establish and scale the legal and compliance function, defining frameworks, policies, and processes tailored for a growing AI company.
- Serve as a trusted advisor to the CEO, leadership, and investors on risk management, regulatory positioning, and long-term compliance strategy.
- Achieve and maintain compliance certifications (e.g., GDPR, ISO, PCI) and manage ongoing SOC 2 and HIPAA requirements.
- Monitor evolving global privacy, cybersecurity, and AI regulations; advise on implications for product development and client engagements.
- Establish AI governance: model inventory, risk tiers, evaluation standards, documentation, and change control; prepare for EU AI Act obligations.
- Draft, review, and negotiate complex enterprise contracts across industries, balancing client needs with company protection.
- Develop and maintain the corporate governance framework.
- Partner with leadership and investors on fundraising and due diligence, ensuring compliance readiness for growth.
- Conduct risk assessments, identify compliance gaps, and implement remediation plans.
- Lead investigations and responses to legal, compliance, or data security incidents, including regulatory reporting.
- Partner with GTM, Product, and Engineering teams to provide regulatory guidance that supports client adoption and retention.
- Join executive client calls as the legal/compliance voice for the company.
- Build and deliver internal training on compliance, data security, and regulatory requirements
- Manage third‑party risk program and subprocessor list; enforce onboarding gates.
- Review vendor and partner agreements for compliance with security, privacy, and regulatory standards.
Qualifications:
- JD with active bar admission (U.S. jurisdiction)
- Minimum 7+ years of legal and/or compliance experience in regulated industries; startup experience preferred.
- Deep understanding of GDPR, CCPA, HIPAA, SOC 2, PCI, ISO standards, and emerging AI regulations.
- Experience advising on data governance and privacy frameworks
- Exceptional verbal and written communication; able to explain complex issues to technical and non-technical audiences.
- Strong negotiation skills with proven success in high-value, enterprise contracts.
- Ability to independently drive projects in a fast-paced, evolving environment.
- Demonstrated success building scalable compliance programs from the ground up.