OneSource Virtual (OSV) has worked exclusively with Workday customers since 2008 to deliver compliant, in-tenant technology and expert services to automate the administrative, transactional tasks of payroll, taxes, earned wage access, accounts payable, and benefits. With over 1,500 customers, 92% retention, and $225+ billion in treasury movement annually, OSV helps organizations maximize their Workday investment and operate it with confidence. Payroll, benefits, and finance solutions — all in one place.
Position Summary
OSV is seeking a VP, Deputy General Counsel to lead legal strategy and day-to-day counsel across Privacy, Compliance, Product Legal, and Artificial Intelligence (AI). Reporting to the Chief Legal Officer, this attorney will serve as a trusted advisor to product, engineering, marketing, and business teams, and will own the company's legal approach to data protection, cybersecurity, and the responsible development and deployment of AI and data-driven products. The ideal candidate combines deep regulatory knowledge with pragmatic, business-focused judgment and is comfortable operating as both a hands-on advisor and a strategic leader.
Key Responsibilities
Product Legal Support
- Serve as the go-to legal advisor for day-to-day questions from the product and engineering teams on new features and builds that affect disclosures, data sharing, or the customer experience.
- Draft, review, and maintain consumer-facing agreements, online terms, and regulatory notices to reflect product updates and compliance/privacy initiatives and applicable regulation/law.
- Review marketing campaigns for legal compliance, including offer T&Cs, promotional disclosures, sweepstakes rules, and modifications to approved templates.
Regulatory Compliance and Risk Advisor
- Provide legal guidance on U.S. and global privacy and cybersecurity laws, regulations, and enforcement trends.
- Interpret evolving regulatory guidance and translate supervisory expectations into actionable legal advice.
- Monitor emerging issues including AI governance, data ethics, digital identity, and advanced cyber threats.
- Advise on privacy-by-design and security-by-design, data minimization and retention, cross-border data transfers, access controls, and other data-related issues.
Incident Response and Cyber Events
- Lead the legal response to privacy and cybersecurity incidents, including investigation, legal risk assessment, and regulatory and contractual analysis.
- Coordinate closely with internal stakeholders and external forensic firms, outside counsel, and crisis management advisors.
- Advise on notification obligations, litigation risk, and regulatory engagement arising from cyber events.
Commercial Transactions and Technology Enablement
- Advise on privacy and cybersecurity issues across commercial transactions, including vendor engagements, cloud services, SaaS platforms, fintech partnerships, strategic investments, and M&A.
- Draft, negotiate, and approve data protection and information security provisions in customer, vendor, and partner agreements.
Emerging Technology and Innovation
- Advise on privacy, data protection, and cybersecurity considerations related to the design, development, and deployment of artificial intelligence, advanced analytics, and other data-driven products and business models.
Education and Enablement
- Educate legal, technology, and business teams on privacy and cybersecurity requirements in a pragmatic, business-focused manner.
- Identify and support efforts to scale consistent, risk-based legal guidance across the enterprise.
Qualifications & Experience
- Experience: Minimum of 15 years of relevant legal experience, with substantial depth in privacy, data protection, cybersecurity, and technology/commercial law; in-house experience advising product and engineering teams strongly preferred.
- Education: Juris Doctor (JD) from an ABA-accredited U.S. law school.
- Licensure: Active license to practice law in good standing in the attorney's state of residence.
- Demonstrated knowledge of U.S. state and federal privacy and data protection laws (e.g., CCPA/CPRA and other state privacy statutes), and familiarity with global frameworks such as GDPR. CIPP and CISSP certifications are a plus.
- Working knowledge of emerging AI governance frameworks and the legal issues raised by AI-enabled products and analytics.
- Experience leading or supporting cybersecurity incident response, including coordination with forensic firms, outside counsel, and regulators.
- Strong track record negotiating data protection and security terms in commercial, vendor, and technology agreements.
- Excellent judgment, business acumen, and the ability to translate complex regulatory requirements into clear, actionable guidance for non-legal audiences.
- Exceptional written and verbal communication skills, with the ability to build trust across legal, product, engineering, marketing, and executive teams.
You are encouraged to learn and share ideas when you join the OneSource Virtual team. We reward innovative thinking, fresh perspectives, creative collaboration, and hard work. As an organization experiencing routine strategic growth, we are always on the lookout for intelligent, talented, and forward-thinking professionals to join our team. OSV employees enjoy a values-based culture, upward mobility, and professional development with opportunities of all kinds.