Back to jobs

AI Data Security & Privacy Engineer

Utah
About Rocket Lawyer
 
We believe everyone deserves access to affordable and simple legal services. Founded in 2008, Rocket Lawyer is the largest and most widely used online legal service platform in the world. With offices in North America, South America, and Europe, Rocket Lawyer has helped over 30 million people create over 50 million legal documents, and get their legal questions answered.
 
We are in a unique position to enhance and expand the Rocket Lawyer platform to a scale never seen before in the company’s history, to capture audiences worldwide. We are expanding our team to take on this challenge!

About your role

Rocket Lawyer’s customer data is the company’s most important asset, and we need to continue maintaining the security and privacy of this data to ensure delighted customers and a successful business. As a seasoned data security and privacy engineer, you will play a critical role in designing, building, and scaling the systems, processes, and controls that protect the company and our users’ data and ensure trust in our products. Working as part of the Security team, you will partner closely with Engineering, Legal, and cross-functional stakeholders to embed privacy-by-design principles into our infrastructure and translate regulatory requirements into scalable technical solutions. You’ll bring to the role a passion for architecting and operating a secure data storage system.

This is a hands-on role for a senior individual contributor who thrives at the intersection of security, privacy, and data infrastructure. You will shape how we discover, classify, and protect information, lead privacy risk mitigation efforts, and help evolve our data security capabilities as the company grows and our AI product flourishes. The ideal candidate will be a seasoned data security and privacy expert with exposure to AI-integrated systems to understand the complexities of data security as it relates to AI.

How you will make a difference day to day

Data Discovery, Classification, and Mapping

  • Design and implement data classification and handling frameworks to provide appropriate protection throughout the data lifecycle.

  • Build and maintain comprehensive data inventories and data flow maps, identifying where data resides and how it is processed across systems.

  • Collaborate with Engineering teams to apply appropriate controls at every point in the data pipeline.

  • Understand the need for encryption, implement it where possible, and implement all appropriate safeguards to ensure keys are both kept secure and available to prevent data exfiltration and loss.

Privacy by Design and Technical Enablement

  • Partner with Engineering, Legal, Product, IT, and other cross-functional stakeholders to design and embed privacy and data protection principles across the entire organization, from product development to operations.

  • Partner with Stakeholders to translate legal and regulatory obligations into actionable technical requirements, policies, and controls.

  • Develop privacy-enhancing capabilities such as data minimisation, anonymisation, and access-control frameworks that scale with our infrastructure.

  • Work with AI teams to ensure that architectural designs are reviewed and threat modeled to minimize data privacy risk.

Risk Assessment, Monitoring, and Compliance Execution

  • Conduct technical risk assessments of internal and third-party systems and applications to identify, evaluate, and mitigate privacy and data security risks, including vulnerabilities, misuse, and compliance gaps.

  • Contribute to Data Protection Impact Assessments (DPIAs) by assessing the technical and security implications of new processing activities.

  • Partner with Legal to transform evolving regulatory frameworks (e.g., SOC2, GDPR, CCPA, NIST, ISO) into secure, scalable engineering solutions that drive compliance and build user trust.

Incident Response and Breach Management

  • Support and coordinate the company’s technical response to data breaches or security incidents, including those impacting personal information (Incidents), enabling timely investigation, effective mitigation, and root-cause analysis.

  • Design and implement processes and tooling to detect, investigate, and remediate data security incidents in compliance with applicable laws.

Privacy Automation And Process Enablement

  • Partner with Stakeholders to design and implement automated workflows and tools to streamline privacy operations, including data subject rights requests and data deletion workflows.

  • Deploy and manage data loss prevention (DLP) capabilities across endpoints, applications, and infrastructure to prevent unauthorised disclosure of sensitive data.

  • Implement continuous auditing, monitoring, and alerting to track compliance posture and surface security and operational privacy risks proactively.

Cross-Functional Collaboration and Enablement

  • Act as a trusted advisor to Stakeholders on the technical implementation of privacy and security controls.

  • Provide strategic input on product design decisions and architectural choices to enable alignment with privacy and security best practices.

  • Partner with cross-functional teams to develop and execute vendor risk assessments as they relate to data security, establishing processes that address technical, security, and privacy requirements across the entire vendor lifecycle.

Additional Responsibilities 

  • Collaborate with Legal on technical aspects of contractual reviews with enterprise customers, partners, vendors, and other third parties.

  • Assist with answering vendor security questionnaires as they relate to Rocket Lawyer’s privacy and data-handling policies.

  • Contribute to the development of internal policies, standards, and procedures based on technical best practices.

What you’ll need

  • 5+ years of hands-on experience in information security, privacy engineering, or related roles.

  • Strong understanding of global data protection laws and regulations (e.g., GDPR, CCPA) and their technical implications.

  • Proven experience in incident response, data protection engineering, and risk assessments.

  • Familiarity with data classification, mapping, and governance methodologies.

  • Experience with at least one software data classification technology, such as a DSPM.

  • Experience with DLP technologies and implementing privacy workflows and automation.

  • Familiarity with workflow automation tools and ticketing systems (e.g., Jira, ServiceNow).

  • Experience in using third-party privacy automation tooling is a plus.

  • Strong analytical, problem-solving, and communication skills, with the ability to work effectively across cross-functional teams.

  • Industry certifications (e.g., CISSP, CISA, CISM) are a plus.

Not sure if you meet all the qualifications? Apply anyway! We value diverse experiences and encourage you to bring your unique talents to our team!

Benefits & Perks

  • Comprehensive health plans (including Medical, Dental, and Vision insurance for full-time employees)
  • Unlimited PTO
  • Competitive salary packages
  • Life insurance
  • Disability benefits
  • Supplemental Optional Life Insurance Benefits
  • FSA Options Optional
  • HSA with Company Match
  • 401k program with Company Match
  • Wellhub & ClassPass fitness platforms
  • Comprehensive Pet Insurance options
  • Financial Wellbeing & Student Loan Program access
  • Access to additional Mental Health & Wellbeing resources
  • Pre-tax Commuter/Transit Benefits
  • Free Rocket Lawyer account with online access to an extensive legal documents library and brilliant licensed attorneys at discounted rates. 

Interview Process

  • Recruiter Phone Screen
  • Role Assessment(s)
  • Hiring Manager Interview
  • Panel Interviews
  • Final Interview
Rocket Lawyer is proudly committed to recruiting and retaining a diverse and inclusive workforce. As an Equal Opportunity Employer, we never discriminate based on race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, military or veteran status, status as an individual with a disability, or other applicable legally protected characteristics. We particularly welcome applications from veterans and military spouses.
 
All your information will be kept confidential according to EEO guidelines.
You may request reasonable accommodations by sending an email to hr@rocketlawyer.com.
 
Compensation
Base salary range by location:
  • San Francisco Bay Area, CA: $161,109 - $189,540
  • California (outside of the San Francisco Bay Area) and Colorado: $136,943 - $175,324
  • Utah, Arizona, and North Carolina: $128,887 - $151,632

Actual compensation packages are determined by various factors unique to each candidate, including but not limited to skill set, depth of experience, certifications, specific work location, and performance during the interview process.

$128,887 - $189,540 USD

By applying for this position, your data will be processed as per Rocket Lawyer Privacy Policy

Create a Job Alert

Interested in building your career at Rocket Lawyer? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

U.S. Standard Demographic Questions

We invite applicants to share their demographic background. If you choose to complete this survey, your responses may be used to identify areas of improvement in our hiring process.
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Rocket Lawyer’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.