Privacy Counsel
Legal
San Francisco, CA, USA · New York, NY, USA
Beacon is building the essential technology infrastructure for the everyday economy: the businesses, organizations, and services that make real life work, and that mainstream tech has largely left behind. We acquire, operate, and grow vertical market software and services companies: niche, founder-built businesses serving industries that are too specific for the enterprise giants and too profitable to ignore. Our model is simple. We buy great businesses, invest in their continued growth, and hold them permanently. We are not a financial firm. We are technology entrepreneurs and operators who believe the most important businesses in the world are already running quietly in industries most people never think about. Our job is to find them, support the people who built them, and make them better. We seek out founders who have built their business by spending years understanding their market and prioritizing their customers' specific needs. Our flexible structure offers entrepreneurs a unique option to implement a transition that ensures the continuity of the company while receiving liquidity at full value for their equity in their business. No mandate to cut, flip, or roll up into something unrecognizable. We are permanent, committed capital with no exit pressure and a long-term time horizon, backed by a diverse base of investors including Wall Street (D1 Capital, CPMG), Silicon Valley (General Catalyst and Lightspeed), the family offices of world-class technology entrepreneurs (including the founders of Stripe, DoorDash, and Ramp), and evergreen funds built for the long game (Sator Grove).
Beacon was founded by Nilam Ganenthiran, entrepreneur, former President of Instacart, and investor at D1 Capital, who has spent his career building, scaling, and backing high-growth technology businesses.
About the Role
We are seeking a strategic and hands-on Privacy Counsel to join Beacon’s legal team as our first dedicated privacy specialist. This is a foundational role: you will build Beacon’s privacy strategy and architecture from the ground up, establishing the frameworks, policies, and processes that will govern how Beacon and its growing portfolio of vertical market software companies collect, use, and protect data. Reporting to Beacon’s VP, Legal, you will partner closely with our IT, Governance, and Risk leader to architect a privacy program that is robust, scalable, and fit for a multi-jurisdictional technology acquirer. You will own data privacy end-to-end across the deal lifecycle — from pre-acquisition diligence through integration and post-close operations — while also advising on day-to-day privacy matters across the Beacon platform. This is a high-impact, high-autonomy role for a privacy lawyer who wants to build something lasting, not just maintain the status quo.
What You'll Do
Privacy Program Architecture: Build and own Beacon’s enterprise data privacy program from inception. Establish the foundational strategy, governance structure, and operating model for privacy across Beacon and its portfolio companies. Define Beacon’s privacy principles and risk appetite, and translate them into practical policies, controls, and accountability structures that can scale as the portfolio grows.
M&A Privacy Diligence & Integration: Own the data privacy workstream across the full deal lifecycle. Conduct and lead privacy due diligence on acquisition targets — assessing data inventories, consent frameworks, cross-border transfer mechanisms, regulatory exposure, and historical compliance posture. Develop standardized privacy diligence checklists and playbooks. Post-close, lead privacy integration planning and execution, ensuring acquired companies are brought into alignment with Beacon’s privacy standards in a structured, risk-based manner.
Policy, Process & Template Development: Draft, implement, and maintain Beacon’s core privacy documentation — including privacy policies, data processing agreements (DPAs), records of processing activities (ROPAs), consent frameworks, data subject rights (DSR) procedures, data retention schedules, and vendor privacy terms. Build a library of reusable templates and precedents that can be deployed efficiently across the portfolio.
Cross-Functional Partnership: Serve as the primary privacy advisor to Beacon’s IT, Governance, and Risk function. Work collaboratively with engineering, product, and operations teams at Beacon and within portfolio companies to embed privacy-by-design principles into technology development, data infrastructure, and business processes. Translate complex regulatory requirements into clear, actionable guidance for non-legal stakeholders.
Multi-Jurisdictional Compliance: Monitor and advise on compliance with applicable data privacy laws across the jurisdictions in which Beacon and its portfolio companies operate, with particular depth in U.S. federal and state privacy law (including CCPA/CPRA and sector-specific regimes), Canadian federal and provincial privacy law (PIPEDA and Law 25/Bill 64), and EU/UK GDPR. Identify and manage cross-border data transfer requirements and implement appropriate transfer mechanisms.
Data Breach Incident Response: Develop and maintain Beacon’s data breach and privacy incident response playbook. Serve as legal lead on privacy incidents — advising on investigation, containment, notification obligations, and regulatory reporting across multiple jurisdictions. Coordinate with IT security, external counsel, and senior leadership on material incidents.
Vendor & Third-Party Privacy Management: Own Beacon’s third-party privacy risk framework, including vendor assessments, DPA negotiations, and ongoing monitoring. Ensure that data sharing arrangements with service providers, partners, and portfolio company vendors meet applicable legal requirements and reflect Beacon’s privacy standards.
AI & Emerging Technology Privacy: Advise on the privacy implications of Beacon’s use of AI tools and data-intensive technologies across the platform. Develop guidelines for responsible data use in AI and machine learning contexts, and stay current on evolving regulatory expectations in this space.
Training & Privacy Culture: Design and deliver privacy training and awareness programs for Beacon and portfolio company employees. Foster a culture of privacy accountability and build internal capacity so that privacy considerations are embedded in day-to-day decision-making across the organization.
Who You Are
J.D. from an accredited law school and member in good standing of at least one bar (California, New York, preferred)
7+ years of privacy law experience at a top-tier law firm, or 5–7 years of in-house privacy counsel experience at a technology company operating in a data-heavy environment.
Demonstrated experience building or leading a privacy function, including developing privacy programs, policies, and governance frameworks — not just advising on them.
Deep expertise in multi-jurisdictional data privacy law, with substantive knowledge of U.S. (CCPA/CPRA, HIPAA, FERPA, and applicable state laws), Canadian (PIPEDA, Law 25/Bill 64), and EU/UK (GDPR) privacy regimes. Experience navigating cross-border data transfer requirements and international compliance obligations.
Hands-on experience advising on diverse data types, including personal data, sensitive personal information, health data, financial data, and B2B data, across a range of industries and use cases.
Experience conducting or advising on privacy due diligence in M&A transactions, and familiarity with privacy considerations in corporate transactions, vendor relationships, and technology deployments.
Strong instincts for pragmatic, business-enabling privacy advice — able to identify and quantify risk, recommend proportionate controls, and help the business move forward rather than defaulting to “no.”
Proficiency with AI tools for legal and privacy work, and a genuine interest in leveraging technology to build efficient, scalable privacy operations.
Excellent written and verbal communication skills, with the ability to translate complex regulatory requirements into clear, actionable guidance for technical and non-technical stakeholders alike.
Experience with vertical market software, SaaS, or multi-product technology platforms is a strong plus.
Our Values at Beacon Software
Humility: We acknowledge that the path to getting to the right answer involves being wrong along the way. We have strong beliefs which are weakly held. We actively seek new ideas and believe we can learn from anyone at any time.
Honesty: We are truth seeking in our approach to business problems. Business is a repeat game and we believe that human relationships generate alpha. We understand that trust is earned over a lifetime and can be lost in an instant.
Hunger: We play to win. We hold ourselves to high standards and will not be outworked. We take pride in having a deep sense of responsibility to ourselves, each other, our partners, and our customers. We believe to whom much is given much is expected.
Horizon: We seek to build a generational software company. This will take decades. We manage our expectations and those of our partners to take advantage of the 8th wonder of the world - compounding growth.
How We Use AI in Our Hiring Process: To ensure transparency, we want candidates to know that Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.
AI does not make hiring decisions: Every application is reviewed by a member of our team, and all decisions throughout the process are made by humans. We use AI to support efficiency and consistency, not to replace human judgment. We are committed to a fair, thoughtful, and equitable experience for every candidate.