SoundCloud empowers artists and fans to connect and share through music. Founded in 2007, SoundCloud is an artist-first platform empowering artists to build and grow their careers by providing them with the most progressive tools, services, and resources. With over 400+ million tracks from 40+ million artists, the future of music is SoundCloud.
As we continue to innovate, data protection and cybersecurity remain at the core of our operations. Join us as our Legal Counsel, Data Protection and Platform Security, to help shape the future of data protection and compliance at SoundCloud.
Key Responsibilities
As Legal Counsel for Data Protection and Platform Security, you will be instrumental in advancing SoundCloud’s data protection compliance and cybersecurity initiatives. You will work closely with our Director Product Counsel and Engineering and Security teams to enhance data protection processes, drive compliance and safeguard user data while enabling what’s next in music.
Support SoundCloud’s consent management system (OneTrust), ensuring cookie and SDK compliance with global protection laws. Perform technology audits in collaboration with our data protection officer. Lead our U.S. data protection compliance program, tracking and operationalizing new regulations across multiple U.S. jurisdictions in coordination with cross-functional stakeholders. Take ownership of our Privacy Policy maintenance, providing a transparent foundation for platform innovation. Be responsible for the regular data protection audit together with SoundCloud’s external DPO, including reviewing internal processes and documentation to ensure compliance with global privacy laws. Establish and maintain a data coordinator function across the organization to support compliant growth. Maintain critical internal compliance documents. Update and refine internal data protection training programs, ensuring all employees understand their role in our data protection program. Provide legal support to our MarTech and AdTech teams. Serve as a key liaison to our external data protection officer. Support our Security team in cybersecurity framework initiatives.
Experience and Background
Qualified lawyer (DE) with at least one year of experience in data protection and cybersecurity law, preferably in the tech or digital media sectors. Parallel U.S. bar admission or U.S. LLM is strongly preferred. Fluent in English so that you can explain complex legal topics to native and non-native English speakers. Excellent communication skills are a must. In-depth knowledge of GDPR and at least one comprehensive U.S. state data protection law (California preferred). Experience with OneTrust or a similar consent management platform. Experience with incident response, data mapping, and compliance reporting. Deep experience with data protection clauses in vendor contracts and DPAs. Familiarity with SOC 2 or similar cybersecurity framework. Strong understanding of data protection issues in the digital advertising and marketing space, including experience with Google Analytics, Google Ad Manager, pixels, and IAB tools. Ability to work cross-functionally, providing pragmatic legal guidance that enables privacy-by-design-based innovation and growth. Familiarity with basic software development lifecycle and project lifecycle concepts. Passion for music and a demonstrated interest in technology.