Full-Time

Senior Privacy

Security & AI Counsel

Collective Health

Collective Health

501-1,000 employees

Manages employer health benefits via platform

Compensation Overview

$160k - $200k/yr

+ Stock Options

Remote in USA + 2 more

More locations: Plano, TX, USA | Lehi, UT, USA

Hybrid

In-office at least two weekdays per week; remote option for specific states.

Category
Legal & Compliance (2)
,
Required Skills
Data Governance
Requirements
  • D. with U.S. state bar admissions in good standing in the jurisdiction in which you practice
  • 8+ years in house experience supporting privacy, cybersecurity, data protection, and/or related regulatory matters, ideally in a healthcare technology setting
  • Knowledge of and ability to apply healthcare privacy, security and AI legal and regulatory frameworks and industry best practices, certifications, and reviews, and experience to a fast-paced environment
  • Ability to interpret new and existing privacy, security and AI requirements and provide practical, actionable guidance to operationalize processes to support regulatory compliance
  • Enthusiasm for and skill at building relationships, sharing necessary information, and collaborating effectively with a broad range of stakeholders within the company, the legal and compliance teams, and the health tech industry
  • Experience identifying and mitigating new risks in heavily regulated or emerging technology areas as a legal advisor to product, security, and/or engineering teams
  • Understanding and experience advising throughout the entire product development lifecycle, including contracting, and regulatory compliance
  • Detail-oriented, with the ability to balance strategic thinking and practical, hands-on execution
  • Outstanding judgment, business acumen, practicality, collaboration, responsiveness, and integrity
  • Excellent communication and presentation skills, with the ability to represent the company effectively in internal communications at all levels and with external stakeholders
  • Passion for Collective Health’s mission and for working in a young, growing company where systems and processes will require hands-on engagement and creativity
  • Bonus Qualifications: Relevant experience at a rapidly growing technology or healthcare company
  • Up to date privacy, security, and/or healthcare certifications preferred (e.g., CIPP/US, AIGP, CIPT, CISSP, CISSP, HCISPP, Security+, CCSP)
Responsibilities
  • Stay apprised of changing state and federal laws and direct the business on practical implementation of privacy, security, and AI requirements for business operations, vendor engagements, and product development
  • Proactively translate state and federal privacy, security, and AI laws into actionable strategies, product requirements and contract terms for business and product teams and assist in development of training and awareness programs
  • Advise regulatory attorneys on privacy, security, and AI implications of healthcare related laws, such as ERISA and the ACA, as they relate to third party administrator functions, claims data, and required communications
  • Draft and negotiate privacy, security and AI terms and agreements, i.e., Business Associate Agreements, Data Security Agreements, and working with commercial attorneys to align terms with product capabilities and company processes while effectively managing privacy, AI, and security risks
  • Empower business and sales teams by providing expert guidance on privacy, security, and AI questions in Requests for Proposals and customer questionnaires
  • Provide strategic legal review, guidance and contract terms for data use, ownership, indemnification, and limitations of liability aligned with state and federal privacy, AI, and security laws and best practice to support the development and evolution of products
  • Remain current on evolving AI laws to educate and provide support to the business to ensure ongoing compliance with privacy, security, and AI-specific regulation, framework, policies, and guidance
  • Proactively identify and mitigate security and AI risks associated with new product features and commercial initiatives, ensuring 'security by design' and 'privacy by design' principles are embedded from conception and engage with product and engineering teams on new development initiatives, providing clear, practical legal guidance
  • Direct teams in the legal classification of AI systems, assessment of risks, and AI governance frameworks, including development of policies and procedures for ethical AI development, deployment, use, and risk mitigation, ensuring responsible innovation and addressing potential biases and fairness in product offerings
  • Guide cross-functional stakeholders on AI principles such as governance, transparency, accountability, and human-oversight
  • Work cross-functionally on a privacy and data governance program (covering data classification, retention, quality, access and disposal) ensuring compliance and enabling data-driven product innovation
  • Act as a legal partner to the Privacy Officer and the Chief Information Security Officer to proactively advise on federal and state privacy and data security obligations, applicable external certifications and benchmarking frameworks (e.g., HITRUST, NIST, NYDFS, SOC2), including participating in tabletop exercises
  • Assist with drafting, updating, and operationalizing cybersecurity, and data protection policies, procedures, standards, and guidelines and support third party risk management, due diligence and contracting
  • Advise and support, as requested by the Privacy Officer and/or Chief Information Security Officer, escalated privacy and/or cyber incidents, lawsuits, regulatory inquiries, or government escalations including communications and outreach to customer, vendor and partner counsel
Desired Qualifications
  • Relevant experience at a rapidly growing technology or healthcare company
  • Up to date privacy, security, and/or healthcare certifications preferred (e.g., CIPP/US, AIGP, CIPT, CISSP, CISSP, HCISPP, Security+, CCSP)

Collective Health provides a health benefits platform that helps employers manage and improve employee health benefits by integrating multiple health insurance plans, wellness programs, and related services into one easy-to-use interface. The product works as a software platform used by employers to enroll employees, compare plans, access claims, and administer benefits, consolidating diverse plans and services into a single portal with administrative tools for streamlined management. Compared with competitors, Collective Health focuses on the employer experience—centralizing plan administration, transparency, and user-friendly access to benefits and wellness options—while aiming to reduce costs and administrative overhead for employers. The company’s goal is to make healthcare benefits easier to access and manage for employees and to simplify benefits administration for employers.

Company Size

501-1,000

Company Stage

Series F

Total Funding

$714M

Headquarters

San Francisco, California

Founded

2013

Simplify Jobs

Simplify's Take

What believers are saying

  • Plano office opened April 23, 2024, supports Spanish-speaking clients with 100 employees.
  • Noom partnership offers 28% GLP-1 medication savings via SmartRx adaptive cost-sharing.
  • Caroline Jessen as CPO and Keven Sticher as CISO drive growth and security enhancements.

What critics are saying

  • Providence outsourcing causes integration failures, HIPAA violations, and PEBB member data loss.
  • Zocdoc captures 20% self-funded market share with cheaper telehealth navigation in 12 months.
  • Google Cloud outages disrupt CAI reliability, raising costs after July 2024 healthcare failures.

What makes Collective Health unique

  • Collective Health integrates medical, dental, vision, pharmacy into unified TPA platform.
  • CAI AI launched February 25, 2026, with Google Cloud enhances member concierge experience.
  • Exclusive Providence Health Plan TPA partnership delivers 50% claims cost reduction over five years.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Collective Health who can refer or advise you

Benefits

Medical, dental, and vision plans

Flexible time off

Life insurance

Retirement plan

Paid time off

Maternity & paternity leave

Free lunch and snacks

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

-1%
Collective Health
Feb 25th, 2026
Collective Health collaborates with Google Cloud to deliver Collective AI (CAI(TM), reimagining the healthcare experience through enterprise-scale AI.

Collective Health collaborates with Google Cloud to deliver Collective AI (CAI(TM), reimagining the healthcare experience through enterprise-scale AI. Collective Health leverages its unique third party administration (TPA) foundation and Google Cloud's secure infrastructure to support responsible artificial intelligence innovation SAN FRANCISCO, CA, Feb. 25, 2026 - Collective Health, an independent, transparent third party administrator (TPA) with Care Navigation and Benefits Hub, today announced a strategic infrastructure expansion and collaboration with Google Cloud to deliver its next generation of human-centric healthcare intelligence, Collective AI (CAI(TM). CAI(TM) brings the power of artificial intelligence across the Collective Health platform. It includes: * CAI MX(TM)(Member Experience): Acts as an intelligent concierge within the My Collective(R) app. Members can use their own words to ask common questions about their specific plan benefits, like "Is my plan active?" or "Can you show me my ID cards?" * CAI Intelligence(TM): Today, CAI Intelligence(TM)"supercharges" customer service representative (Member Advocate) abilities when on the phone with members. By automating plan-specific search and real-time documentation, CAI(TM) allows Member Advocates to actively engage and be present while interfacing with members. * CAI CX(TM)(Client Experience): The first applications of CAI CX(TM) will focus on transforming the administrative burden of annual enrollment and plan implementation processes into an easy-to-follow guided project management experience with CAI(TM) plan design insights, supporting benefit leaders and their consultant teams to collaborate and execute their benefits strategy all within the Collective Compass(R) employer portal. "Our focus at Collective Health has never been on chasing headlines, but on the real, practical application of technology to solve the problems that affect millions of people trying to get the care they need," said Ali Diab, CEO and Co-founder of Collective Health. "By collaborating with Google Cloud, we are combining our deep healthcare expertise with world-class infrastructure to improve access to benefits information for employers and members, with robust security and privacy protections for sensitive healthcare data." "Healthcare requires a unique balance of rapid innovation and an uncompromising commitment to data privacy and user safety," said Aashima Gupta, Global Director, Healthcare Strategy & Solutions, Google Cloud. "By choosing Google Cloud to help deliver CAI(TM), Collective Health is able to deploy sophisticated generative AI models on a foundation built for privacy, scale, and reliability. We are excited to support their mission of helping healthcare consumers better understand, navigate, and pay for their healthcare, proving that advanced technology can be used to significantly improve the day-to-day experience of employers and their members." Collective Health's platform is built on a privacy-by-design framework, providing employers with the confidence that sensitive employee health data is protected and never used to train external foundational models. In addition, Collective Health's AI implementation follows the same rigorous security standards as its core infrastructure - including foundational, actively monitored compliance with the HIPAA Security Rule and SOC 2 Type 2 trust principles. Collective Health's commitment to privacy and compliance distinguish its approach in the market. CAI's(TM) development is anchored in a framework of responsible AI including: * Enhance, never diminish: AI must always improve the customer experience. * Superior accuracy: AI must be at least as accurate as a human, and ideally much more. * Human boundaries: AI can never be catastrophically wrong and must respect the necessity of human interaction. * Do no harm: AI must protect customers, workers, and society at large. About Collective Health Collective Health is the leading independent TPA and navigation platform powered by AI that transforms how employers deliver healthcare benefits. By unifying medical, dental, vision, pharmacy, and program partners into a single platform, Collective Health delivers measurable cost savings with a better member experience and lowers administrative burden for HR teams. Collective Health, Inc. is headquartered in San Francisco, CA with customer experience centers in Lehi, UT, and Plano, TX. For more, please visit collectivehealth.com. Media Contact

Health Technology Insights
May 13th, 2025
Collective Health Names New CPO and CISO to Drive Growth and Security

Collective Health, a leading employee health benefits platform with integrated member advocacy, clinical navigation, and an extensive partner ecosystem, announced the appointments of Caroline Jessen as Chief People Officer (CPO) and Keven Sticher as Chief Information Security Officer and VP of Engineering.

Collective Health
Apr 15th, 2025
AI in Benefits: A Game-Changer or a Cautionary Tale?

At its Together 2025 customer conference in Scottsdale, CollectiveHealth, Inc. had an engaging and thought-provoking discussion on AI in healthcare to kick off the event.

Health Technology Insights
Apr 2nd, 2025
Providence Health Plan Partners with Collective Health

Providence Health Plan partners with Collective Health.

OurHealth
Mar 27th, 2025
Collective Health, Noom Health partner for weight management

In 2023, Collective Health laid off 54 employees and restructured its workforce to better align with customer needs.