Senior Corporate Counsel, Privacy (Hybrid, Seattle)
Nordstrom
last date
Open Access
Location/Place/Mode
Seattle, WA (Hybrid)
Eligibility
J.D. with license to practice law in Washington State; 7-10 years legal experience with meaningful focus on U.S. privacy law; in-house or law firm experience advising large complex organizations; expertise in CCPA/CPRA, state comprehensive privacy statutes, CAN-SPAM, TCPA, behavioral advertising, GLBA, HIPAA, PIPEDA; familiarity with AI governance frameworks, EU AI Act, FTC guidance, Washington My Health My Data Act; experience with data security incidents and breach notification; strong drafting skills for policies, contracts, legal summaries

Opportunity
Nordstrom's Senior Privacy Counsel Role: A Career-Defining Opportunity in Retail Tech Law
When a legacy retailer like Nordstrom—founded in 1901 as a Seattle shoe store and now a $15+ billion omnichannel fashion powerhouse—posts a Senior Corporate Counsel, Privacy role with a mandate spanning AI governance, biometric data compliance, and enterprise-scale incident response, it signals something profound: privacy has officially graduated from a compliance checkbox to a board-level strategic imperative. For the mid-to-senior privacy lawyer eyeing this hybrid Seattle position, this isn't merely a job change. It's a chance to architect the legal infrastructure of one of America's most recognized retail brands at the exact moment the regulatory landscape is undergoing its most violent upheaval in two decades.
"The privacy function at Nordstrom sits inside Technology, not Legal—a structural choice that reveals how seriously this organization treats data as a product discipline rather than a risk silo."
Why This Role Exists Now: The Regulatory Perfect Storm
The job description reads like a syllabus for the current state of U.S. privacy law: CCPA/CPRA enforcement actions accelerating, the Washington My Health My Data Act (MHMDA) creating private rights of action for consumer health data, Texas and Oregon comprehensive statutes taking effect, and the FTC wielding Section 5 authority against "unfair" AI practices. Add to this the EU AI Act's extraterritorial reach for any retailer deploying algorithmic pricing or personalized recommendations to European customers, and you have a compliance matrix that demands not just knowledge, but operational fluency.
Nordstrom's privacy team, housed within Technology, partners with Marketing on behavioral advertising compliance, with Strategic Sourcing on vendor DPAs, with HR on employee monitoring and biometric timekeeping, and with Product on generative AI deployment guardrails. The Senior Counsel will be the primary legal advisor on U.S. state privacy laws—meaning you own the interpretation function for a business that touches millions of consumers across every regulated jurisdiction.
Deconstructing the Mandate: Four Pillars of High-Impact Work
The role description organizes responsibilities into four domains that map directly to the career capital you'll accumulate:
- Privacy Law & Compliance: Leading the U.S. privacy compliance program—privacy notices, consent mechanisms, opt-out frameworks, DSAR processes. This is program ownership, not ticket-taking. You'll monitor legislative developments and translate them into required compliance changes in the context of rapidly evolving business processes—the phrase "rapidly evolving" doing heavy lifting for a retailer rolling out new personalization engines quarterly.
- AI Governance & Policy: Developing the company's AI governance framework including responsible AI use policies, vendor AI due diligence, and internal deployment standards. You'll advise on legal risks of AI in retail contexts: personalization, pricing, fraud detection, hiring tools, generative AI applications. This is greenfield work—few in-house lawyers have built an AI governance program from scratch at enterprise scale.
- Data Security & Incident Response: Legal counsel for breaches and security incidents, including breach notification coordination across state laws, forensic teams, communications, and regulators. This is crisis leadership experience that distinguishes senior privacy leaders from subject-matter specialists.
- Cross-Functional & Strategic Counsel: Drafting privacy provisions in commercial and technology agreements, serving as trusted partner to InfoSec and Technology, developing training programs, representing Legal on data governance committees. This is where you build the internal network that makes you indispensable.
The Seattle Advantage: Geography as Career Strategy
The hybrid Seattle requirement isn't arbitrary. Washington State has emerged as a privacy laboratory: the MHMDA (consumer health data), the Biometric Privacy Law (BIPA-adjacent), and aggressive AG enforcement under the Consumer Protection Act. Being physically present in the jurisdiction where your company is headquartered—and where your regulator operates—creates informal access that remote counsel simply cannot replicate. You'll build relationships with the AG's office, local outside counsel, and the Seattle privacy bar that compound over a career.
Moreover, Nordstrom's legal function is headquartered in Seattle. The General Counsel, the CPO, the CISO—your stakeholders sit in the same buildings. Hybrid work (typically 3 days onsite) preserves the hallway conversations where real strategy happens while respecting the flexibility the market now demands.
"The 7-10 year experience requirement with 'meaningful focus on U.S. privacy law' is a filter for lawyers who lived through the CCPA implementation chaos and survived to tell the tale. This isn't an entry point—it's a mastery role."
Qualification Reality Check: Who Actually Gets This Interview
Let's be precise about the bar. The posting requires:
- Washington Bar license (or eligibility for immediate admission via reciprocity/waiver)—non-negotiable for an in-house role advising on WA-specific statutes like MHMDA.
- 7-10 years with meaningful focus on U.S. privacy law. This excludes general commercial lawyers who "did some GDPR work" in 2018. They want someone who can distinguish CPRA's "sharing" vs "selling" analysis in their sleep.
- In-house OR law firm experience advising large, complex organizations. The "or" is deliberate. A 5th-year associate from a top-tier privacy practice group (think Morrison Foerster, Wilson Sonsini, Hunton Andrews Kurth, Davis Wright Tremaine in Seattle) with deep retail/tech client experience is competitive. So is a 4th-year in-house counsel from a comparable retailer or tech platform.
- AI governance familiarity—not expertise, but demonstrated engagement. Have you advised on vendor AI assessments? Written a generative AI use policy? Commented on NIST AI RMF? That's the baseline.
- Breach response experience. You've sat in the war room. You know the 30/45/60-day notification clocks across states. You've negotiated with forensic firms and cyber insurers.
Compensation Intelligence: What the Market Bears
While the posting doesn't disclose compensation, market data for Senior Corporate Counsel roles at Fortune 500 retailers in Seattle provides a reliable frame. Base salary typically ranges $220K–$280K, with annual bonus targets of 20–30% and RSU grants vesting over 4 years. Total first-year compensation often lands in the $300K–$380K range. Nordstrom's proxy statements confirm competitive equity practices for senior legal roles. The hybrid model also preserves Seattle cost-of-living advantages relative to Bay Area peers.
Career Trajectory: Where This Role Leads
This position sits at a pivotal inflection point. The privacy function at Nordstrom is expanding—"94 applicants in 1 day" suggests organizational investment. A successful Senior Counsel here positions for:
- Chief Privacy Officer track (internal or external) within 3–5 years
- Deputy General Counsel with technology/commercial portfolio
- VP, Legal & Privacy at a high-growth retail-tech or marketplace platform
- Partner-track return to AmLaw 50 with a portable book of business: "I built the AI governance program for a $15B retailer"
The AI governance mandate is the differentiator. Most privacy lawyers react to AI regulation. This role requires you to build the governance framework proactively. That experience is scarce and highly portable across industries.
Application Strategy: Standing Out in a 94-Candidate Pool
With nearly 100 applicants in 24 hours, your application must signal immediate value. Three tactical moves:
- Tailor your resume to the four pillars. Create a "Privacy Leadership" section with quantified bullets: "Reduced DSAR response time from 45 to 18 days via automated workflow," "Drafted generative AI use policy adopted by 3,000-employee organization," "Led breach response for 2.3M record incident across 12 state notification regimes."
- Leverage the Seattle network. Identify Nordstrom legal alumni on LinkedIn (filter by "Nordstrom" + "Legal" + "Seattle"). Request 15-minute coffee chats—not for referrals, but for intelligence: team culture, GC's leadership style, current pain points. Reference those conversations in your cover letter: "Speaking with [Name], I understand the team's current priority is operationalizing MHMDA compliance across the loyalty program..."
- Prepare a 30-60-90 day plan. If you reach the hiring manager screen, bring a one-pager: First 30 days (audit current privacy notice stack against new state laws), 60 days (draft AI vendor assessment questionnaire), 90 days (tabletop breach exercise with InfoSec). This demonstrates the "business-minded" orientation the posting emphasizes.
"The most competitive candidates won't just answer 'have you done X?' They'll answer 'here's how I'd approach X at Nordstrom given your specific retail context.'"
The Hidden Curriculum: What You'll Learn That No CLE Teaches
Beyond the bullet points, this role forces mastery of three competencies that define the next generation of privacy leaders:
- Retail Data Supply Chain Fluency: You'll trace personal data from POS terminals → CDP → ESP → DSP → attribution vendor → clean room → analytics warehouse. Each hop has distinct contractual, regulatory, and technical controls. This systems thinking transfers to any data-intensive industry.
- AI Procurement Governance: Every SaaS vendor now embeds ML. You'll build the due diligence framework that distinguishes "AI washing" from genuine algorithmic risk—model transparency, training data provenance, bias testing, drift monitoring. This skill set is currently rarer than privacy law expertise itself.
- Consumer Trust as Legal Metric: At a brand like Nordstrom, privacy UX is brand equity. You'll collaborate with Design and Product on consent experiences that satisfy regulators and convert. That translation layer—legal requirement → customer experience → business outcome—is where General Counsels are made.
Final Assessment: A Rare Confluence of Scope, Brand, and Timing
Senior in-house privacy roles at consumer-facing Fortune 500 companies with hybrid flexibility, AI governance mandate, and headquarters access appear perhaps once per market cycle. The 7-10 year requirement filters for battle-tested operators. The Washington Bar requirement filters for local commitment. The AI governance requirement filters for forward-looking practitioners. If you clear all three, you're not just qualified—you're the target demographic.
The application window on LinkedIn typically runs 4–6 weeks for roles at this level, but early applicants capture disproportionate attention. The "1 day ago / 94 applicants" timestamp suggests the recruiter is actively screening. Your move: apply this week with a tailored resume, a Seattle-network-informed cover letter, and a mental 30-60-90 plan ready for the first screen.
Frequently Asked Questions
Q: Does Nordstrom sponsor H-1B or other work visas for this role?
A: The job posting does not specify visa sponsorship policy. However, as a Fortune 500 company with a significant technology and legal workforce, Nordstrom has historically sponsored H-1B visas for specialized roles. Candidates requiring sponsorship should apply and disclose status early in the process; the requirement for a Washington State bar license (or immediate eligibility via reciprocity) may simplify the analysis for TN visa holders (Canadian/Mexican citizens) and E-3 visa holders (Australian citizens).
Q: What is the typical interview process timeline for Nordstrom senior legal roles?
A: Based on market patterns for comparable roles, expect: (1) Recruiter screen (30 min), (2) Hiring manager screen with Senior Director/VP Privacy (45–60 min), (3) Panel interview with cross-functional stakeholders (InfoSec, Marketing, Technology, Commercial Legal) (60–90 min), (4) Final conversation with General Counsel or Deputy GC (30–45 min). The process typically spans 3–5 weeks. Given 94+ applicants, the recruiter screen may be more competitive; a tailored application increases odds of advancing past the initial filter.
Q: How does Nordstrom's privacy team structure compare to other major retailers?
A: Unusually, Nordstrom's privacy function sits within Technology rather than Legal—a model more common at tech platforms (Meta, Google, Amazon) than traditional retailers. This signals engineering-first privacy culture: privacy engineers, not just lawyers, own implementation. The Senior Counsel role is an individual contributor embedded in this hybrid team, partnering with privacy engineers on technical controls while owning legal interpretation. This structure accelerates skill development in technical privacy governance—a differentiator for future CPO roles.
Q: What are the most critical Washington State–specific laws this role must master immediately?
A: Beyond the comprehensive privacy statutes (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, OCPA, TDPSA, MCDPA, INCDPA), three Washington-specific regimes demand immediate fluency: (1) My Health My Data Act (MHMDA)—broad consumer health data definition, private right of action, regulates "geofencing" near healthcare facilities; (2) Biometric Privacy Law (RCW 19.375)—notice/consent for biometric identifiers, retention/destruction requirements, private right of action; (3) Consumer Protection Act (CPA)—AG enforcement authority for "unfair/deceptive" data practices, frequently used for privacy violations. The Senior Counsel will own operational compliance for all three.