Not currently open. Kept for reference — do not submit against this role.
🧑🧑🧒🧒 Team & Environment Context
- The Product: Candy.ai — an AI companionship platform. Candidates will be exposed to uncensored, NSFW AI-generated content as part of the job (testing/reviewing the platform) — must be 100% comfortable with that.
- The Role: A generalist Compliance seat owning legal/compliance workflows across data protection (GDPR — DPAs, TIAs), AI governance documentation, product/feature compliance reviews, IP (DMCA, copycats), contract review (NDAs, licenses), and legal terms upkeep (ToS, Privacy Notice, content policy). Guided by and works side-by-side with Maxwelle Sokol (Legal & Safety Lead, US-trained lawyer, 10+ years litigation/in-house).
- The Focus: Breadth over depth — the JD explicitly doesn't expect experience in every category, but does expect a doer mindset and motivation to learn unfamiliar legal areas fast.
- The Bar: A generalist who can handle the wide array of legal/compliance topics that come in. We don't expect experience in every category listed — a doer mindset and motivation to learn is non-negotiable.
🎯 Calibration Anchors & Target Profiles
⛔️ Non-Negotiables
- Legal education — Masters of Law, JD, or recognized legal certification. Not necessarily a licensed attorney.
- 2–6 years relevant experience, including at least 2 years working with contracts generally and data protection law specifically (e.g. GDPR, CCPA, LGPD) — can speak concretely to preparing a DPA/TIA and has experience contacting vendors on contract issues.
- NSFW comfort — 100% dealbreaker; must be comfortable reviewing and discussing uncensored AI-generated content directly.
- Fluent, plain-English communicator — can distill complex legal concepts for non-legal stakeholders.
- Doer mindset / generalist adaptability — balances execution, planning, and strategy; comfortable picking up unfamiliar compliance topics without a narrow specialist lane.
- Backbone with stakeholders — can push back and say no on compliance grounds, even under pressure to move fast, without being obstructive for its own sake.
✨ Nice-to-have
- Full attorney/legal counsel certification
- Experience in high-growth startups, B2C, and/or AI compliance specifically
- Additional language fluency
📋 Evaluation Framework
1. Legal & Compliance Execution — 40%
Legal education plus 2–6 years as legal counsel or similar, including at least 2 years on contracts and data protection law specifically — can speak concretely to preparing a DPA/TIA, contacting vendors on contract issues, and the day-to-day compliance workload (IP, contract reviews, terms updates, tracking legal developments).
Hard Filters: no legal education; no contracts or data-protection experience.
2. Doer Mindset, Ownership & Humility — 25%
Goal-oriented, takes ownership and commitment; balances execution, planning, and strategy; humble and open to feedback, willing to learn unfamiliar legal topics rather than staying in a narrow lane.
Hard Filters: not coachable; no delivery language; unwilling to work outside a narrow specialty.
3. Communication & Cross-functional Collaboration — 20%
Distills complex legal concepts into plain English for non-legal stakeholders; strong, collaborative communicator; fully fluent in English; works well with regular guidance from Maxwelle Sokol. Has the backbone to push back and say no to stakeholders on compliance grounds, even under pressure to move fast.
Hard Filters: can't explain legal concepts in plain English; not fluent in English; can't meet the 4+ hr/day CET overlap; folds under stakeholder pressure instead of holding a compliance line.
4. NSFW Comfort & AI Interest — 15%
Genuinely comfortable reviewing and discussing uncensored, NSFW AI-generated content; professional experience with or interest in AI.
Hard Filters: hesitant or moralizes on the NSFW question.
💬 Screening Questions
Use these questions during your screening call. Include a summary of the candidate's answers in your submission notes in Ashby.
- Our product involves AI companionship and uncensored, adult-oriented content — you'd be reviewing and discussing NSFW material directly as part of this role. Are you fully comfortable with that?
- Walk me through your experience with data protection law — have you prepared a DPA or Transfer Impact Assessment? What did that process actually involve?
- Do you have experience in trust & safety or moderation on online platforms? Tell me about it.
- This role spans GDPR, AI governance documentation, IP, contract review, and policy updates — a generalist mix. How do you approach picking up an unfamiliar legal area quickly?
- Do you have professional experience in the online B2C context? Tell me about it.
- Tell me about a time you had to push back on a stakeholder or say no on compliance grounds — even when there was pressure to move fast. What happened, and how did you handle it?
- What are the top 2–3 things you're looking for in your next opportunity?