Zello The Contracts Manager at Zello owns the end-to-end customer and vendor contracting lifecycle including NDAs, MSAs, DPAs, and security exhibits. This role supports governance, risk, and compliance programs and builds contracting infrastructure.
Responsibilities
Own the customer contract lifecycle: review, redline, and negotiate NDAs, MSAs, DPAs, AI data-processing addendums, BAAs, amendments, and security exhibits from first draft to signature.
Decide when an issue is genuinely novel enough to loop in outside counsel - and handle everything else yourself.
Build the contracting infrastructure: playbooks, fallback positions, template libraries, and the escalation bar that keeps routine deals out of anyone else's inbox.
Own the vendor lifecycle: intake, due diligence, tiering, approval, renewal, and termination.
Run data subject requests in support of GDPR) and subpoena/legal-request intake end-to-end,and track the contractual notification commitments tied to Zello products and AI data changes to support compliance with respective requirements.
Support the administration of Zello's compliance stack - Drata, KnowBe4 - and run the policy lifecycle (drafting, review cadence, attestation) and periodic access reviews.
Use AI on the repetitive parts of this work - first-pass review, questionnaire drafting, clause comparison, obligation tracking - and keep improving how you use it.
Qualification
You are at home in the detailYou are already using AI in your workThis role is not
Required
You are organized to a degree other people find slightly excessive. Every open redline, obligation, and renewal date is tracked, and nothing falls off.
You are at home in the detail. A DPA with three conflicting definitions of “Personal Data” is a puzzle you enjoy, not a chore you dread.
Law was a real consideration for you at some point - you may have prepped for the LSAT, worked shoulder-to-shoulder with attorneys, or come close to applying - and you concluded the operating side of legal is where you do your best work.
You are already using AI in your work, or you are impatient to. You don't need to know how the models work; you need to believe the first draft should come from a machine and your judgment should be spent on what matters.
GRC is new to you and that reads as interesting rather than intimidating. You've noticed it runs on the same things contracting does - structure, evidence, follow-through - and you want the surface area.
You spot a manual or error-prone process before anyone points it out, and you fix it - building a clause library instead of redlining from scratch every time.
You communicate clearly and concisely with Sales, Customer Success, Engineering, and outside counsel, without over-explaining or leaving people guessing.
This role is not
An attorney role - no JD or bar admission is required or expected. Outside counsel handles the genuinely novel; you handle the rest.
A management role - there are no direct reports.
A GRC or security engineering role - you own the compliance program's operational rigor, not the underlying technical controls (IAM, SIEM, pen testing), and you do not need a GRC background walking in.
A redline-only role - contracting is the core, but vendor management and the compliance program's operational cadence come with it.