Senior Legal Counsel - Privacy

United Kingdom
Legal – Compliance /
Permanent /
Remote
About Us
Sophos is a worldwide leader and innovator of advanced cybersecurity solutions, including Managed Detection and Response (MDR) and incident response services and a broad portfolio of endpoint, network, email, and cloud security technologies that help organizations defeat cyberattacks. As one of the largest pure-play cybersecurity providers, Sophos defends more than 500,000 organizations and more than 100 million users globally from active adversaries, ransomware, phishing, malware, and more. Sophos’ services and products connect through its cloud-based Sophos Central management console and are powered by Sophos X-Ops, the company’s cross-domain threat intelligence unit. Sophos X-Ops intelligence optimizes the entire Sophos Adaptive Cybersecurity Ecosystem, which includes a centralized data lake that leverages a rich set of open APIs available to customers, partners, developers, and other cybersecurity and information technology vendors. Sophos provides cybersecurity-as-a-service to organizations needing fully managed, turnkey security solutions. Customers can also manage their cybersecurity directly with Sophos’ security operations platform or use a hybrid approach by supplementing their in-house teams with Sophos’ services, including threat hunting and remediation. Sophos sells through reseller partners and managed service providers (MSPs) worldwide. Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com. 

Role Summary

We are searching for an experienced, pragmatic, and process-minded lawyer to join our Legal Team to serve as Privacy Counsel to the Company and to lead the existing Privacy Team in its day-to-day data protection and data governance functions, as well as cross-functional work to limit and act on data breaches. This is a multi-faceted global legal role in in which you will own the regulatory requirements governing data protection, subject matter expert on privacy agreements, lead privacy requirements for data governance, and develop privacy and data protection for the Team going forward. We need an experienced privacy lawyer who is genuine, dynamic, forward thinking, and a team player. You will report to the VP, Regulatory & Associate General Counsel.

What You Will Do:

    • Lead the Privacy Team in its work driving Data Protection, Data Governance, regulatory compliance, legal advice on privacy matters, to bring this Team to excellence in its function
    • Subject matter expert to Commercial lawyers on third party agreements and the Company’s Data Processing Agreements (DPAs)
    • Perform Privacy Reviews on the Company’s new product launches.
    • Drive operational processes that guide the Team’s Data Protection functions
    • Drive operational processes that guide the Team’s Data Governance functions
    • Support the Security Team with legal advice and practical input regarding data breach, the Company’s Incident Response Plan, and regulatory reporting
    • Support the Legal Team’s Employment lawyers with legal advice on privacy matters.
    • Support Privacy Team in its development and implementation of best practices that create and make daily use of a universal platform for Privacy regulatory requirements, including Privacy by Design and bringing forward Privacy as a strategic advantage for the Company 
    • Partner with and leverage the services provided by Sophos DPO, including data privacy regulatory developments, DPO registrations, and jurisdictional privacy regulatory requirements
    • Partner with security teams and cross-functional stakeholders to advise on privacy issues, support security incident investigations, support privacy-specific incident matters including legal advice about customers and partners regarding privacy issues
    • Review, advise, and close on privacy requirements in Sophos products, working with product management and engineering teams to provide early privacy counselling on new products and product features
    • Support Sales teams to anticipate and align privacy requirements with product use in countries where Sophos products are sold
    • Work with Legal Commercial and Contract Teams to advise on privacy requirements, negotiate Data Processing Agreements, address special privacy scenarios, including the updating, revising, and monitoring of advisory playbooks, templates, standard contract clauses, and escalations
    • Serve as an available resource to all members of the Legal Team to address privacy issues as they impact or apply to their respective practice areas

What You Will Bring:

    • Admitted to practice law in the country where your associated Sophos office is located
    • 5+ years of relevant experience, including in-house experience with a high-tech company or a more senior lawyer with significant privacy experience
    • Deep experience with privacy and data protection laws and managing a multinational organization’s compliance with such laws
    • Proven ability to translate technical knowledge into pragmatic advice that appropriately balances legal risks with commercial requirements in Sophos products
    • Experience providing privacy counselling to product and engineering teams on privacy considerations for product development and new product/product feature launch
    • Experience drafting and negotiating privacy, security, and confidentiality terms in commercial agreements, including data processing agreements
    • Strong interpersonal skills with an ability to successfully counsel and interact with senior management
    • Self-starter with ability to execute tasks efficiently with sound business judgment and attention to detail
    • A proven ability to manage and prioritize a complex workload
    • Experience as privacy counsel in jurisdictions outside EU, UK, and US

    • Desirable

    • CIPP certification is a plus
    • Technical or engineering background in software products is a plus
    • Experience in Office 365 and useful privacy apps
    • Experience with OneTrust 
#B2

Ready to Join Us?
At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply.

What's Great About Sophos?
·   Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. Please refer to the location details in our job postings for further information.
·   Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit
·   Employee-led diversity and inclusion networks that build community and provide education and advocacy
·   Annual charity and fundraising initiatives and volunteer days for employees to support local communities
·   Global employee sustainability initiatives to reduce our environmental footprint
·   Global fitness and trivia competitions to keep our bodies and minds sharp
·   Global wellbeing days for employees to relax and recharge 
·   Monthly wellbeing webinars and training to support employee health and wellbeing

Our Commitment To You
We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity.   We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team.  All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation.  We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. 

Data Protection
If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos.  If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights.  If you have any questions about Sophos’ data protection practices, please contact dataprotection@sophos.com.