MetaCompliance is the European leader in cybersecurity awareness, specialising in providing cutting-edge solutions for businesses. Our innovative platform personalises training and drives real behavioural change, enhancing cybersecurity awareness of employees across all organisations in our customer base.
We are looking for an experienced, commercially minded in-house counsel to join our legal team. This role will be central to our contracting engine — leading negotiation of customer, vendor, and partner agreements — while also acting as a versatile generalist across corporate, privacy, product, and operational matters as we scale our SaaS business.
This is an excellent opportunity for a pragmatic, business-oriented lawyer who enjoys moving fast, solving problems creatively, and being a trusted advisor across the organization.
What You'll Do
Contract Negotiation (Primary Focus)
- Own end-to-end negotiation of customer agreements (negotiating MetaCompliance terms and conditions, or customer MSAs / SOWs / tenders).
- Negotiate vendor, supplier, and reseller/partner agreements
- Draft, review, and maintain a suite of contract templates and playbooks to improve deal velocity and consistency and provide training and guidance to internal stakeholders
- Partner closely with Sales, Customer Success, and Finance to balance commercial goals with risk tolerance
- Identify recurring negotiation friction points and drive process improvements (e.g., redlining guidelines, fallback positions, approval workflows)
- Utilise our contract lifecycle management tool to review and negotiate contracts, consistently and continually identifying trends and working towards improving processes and increasing efficiency
Privacy & Data Protection
- Advise on data privacy matters arising in commercial contracts, including DPAs, SCCs, and cross-border data transfer terms
- Support compliance with applicable privacy laws (e.g., GDPR and other relevant regimes)
- Work with Security and Product teams on privacy-by-design considerations for new features and data flows
Product & Commercial Support
- Partner with Product and Engineering on legal considerations for new feature and product launches (terms of use, licensing terms, AI/data usage terms, third-party integrations, IP considerations)
Corporate & Operational Matters
- Support general corporate matters: entity management, subsidiary governance, board materials, and corporate housekeeping
- Assist with equity, financing, or M&A-related work, as needed
- Contribute to policy development (employment-adjacent policies, vendor risk management, records retention, etc.)
- Provide practical, business-friendly legal advice across departments as the company scales
What We're Looking For
- 8+ years PQE gained in private practice or (preferred) a combination of in-house and private practice experience.
- Qualified lawyer in good standing (in any UK Jurisdiction, France or Germany).
- Experience negotiating SaaS/technology commercial contracts (customer-facing and vendor-facing)
- Solid working knowledge of data privacy law (GDPR, or equivalent) and practical experience handling DPAs and data transfer mechanisms
- Demonstrated ability to work as a generalist — comfortable moving between contracts, privacy, corporate, and product legal questions in the same week
- Strong business judgment: able to identify real risk vs. theoretical risk, and give clear, actionable guidance
- Excellent drafting, negotiation, and communication skills, with the ability to explain legal concepts to non-lawyers
- Comfortable operating with autonomy in a fast-paced, lean legal team environment
- Experience with entity management and basic corporate governance is a plus
- Prior experience supporting product launches or working closely with Product/Engineering teams is a plus
Skills Required
- 8+ years of post-qualification experience gained in private practice or a combination of in-house and private practice experience
- Qualified lawyer in good standing in any UK jurisdiction, France, or Germany
- Experience negotiating SaaS or technology commercial contracts, including customer-facing and vendor-facing agreements
- Working knowledge of data privacy law, including GDPR or equivalent, with practical experience handling DPAs and data transfer mechanisms
- Ability to work as a legal generalist across contracts, privacy, corporate, and product matters
- Strong business judgment and ability to provide clear, actionable guidance
- Excellent drafting, negotiation, and communication skills, including explaining legal concepts to non-lawyers
- Ability to operate autonomously in a fast-paced, lean legal team environment
- Experience with entity management and basic corporate governance
- Experience supporting product launches or working closely with Product and Engineering teams
What We Do
With 18+ years of experience in the Cyber Security and Compliance market, MetaCompliance provides an innovative solution for staff information security awareness and incident management automation. The MetaCompliance platform was created to meet customer needs for a single, comprehensive solution to manage the people risks surrounding Cyber Security, Data Protection and Compliance. The solution provides an easier approach to managing ISO27001, NIST and Cyber Security Resilience. Our focus on staff awareness and security risk management enables customers to benefit from functionality that includes eLearning, simulated phishing, policy management, incident management regulatory reporting. Our SaaS platform offers the highest quality cyber security and compliance training content available on the market. It is easy to use, engaging and regularly updated; allowing cyber and compliance professionals to track progress of their staff members and demonstrate human risk reduction. MetaCompliance has a unique focus on encouraging participation by employees with Personalised Security Awareness. This leverages behavioural science best practices to make security awareness meaningful for each employee. This means providing training content that is in the correct language and relevant to each person’s role and department. In addition, the content is customised to leverage brand loyalty, reflect the unique organisational practices and reflect their specific approach to threat mitigation. By leveraging the power of MetaCompliance, customers can optimise their cyber security and compliance response to meet the demands of today’s digital world.







