Senior Legal Counsel

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
152K-253K
Senior level
Security • Software
The Role
The Senior Legal Counsel will manage cybersecurity regulatory compliance, advise business functions, and create necessary policies. Responsibilities include legal research, incident reporting, and maintaining a regulatory platform.
Summary Generated by Built In
About Us
Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. The company acquired Secureworks in February 2025, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI-optimized services, technologies and products. Sophos is now the largest pure-play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. In addition to MDR and other services, Sophos’ complete portfolio includes industry-leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market-leading Taegis XDR/MDR, identity threat detection and response (ITDR), next-gen SIEM capabilities, managed risk, and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, other every day and state-sponsored cybercrimes. The solutions are powered by historical and real-time threat intelligence from Sophos X-Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.

Role Summary
This role demands a strong understanding of cybersecurity laws and regulations impacting the providers of cybersecurity services and products, including their impact on AI, data protection, the licensing of products and services, and the reporting of security incidents that arise from cybersecurity laws and regulations; and a strong understanding of cybersecurity laws and regulations impacting the users cybersecurity products and services in regulated industries, including their requirements for material outsourcing, audit, and certification. This role requires a lawyer who can distill legal and regulatory requirements into actionable business processes that protect the enterprise and into technical sales and marketing data that communicates compliance-ready products and services available from a cybersecurity technology provider to users that exist in a regulated industries environment. 
 
Key responsibilities include performing industry sector impact assessments, understanding user requirements, acting on enterprise licensing requirements in various jurisdictions, evaluating incident matters to determine reportable data, reporting to cybersecurity authorities in various jurisdictions, legal research, providing day-to-day advice to the business about cybersecurity regulations, understanding the impact of cybersecurity regulations on data protection, security requirements, audit, and certification, and producing policies, standard operating procedures, and governing regulatory criteria for the Company.  This role will work cross-functionally with Security, Marketing, Sales, Privacy and the broader Legal Team. This role will report to the VP, Regulatory and Associate General Counsel based in the U.S. and offers flexibility to be based anywhere within the U.S, U.K., Canada, or EU.

What You Will Do

  • Own lead responsibility for tracking, monitoring, and driving into the business customer purchase and use requirements arising from worldwide cybersecurity regulations
  • Work cross-functionally with products, marketing, sales, and products to support regulatory frameworks that guide customer purchase and use requirements arising from worldwide cybersecurity regulations
  • Fulfill all licensing requirements for rendering cybersecurity services required under new and existing worldwide cybersecurity regulations
  • Evaluate and report enterprise security incidents in all jurisdictions as required under new and existing worldwide cybersecurity regulations
  • Review and understand worldwide data protection and artificial intelligence laws and regulations, its impact on cybersecurity, to support regulatory advice to the business
  • Contribute to AI use case and legal guidance arising from AI regulatory requirements
  • Work cross-functionally to support Certification Team to drive worldwide cybersecurity regulatory requirements into business certifications
  • Create standard operating procedures that support functions owned by this role
  • Host sessions with stakeholders to build awareness of cybersecurity regulatory requirements and internal processes
  • Be the Company contact for legal advice guiding cybersecurity regulatory requirements, including those impacting standard contract issues, sales and marketing, product, business certification, information security, and licensing
  • Develop, maintain, and enhance a global cybersecurity regulatory platform
  • Conduct legal research into a variety of topics and produce clear and concise guidance
  • Manage a varied workload and manage business expectations amid tight timelines

What You Will Bring

  • 7+ years’ experience as an in-house counsel or equivalent experience in a national law firm performing equivalent regulatory counsel work
  • A strong operational knowledge of regulations that impact the users of technology, including cybersecurity, and an understanding of laws, regulations, and standards impacting data protection and artificial intelligence
  • Develop and drive into the business the cybersecurity regulatory requirements defining the purchase and user decisions of customers operating in regulated industries
  • Proven ability to perform functional legal research into a variety of cybersecurity legal and regulatory requirements, make a practical application of legal research results, and advise the Sophos business in a clear and concise manner
  • Prioritize and manage regulatory requirements that impact the business and require reporting or licensing with specific cybersecurity regulatory authorities
  • Experience working in a global company across multiple jurisdictions and advising a varied set of business functions
  • An ability to work cross-functionally with business teams to support their objectives and key results
  • Strong organizational skills and an ability to prioritize and manage a varied workload
  • Excellent oral and written communication and presentation skills
  • Strong attention to detail and analytical skills
  • Collaborative spirit, positive attitude, and high level of integrity
  • Fluency in English is mandatory, additional European languages are helpful

In the United States, the base salary for this role ranges from $152,000 to $253,000. In addition to base salary, we offer additional  compensation including bonus eligibility and a comprehensive benefits package.  A candidate’s specific pay within this range will depend on a variety of factors, including job-related skills, training, location, experience, relevant education, certifications, and other business and organizational needs. 

#li-remote
#B2
#li-ND2

Ready to Join Us?
At Sophos, we believe in the power of diverse perspectives to fuel innovation. Research shows that candidates sometimes hesitate to apply if they don't check every box in a job description. We challenge that notion. Your unique experiences and skills might be exactly what we need to enhance our team. Don't let a checklist hold you back – we encourage you to apply.

What's Great About Sophos?
·   Sophos operates a remote-first working model, making remote work the primary option for most employees. However, some roles may necessitate a hybrid approach. While we are a remote first organization, applicants must have legal authorization to work in the jurisdiction where the position is posted, without requiring employer sponsorship.
·   Our people – we innovate and create, all of which are accompanied by a great sense of fun and team spirit
·   Employee-led diversity and inclusion networks that build community and provide education and advocacy
·   Annual charity and fundraising initiatives and volunteer days for employees to support local communities
·   Global employee sustainability initiatives to reduce our environmental footprint
·   Global fitness and trivia competitions to keep our bodies and minds sharp
·   Global wellbeing days for employees to relax and recharge 
·   Monthly wellbeing webinars and training to support employee health and wellbeing

Our Commitment To You
We’re proud of the diverse and inclusive environment we have at Sophos, and we’re committed to ensuring equality of opportunity.   We believe that diversity, combined with excellence, builds a better Sophos, so we encourage applicants who can contribute to the diversity of our team.  All applicants will be treated in a fair and equal manner and in accordance with the law regardless of gender, sex, gender reassignment, marital status, race, religion or belief, color, age, military veteran status, disability, pregnancy, maternity or sexual orientation.  We want to give you every opportunity to show us your best self, so if there are any adjustments we could make to the recruitment and selection process to support you, please let us know. 

Data Protection
If you choose to explore an opportunity, and subsequently share your CV or other personal details with Sophos, these details will be held by Sophos for 12 months in accordance with our Privacy Policy and used by our recruitment team to contact you regarding this or other relevant opportunities at Sophos.  If you would like Sophos to delete or update your details at any time, please follow the steps set out in the Privacy Policy describing your individual rights.  For more information on Sophos’ data protection practices, please consult our Privacy Policy Cybersecurity as a Service Delivered | Sophos

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Burlington, MA
3,747 Employees
Year Founded: 1985

What We Do

Cybersecurity Evolved.

As a worldwide leader in next-generation cybersecurity, Sophos protects nearly 400,000 organizations of all sizes in more than 150 countries from today’s most advanced cyberthreats.

Powered by SophosLabs – a global threat intelligence and data science team – Sophos’ cloud-native and AI-enhanced solutions secure endpoints (laptops, servers and mobile devices) and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more.

Similar Jobs

Coinbase Logo Coinbase

Senior Counsel

Artificial Intelligence • Blockchain • Fintech • Financial Services • Cryptocurrency • NFT • Web3
Remote
United States
225K-265K Annually

Garner Health Logo Garner Health

Legal Counsel

Big Data • Healthtech • HR Tech • Machine Learning • Software • Telehealth • Big Data Analytics
Easy Apply
Remote
USA
210K-240K

H.B. Fuller Logo H.B. Fuller

Legal Counsel

Industrial • Manufacturing
Remote
USA
145K-190K Annually
In-Office or Remote
2 Locations
170K-200K Annually

Similar Companies Hiring

Credal.ai Thumbnail
Software • Security • Productivity • Machine Learning • Artificial Intelligence
Brooklyn, NY
Standard Template Labs Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
10 Employees
PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account