1 день назад
Assistant General Counsel
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Assistant General Counsel (Privacy and Data Protection): Advising on international privacy, data protection, cybersecurity, and contract matters across KBRA’s Ireland, UK, EU, US, and international operations with an accent on GDPR, cross-border data transfers, ePrivacy, and privacy-sensitive agreements. Focus on conducting impact assessments, coordinating breach response, negotiating DPAs and commercial contracts, and monitoring developments in AI and privacy regulation.
Location: Dublin, Ireland or London, England; flexible hybrid schedule with office attendance on Tuesdays, Wednesdays, and Thursdays.
Company
is a full-service credit rating agency operating across the US, UK, EU, and broader international markets.
What you will do
- Advise on international privacy, data protection, cybersecurity, ePrivacy, cookies, and direct marketing laws, including GDPR, UK GDPR, CCPA/CPRA, and the ePrivacy Directive.
- Research privacy requirements across jurisdictions and support the implementation and maintenance of privacy, data protection, cybersecurity, operational resilience, and regulatory practices.
- Conduct privacy impact assessments, legitimate interest assessments, records of processing activities, vendor due diligence, and cross-border data transfer reviews.
- Draft, review, and negotiate data processing agreements, non-disclosure agreements, vendor contracts, client engagement letters, and subscription agreements.
- Support incident and breach response in collaboration with Technology, Information Security, Compliance, Marketing, Business Development, external counsel, regulators, and auditors.
- Monitor developments in privacy, data protection, cybersecurity, and AI; update privacy notices and policies; and deliver internal training and governance materials.
Requirements
- Qualifying law degree or equivalent and admission to practise as a solicitor in Ireland or England & Wales, with a current practising certificate or equivalent authorization to practise.
- 4–8 years of post-qualification experience with hands-on exposure to privacy and data protection law.
- Strong experience drafting, reviewing, and negotiating contracts, especially DPAs, vendor agreements, client contracts, and other privacy-sensitive clauses.
- Demonstrated knowledge of EU and UK GDPR, cross-border data transfer mechanisms, ePrivacy laws, vendor and third-party risk, and cybersecurity fundamentals.
- Excellent verbal and written communication, research, analytical, organizational, and project management skills, with the ability to explain legal and technical privacy concepts to non-legal stakeholders.
Nice to have
- IAPP certification such as CIPP/E, CIPP/US, or CIPM.
- Experience in regulated environments, particularly financial services, technology, data, or analytics.
- Familiarity with generative AI tools such as ChatGPT for research, data insights, and productivity.
Culture & Benefits
- Flexible hybrid work schedule with regular office collaboration.
- Competitive benefits and paid time off.
- Pension plan.
- Financial assistance for educational and professional development.
- Employee referral bonus program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →