Cyber, Privacy and Resilience Legal Counsel
Cyber, Privacy & Resilience Legal Counsel, Glasgow
The Opportunity
We are working with a leading global financial services institution to recruit a Cyber, Privacy & Resilience Legal Counsel to join its legal function.
The organisation is a highly sophisticated international financial institution with a significant global presence and a diverse range of businesses spanning investment banking, securities, wealth management and asset management. The successful candidate will join a specialist legal team supporting the organisation on a broad range of matters relating to cybersecurity, data privacy, technology risk and operational resilience.
This is an excellent opportunity for a lawyer with strong experience in technology, privacy, cyber or financial services regulation to work closely with senior stakeholders across Legal, Compliance, Technology, Information Security, Risk and the wider business.
Key Responsibilities
The successful candidate will provide legal advice and support across a broad range of cyber, privacy and resilience matters, including:
- Advising on cybersecurity, technology risk and information security issues arising across the organisation.
- Providing legal advice on data privacy and data protection, including the collection, use, transfer, retention and sharing of personal data.
- Supporting the business on operational resilience and technology resilience requirements, including regulatory expectations and emerging legal obligations.
- Advising on the legal implications of cyber incidents, data breaches and other technology-related events, including incident response and regulatory notification considerations.
- Supporting the development, review and implementation of policies, procedures, standards and governance frameworks relating to cyber, privacy and resilience.
- Advising on relevant technology and outsourcing arrangements, including contractual provisions relating to data protection, cybersecurity, business continuity, audit rights, incident management and regulatory access.
- Working with procurement and commercial legal teams on technology, cloud, software and other third-party arrangements.
- Monitoring and advising on new and emerging legislation and regulatory requirements affecting cybersecurity, privacy, technology and operational resilience.
- Supporting the organisation in responding to regulatory enquiries, examinations and information requests relating to cyber, privacy and resilience matters.
- Working closely with internal stakeholders to identify legal and regulatory risks and develop practical, commercially appropriate solutions.
- Providing clear and concise advice to senior stakeholders and business teams on complex and evolving areas of regulation.
- Supporting broader legal and regulatory projects, including cross-border initiatives and strategic technology programmes.
Key Stakeholders
The role will involve extensive collaboration with stakeholders across the organisation, including:
- Legal and Compliance
- Information Security / Cybersecurity
- Technology and Engineering
- Enterprise Risk
- Operational Resilience
- Data Privacy
- Procurement and Vendor Management
- Internal Audit
- Business and Operations teams
- Senior management and governance committees
Candidate Profile
We are looking for a qualified lawyer with relevant experience in one or more of the following areas:
- Cybersecurity and information security
- Data privacy / data protection
- Technology law
- Operational resilience
- Technology risk
- Financial services regulation
- Technology outsourcing and third-party risk
The ideal candidate will have:
- Strong academic and professional credentials.
- Relevant experience gained within a leading law firm, financial institution, technology business, regulator or similarly sophisticated organisation.
- A strong understanding of privacy, cybersecurity and/or technology regulation, ideally within a financial services environment.
- Experience advising on complex, cross-border matters and working with multiple stakeholders.
- The ability to translate complex legal and regulatory requirements into clear, practical and commercially focused advice.
- Excellent drafting, communication and stakeholder management skills.
- The confidence to engage with senior business, technology, risk and legal stakeholders.
- A pragmatic and solutions-oriented approach, with the ability to operate effectively in a fast-paced and highly regulated environment.
Why Consider the Role?
This is an opportunity to join a highly regarded global financial institution at a time when cybersecurity, data protection and operational resilience are increasingly central to the legal and regulatory landscape.
The role offers significant exposure to senior stakeholders and complex, high-profile matters at the intersection of law, technology, regulation and financial services, as well as the opportunity to work on emerging issues in a rapidly developing area.
The successful candidate will play an important role in helping the organisation navigate an increasingly complex cyber, privacy and resilience environment while supporting strategic technology and business initiatives.