Senior Legal Counsel
New Yesterday
Sophos is a global leader and innovator of advanced security solutions for defeating cyberattacks. In February 2025 the company acquired Secureworks, bringing together two pioneers that have redefined the cybersecurity industry with their innovative, native AI‑optimized services, technologies and products. Sophos is now the largest pure‑play Managed Detection and Response (MDR) provider, supporting more than 28,000 organizations. Sophos’ complete portfolio includes industry‑leading endpoint, network, email, and cloud security that interoperate and adapt to defend through the Sophos Central platform. Secureworks provides the innovative, market‑leading Taegis XDR/MDR, identity threat detection and response (ITDR), next‑gen SIEM capabilities, managed risk and a comprehensive set of advisory services. Sophos sells all these solutions through reseller partners, Managed Service Providers (MSPs) and Managed Security Service Providers (MSSPs) worldwide, defending more than 600,000 organizations worldwide from phishing, ransomware, data theft, and other everyday and state‑sponsored cybercrimes. The solutions are powered by historical and real‑time threat intelligence from Sophos X‑Ops and the newly added Counter Threat Unit (CTU). Sophos is headquartered in Oxford, U.K. More information is available at www.sophos.com.
Role Summary
This role demands a strong understanding of cybersecurity laws and regulations impacting the providers of cybersecurity services and products, including their impact on AI, data protection, the licensing of products and services, and the reporting of security incidents that arise from cybersecurity laws and regulations; and a strong understanding of cybersecurity laws and regulations impacting the users of cybersecurity products and services in regulated industries, including their requirements for material outsourcing, audit, and certification. This role requires a lawyer who can distill legal and regulatory requirements into actionable business processes that protect the enterprise and into technical sales and marketing data that communicates compliance‑ready products and services available from a cybersecurity technology provider to users that exist in a regulated industries environment.
Key Responsibilities
- Perform industry sector impact assessments, understand user requirements, and act on enterprise licensing requirements in various jurisdictions.
- Evolve and maintain reporting of incident matters to determine reportable data; report to cybersecurity authorities in various jurisdictions.
- Conduct legal research and provide day‑to‑day advice to the business about cybersecurity regulations, data protection, security requirements, audit and certification.
- Produce policies, standard operating procedures, and governing regulatory criteria for the Company.
- Work cross‑functionally with Security, Marketing, Sales, Privacy and the broader Legal Team.
- Report to the VP, Regulatory and Associate General Counsel based in the U.S.; offer flexibility to be based anywhere within the U.S., U.K., Canada, or EU.
What You Will Do
- Own lead responsibility for tracking, monitoring, and driving into the business customer purchase and use requirements arising from worldwide cybersecurity regulations.
- Work cross‑functionally with products, marketing, sales, and products to support regulatory frameworks that guide customer purchase and use requirements arising from worldwide cybersecurity regulations.
- Fulfill all licensing requirements for rendering cybersecurity services required under new and existing worldwide cybersecurity regulations.
- Evaluate and report enterprise security incidents in all jurisdictions as required under new and existing worldwide cybersecurity regulations.
- Review and understand worldwide data protection and artificial intelligence laws and regulations, and their impact on cybersecurity, to support regulatory advice to the business.
- Contribute to AI use case and legal guidance arising from AI regulatory requirements.
- Work cross‑functionally to support the Certification Team to drive worldwide cybersecurity regulatory requirements into business certifications.
- Create standard operating procedures that support functions owned by this role.
- Host sessions with stakeholders to build awareness of cybersecurity regulatory requirements and internal processes.
- Serve as the company contact for legal advice guiding cybersecurity regulatory requirements, including those impacting standard contract issues, sales and marketing, product, business certification, information security, and licensing.
- Develop, maintain, and enhance a global cybersecurity regulatory platform.
- Conduct legal research into a variety of topics and produce clear and concise guidance.
- Manage a varied workload and business expectations amid tight timelines.
What You Will Bring
- 7+ years’ experience as an in‑house counsel or equivalent experience in a national law firm performing regulatory counsel work.
- A strong operational knowledge of regulations that impact the users of technology, including cybersecurity, and an understanding of laws, regulations, and standards impacting data protection and artificial intelligence.
- Develop and drive into the business the cybersecurity regulatory requirements defining the purchase and user decisions of customers operating in regulated industries.
- Proven ability to perform functional legal research into a variety of cybersecurity legal and regulatory requirements; make a practical application of legal research results; and advise the Sophos business in a clear and concise manner.
- Prioritize and manage regulatory requirements that impact the business and require reporting or licensing with specific cybersecurity regulatory authorities.
- Experience working in a global company across multiple jurisdictions and advising a varied set of business functions.
- An ability to work cross‑functionally with business teams to support their objectives and key results.
- Strong organizational skills and an ability to prioritize and manage a varied workload.
- Excellent oral and written communication and presentation skills.
- Strong attention to detail and analytical skills.
- Collaborative spirit, positive attitude, and high level of integrity.
- Fluency in English is mandatory; additional European languages are helpful.
Ready to Join Us?
At Sophos, we believe in the power of diverse perspectives to fuel innovation. If your unique experience and skills could help us grow, we encourage you to apply. We challenge the notion that you must check every box to be considered.
What's Great About Sophos?
- Remote‑first working model, with hybrid options for certain roles.
- Global diversity and inclusion networks, charity and volunteer initiatives, sustainability projects, and fitness and well‑being programs.
- Dedicated training and wellness webinars, as well as annual health and autism inclusion initiatives.
Our Commitment To You
We are committed to ensuring equality of opportunity and encouraging a diverse workforce. All applicants will be treated fairly and equally in accordance with the law.
Data Protection
Personal details shared with Sophos will be retained for 12 months and used by our recruitment team to contact you about relevant opportunities. For more information, consult our Privacy Policy.
Seniority level
Not Applicable
Employment type
Contract
Job function
Legal
Industries
Software Development
Referrals increase your chances of interviewing at Sophos by 2x.
- Location:
- United Kingdom
- Salary:
- £125,000 - £150,000
- Job Type:
- PartTime
- Category:
- Legal