Legal Counsel - Security & Privacy

Adobe Adobe · Enterprise · Bucharest, Romania

Legal Counsel role at Adobe focusing on global cybersecurity, data protection laws, SaaS tech, and AI. The role provides strategic and operational legal support for security and technology initiatives, ensuring compliance with evolving regulations and enabling business innovation. Responsibilities include partnering with cross-functional teams, staying updated on legal developments, assisting with incident response programs, conducting privacy assessments, and reviewing/drafting contracts related to data, privacy, and security. The role also involves developing cybersecurity legal training and serving as a point of contact for regulatory engagement.

What you'd actually do

  1. Partner closely with cross-functional teams (e.g., Third Party Risk Management (TPRM), Security, IT, Product, Engineering, Marketing, and other Corporate teams) to assess and provide guidance on potential security risks and regulatory requirements our business operations, as well as for our products and services.
  2. Stay current on evolving cybersecurity, information security, information technology, and data breach notification laws, developments, and frameworks (e.g., DORA, NIS 2, and CRA) in order to provide practical and strategic advice to the business, Security and IT.
  3. Assist in leading the development, enhancement, maintenance, and compliance activities for our global incident response program.
  4. Provide legal analysis regarding notification obligations for Adobe’s incident response efforts.
  5. Provide periodic review and drafting to help maintain Adobe's global security, IT, and data governance policies, standards, and processes.

Skills

Required

  • Proficiency in Romanian and English languages
  • Law degree or equivalent
  • Fully qualified lawyer with a minimum 3+ years of relevant privacy, IT and cyber legal experience
  • Prior in-house and/or law firm experience
  • Strategic problem solver with excellent legal and business judgment
  • Strong understanding and experience with cybersecurity, information security, information technology and privacy laws governing the EU
  • Familiarity and curiosity about new media and emerging digital technologies, including generative Al
  • Comfort working in a very fast-paced environment

Nice to have

  • CIPP certification(s) preferred
  • previous in-house experience at a multinational organization would be a plus
  • A detailed, business-friendly teammate who can think creatively
  • Desire to learn, excellent judgment, fun spirit, and sense of humor
  • Work ethic based on a strong desire to exceed expectations

What the JD emphasized

  • global cybersecurity
  • data protection laws
  • SaaS tech
  • AI
  • incident response
  • cybersecurity regulations
  • privacy and cybersecurity regulations
  • cybersecurity legal training
  • NIS2 compliance