Senior Corporate Counsel

Microsoft Microsoft · Big Tech · Brussels, Brussels, Belgium +3 · Legal Counsel

Microsoft is seeking a Europe-based cybersecurity attorney to advise on complex regulatory and technological issues, particularly those driven by AI. The role involves developing strategies for cybersecurity regulatory compliance, providing counseling, leading initiatives, reporting incidents, and shaping global cybersecurity laws. The attorney will support compliance programs worldwide, focusing on European laws, and engage with regulatory authorities. They will act as a cybersecurity expert, tracking, analyzing, and shaping legislation, and ensuring business goals are met through compliance and policy implementation.

What you'd actually do

  1. As part of a team of attorneys and working with our policy experts, review regulations around cybersecurity through the lens of compliance, articulating legal obligations for our product and services teams globally.
  2. Provide guidance as to whether cybersecurity controls comply with regulatory requirements.
  3. Work with legal, engineering, and compliance teams around the company on implementation of security compliance regimes for new laws and obligations.
  4. Provide strategic direction to other legal teams and business partners on specific issues and trends in cybersecurity, including AI security, and related legal compliance that will impact Microsoft’s businesses, our customers, and our ecosystem.
  5. Provide expertise to legal and policy teams across Microsoft seeking counsel on the interpretation of cybersecurity legal and regulatory obligations.

Skills

Required

  • Juris Doctorate Degree or Equivalent International Degree
  • active license in good standing to practice law
  • Demonstrable experience as a practicing attorney or equivalent practice of law
  • Relevant experience in cybersecurity law, cybersecurity compliance, critical infrastructure, privacy, telecommunications, or digital safety, ideally in the EU’s DORA, NIS1 or NIS2 Directives, GDPR, and/or analogous regulations in other European states.
  • Demonstrable experience in criminal or civil litigation or regulatory proceedings.

Nice to have

  • Fluency and facility with cyber risks, remediation, cybersecurity standards (e.g., NIST, ISO/IEC), frameworks, risk assessments or certification processes, ideally including a practical understanding of same.
  • Experience designing and implementing cross-functional programs and processes to track legal or regulatory requirements, including compliance programs.
  • Experience advising or representing organizations in regulatory oversight matters or representing or supporting regulatory agencies in their oversight or enforcement activities.
  • Curiosity to understand Microsoft’s products and services, with a drive to get precise and complete information to make informed decisions.
  • Practical business judgment, ability to think strategically, and desire to establish a “trusted advisor” relationship with key clients.
  • Independent and able to prioritize in an ever-changing legal and regulatory environment.
  • Ability to creatively problem-solve with a focus on achieving results that both benefit our business and maintain the trust of our customers and partners.
  • Desire and ability to work with diverse, global teams.

What the JD emphasized

  • cybersecurity law
  • cybersecurity compliance
  • cybersecurity regulatory compliance
  • cybersecurity laws worldwide
  • cybersecurity regulatory affairs
  • cybersecurity compliance counseling
  • cybersecurity compliance programs
  • cybersecurity legal and regulatory obligations
  • cybersecurity governance
  • cybersecurity-related legislative priorities
  • cybersecurity and resilience regulatory authorities
  • cybersecurity standards
  • cybersecurity risks