We are seeking a Cyber Counsel to join Lenovo's Legal Department as part of our Global Privacy & Data Protection team. Based in Europe, this role will primarily support cybersecurity legal matters across the EMEA region while also contributing to global cybersecurity initiatives and projects.
As part of a growing team focused on cybersecurity legal and regulatory aspects, you will work at the forefront of emerging cyber regulation, helping the company navigate a rapidly evolving legal and regulatory landscape. You will serve as a trusted advisor to Security, Product, Government Relations, Legal, Procurement, and business stakeholders, providing practical legal guidance on cybersecurity requirements, technology risk, cyber incident response, and global data governance challenges.
This is an exciting opportunity to join one of the world's leading technology companies at a time of significant regulatory change. You will have the chance to help shape Lenovo's cybersecurity legal strategy, work on cutting-edge technology and security issues, collaborate with colleagues around the world, and play a meaningful role in supporting the company's commitment to security, trust, and responsible innovation.
Wha you will do:
-
Advise business, security, product, and legal stakeholders on cybersecurity laws, regulations, and emerging legal requirements, including NIS2, Cyber Resilience Act, DORA, and related global cyber frameworks.
-
Provide practical legal guidance on cybersecurity governance, security-by-design, cyber risk management, resilience, vulnerability disclosure, and supply chain security requirements.
-
Review, draft, and negotiate cybersecurity, and regulatory compliance provisions in customer, supplier, and other commercial agreements, as needed.
-
Partner closely with security teams to support compliance programs, implementation of legal and regulatory requirements and internal governance frameworks.
-
Support legal aspects of privacy and security incidents, cyber investigations, and crisis response activities, including regulatory notification and reporting obligations.
-
Advise on the intersection of cybersecurity requirements, cross-border data transfers, data localization, digital sovereignty, and government access considerations.
-
Monitor legal and regulatory developments in cybersecurity and provide timely, practical guidance.
-
Collaborate with Product, Security, Government Affairs, Procurement, Privacy, and other stakeholders to support strategic cybersecurity initiatives and embed legal requirements into business processes.
-
Support customer engagements, audits, privacy and security questionnaires, and RFP responses related to cybersecurity and regulatory compliance.
-
Develop and deliver training, guidance materials, and best practices on cybersecurity legal and regulatory topics.
What you will bring:
-
Law degree and qualification to practice in at least one EU or EEA jurisdiction.
-
Approximately 8 years of experience in cybersecurity, technology, privacy, regulatory, or commercial legal practice, preferably within a multinational technology company or leading law firm.
-
Strong knowledge of cybersecurity regulatory frameworks, including NIS2, Cyber Resilience Act, DORA, and related EU cyber legislation.
-
Familiarity with global cybersecurity frameworks and standards such as ISO 27001, NIST Cybersecurity Framework, SOC 2, and cloud security practices.
-
Experience reviewing and negotiating technology, security, and commercial agreements.
-
Understanding of data protection concepts, international data transfers, data sovereignty issues, and the interaction between privacy and cybersecurity requirements.
-
Experience supporting or advising on cybersecurity incidents, investigations, or crisis management activities is preferred.
-
Excellent legal drafting, analytical, communication, and stakeholder management skills.
-
Ability to work effectively across technical and non-technical teams in a fast-paced global environment.
-
Strong attention to detail, sound judgment, collaborative mindset, and willingness to learn.
-
Professional certifications such as CISSP, CISM, CRISC, GIAC, CIPM, CIPP/E, or similar are a plus.
Preferred Attributes
-
Interest in emerging technologies, product security, and cyber resilience.
-
Ability to translate complex legal requirements into practical business and technical guidance.
-
Experience working with international stakeholders across multiple jurisdictions.
-
Strong project management and organizational skills with the ability to manage multiple priorities simultaneously.
What Lenovo can offer you:
-
Disability Excess Insurance Plan
-
Pension Plan
-
Employee Referral Bonus
-
Children of Lenovo Employees Scholarship Program
-
Lenovo and Motorola Product Discounts
-
Employee Assistance Program, e.g., for health, legal & financial consultancy
-
Internal E-learning Development Platform Available for Employees
-
Contribution to Gym membership
- 25 holiday days + additional days based on internal policy
-
Possibility to join volunteering activities