Senior Cybersecurity Legal Counsel
Listed on 2025-12-14
-
IT/Tech
Cybersecurity, Information Security, Data Security
Position Title
Senior Cybersecurity Legal Counsel at Workday
1 day ago – Be among the first 25 applicants
About the TeamThe Cybersecurity Legal team supports Workday’s business by providing oversight of and strategic leadership for a diverse range of cybersecurity legal issues. We play a meaningful role in supporting Workday’s growth, innovation, security, and integrity. You'll be joining a high-functioning and highly regarded team that covers Litigation and Cybersecurity. The team is composed of experienced professionals who are specialists in their fields.
Aboutthe Role
We are seeking a dynamic and experienced Senior Cybersecurity Legal Counsel to manage our global Cybersecurity Legal Program. In this role, you will play a key part in supporting and developing Workday’s ongoing efforts to ensure secure networks and products and will manage Workday’s cybersecurity legal strategy in alignment with evolving global cybersecurity laws and regulations. We seek a confident self‑starter who can prioritize and balance multiple tasks and responsibilities and who enjoys working in a fast‑paced and high‑energy environment.
Responsibilities- Manage and further develop Workday's Cybersecurity legal program.
- Provide cybersecurity legal expertise and guidance to executives, cross‑functional leaders, and other relevant partners on variety of issues, including data security, incident response, risk mitigation, and relevant cybersecurity and data protection laws, regulations, and requirements.
- Provide dedicated legal support and counsel to the Chief Information Security Officer and the Cybersecurity and Trust organization.
- Lead the legal response of the investigation of potential security and privacy incidents and vulnerabilities, including identifying any legal or regulatory obligations, drafting and reviewing relevant communications and notifications, and providing counsel on Workday’s response, remediation, and mitigation efforts.
- Partner with Workday's Cybersecurity and Trust organization on the development and implementation of various cybersecurity programs, initiatives, training, and exercises, including cybersecurity awareness programs, bug bounty programs, penetration testing, phishing simulations, tabletops, and red‑team exercises.
- Develop, maintain, and improve cybersecurity legal processes and procedures, including Workday’s cybersecurity incident response plan, and advise on other relevant policies, procedures, playbooks, and standards.
- Partner with cross‑functional teams to draft, review, and ensure compliance with security terms in customer, vendor, and partner contracts.
- Monitor, analyze, and advise on compliance with global and domestic cybersecurity and data security laws, regulations, industry standards, and certifications.
- Advise on responses to external inquiries regarding Workday’s information security practices and procedures.
- Provide legal support to Workday’s Corporate Affairs team in formulating and advocating the company’s policy positions on cybersecurity matters.
- Collaborate with internal teams on cross‑functional projects related to a wide‑range of cybersecurity issues that touch upon privacy, data security, product development, public policy, and compliance.
- Handle outside counsel relationships, including strategy, work product, and budget.
We’re looking for a legal professional who is experienced, proactive, and collaborative.
Required Qualifications- J.D. Degree and membership in at least 1 state bar in good standing.
- 7+ years of experience as a practicing attorney, including 3+ years of cybersecurity experience at a national law firm, governmental agency, or in‑house.
- In‑house experience at a global SaaS company is a plus.
- Experience building cybersecurity programs and working with Information Security teams.
- Expertise in global security, privacy, and regulatory frameworks.
- Experience with SaaS, web technologies, cloud technologies/platforms.
- Outstanding verbal and written communication skills, including the ability to quickly translate complex and technical cybersecurity issues into clear guidance and to effectively communicate with non‑legal collaborators.
- Ability to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).