Legal Counsel - Compliance (m/w/d)
RemoteGermany
Job Summary
Operate IT and data privacy compliance processes at the intersection of GDPR, AI Act, and US higher education requirements. Answer security and privacy questionnaires (e.g., HECVAT, VPAT), conduct interviews with university IT security leads, and maintain a central Trust & Compliance Knowledge Base. Manage vendor registries, certificates, and incident records while triaging new IT and AI tools from business units. Build and update a central contract register, analyzing standard versus individual agreements and keeping technical addenda current. Establish scalable workflows and leverage AI and automation tools for document comparisons and drafts. Work 20 hours weekly in a remote setting with a focus on diverse team collaboration and continuous professional development via the company's internal learning platform.
Required Qualifications
- Ca. 3–5 Jahre Erfahrung in IT-Compliance, GRC, Informationssicherheit, Datenschutz-Operations oder Third-Party-Risk
- Erfahrung in der Beantwortung von Enterprise-Sicherheitsfragebögen (z. B. HECVAT, VSA, SIG)
- solides technisches Grundverständnis (z. B. Verschlüsselung, SSO, Hosting, Backups)
- Deutsch und Englisch fließend in Wort und Schrift (mind. C1-Niveau)
- Routinierter und kritischer Umgang mit KI-Tools
- Hohe Selbstständigkeit und Eigenverantwortung
- strukturierte Priorisierung
- souveränes Auftreten im direkten Austausch mit Kund:innen und IT-Verantwortlichen
- 20 Stunden pro Woche
- zunächst auf 12 Monate befristet
Desired Qualifications
- idealerweise im SaaS-/Software-Umfeld
- Erfahrung mit Automatisierung (n8n, Zapier) oder GRC-Plattformen (z. B. Vanta, Drata)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.