Senior Consultant In Cyber

Il y a 2 jours

WatermaelBoitsfort, Brussels, Belgique LinkedIn Temps plein

CMS Belgium is looking for a Senior Consultant in Cyber & Digital Law to reinforce its Technology, Media & Communications law practice between Brussels and Antwerp.

Profile:

Essential

  • A Belgian law degree (Master in Laws or equivalent). Admission to the bar is not required — we welcome candidates from law firms, consultancies, in-house legal or compliance teams, regulators and public authorities alike
  • At least 3–5 years of relevant professional experience in data protection, cybersecurity, technology or digital regulation
  • Solid working knowledge of EU and Belgian digital law, and genuine interest in keeping that knowledge current in a field that changes constantly
  • A keen interest in IT and cybersecurity — you enjoy understanding how the technology actually works, follow the threat landscape, and are curious about what sits behind the legal questions
  • Fluency in Dutch and English, both written and spoken. French is a strong asset
  • Self-propelled and pro-active: you identify what needs to happen and take it forward without waiting to be asked
  • Strong communicator, able to explain legal and regulatory issues clearly to CISOs, IT teams, executives and boards — not only to lawyers
  • Composure and sound judgment under time pressure, and the discretion that sensitive incident work demands
  • Willingness to participate in a standby rota, given the unpredictable nature of incidents

Nice to have

  • Prior involvement in live breach or incident response matters
  • Familiarity with security frameworks and standards such as ISO/IEC 27001, NIS2 CyberFundamentals or the NIST CSF
  • Certifications such as CIPP/E, CIPM, CISM or CISSP
  • Experience in a regulated sector — financial services, healthcare, energy, telecoms or critical infrastructure
  • Enough technical literacy to hold a credible conversation with a forensic team (you do not need to be an engineer)

The role:

We are looking for a Senior Consultant – Cyber & Digital Law to strengthen our cyber and digital regulatory team. You will work as a consultant alongside our lawyers, combining hands-on incident response support with regulatory advisory work.

The position has two clear halves.

Incident response (non-technical). You act as a calm, structured point of contact when clients are dealing with a cyber incident — coordinating the various workstreams (digital forensics, legal, communications, insurance, etc.).

Digital regulatory advisory. Between incidents, you advise clients on compliance with digital laws & regulations: data protection, cybersecurity regulation, AI, data governance and platform rules.

You will report to the partner leading the TMC practice and work closely with colleagues in the Belgian TMC team and across the CMS network on cross-border matters.

What you will do:

Incident response

  • Serve as first point of contact for clients reporting a cyber incident, the intake and scoping process, manage the status update meetings and act as the liaison with cyber insurers
  • Coordinate the incident workstream between the client, forensic investigators, IT and security providers, insurers, brokers and communications advisers
  • Assess notification and reporting obligations across regimes — GDPR and the Belgian Data Protection Act, the Belgian NIS2 Law and CCB / CERT.Be reporting, DORA, sectoral and contractual duties — and manage the timelines these create
  • Draft notifications to the Data Protection Authority, the CCB, sectoral supervisors and other regulators, as well as communications to data subjects, customers and business partners
  • Manage external service providers assisting clients (e.G. digital forensics providers;

    Please ensure you read the below overview and requirements for this employment opportunity completely.
    threat actor engagementproviders;
    crisis communications consultants;
    etc.)
  • Support decision-making in extortion and ransomware scenarios, including the legal and sanctions-related considerations around payment
  • Run post-incident reviews and translate the findings into concrete improvements for the client
  • Build and test client readiness: incident response plans and playbooks, escalation matrices, tabletop exercises and training for legal, IT and executive teams
  • Help develop and manage our incident response retainers and standby arrangements

Regulatory advisory

  • Advise on GDPR and Belgian data protection law: governance frameworks, DPIAs, international transfers, data subject rights, records and retention, and vendor management
  • Advise on the cybersecurity regulatory landscape — NIS2 and its Belgian implementation, the CyberFundamentals framework, DORA, the Cyber Resilience Act and sectoral security requirements — including scoping, gap analyses and complian