About the Role
This role owns the end-to-end compliance lifecycle at Cloud Office. You will manage legal compliance operations, handle all customer and vendor contracting flows, oversee DPAs, maintain our Terms of Service, enable regulatory alignment (GDPR, NIS2, SOC 2 requirements), support DORA-related customer obligations, and integrate compliance practices across the company. This is a hands-on role combining legal operations, regulatory compliance, contracting governance, and internal process management.
What You’ll Do
- Draft and negotiate a full suite of commercial agreements, including customer, partner, reseller, and vendor contracts.
- Support the Sales team by managing contract redlines, customer negotiations, and procurement questionnaires.
- Maintain standardized templates and version control across international entities (BG, GR, UK).
- Provide practical legal advisory to internal teams, translating complex legal risks into business-friendly guidance.
- Advise internal teams on day-to-day commercial legal matters and contractual obligations.
- Ensure "Privacy-by-Design" is integrated into all internal tools, automation projects, and new processes (e.g., AI usage).
- Oversee regulatory alignment with GDPR, NIS2, DORA-lite, and specific industry expectations.
- Own the compliance calendar, managing timelines for audits, disaster recovery (DR) tests, and policy reviews.
- Maintain the Register of Regulations (RoR) to track applicable laws, obligations, and required evidence.
- Manage the Vendor Risk lifecycle, from initial security/DPA assessments to final data deletion during offboarding.
- Drive audit readiness for SOC 2 and ISO 27001, coordinating with tech teams to gather evidence and documentation packs.
- Embed compliance into daily operations across Engineering, Support, and HR through regular training and monitoring.
- Maintain public-facing documentation, ensuring consistency across Terms of Service, Privacy Policies, and marketing materials.
What We’re Looking For
- Law degree. Qualification to practice law in the relevant jurisdiction is a plus.
- Strong understanding of GDPR, privacy compliance, and data processing obligations.
- Experience reviewing contracts, DPAs, and ToS/AUS content.
- Familiarity with SaaS business models, cloud providers, and vendor management.
- Ability to analyse regulations and translate them into internal processes.
- Excellent writing skills and ability to produce clear, high-quality documentation.
- Strong project management and organisational capabilities.
- Comfortable coordinating across teams and driving processes end-to-end.
Nice to Have
- Experience working with SOC 2, ISO, NIS2, DORA, AML/KYC, or other regulated frameworks.
- Previous experience in a SaaS company or cloud services provider.
- Experience supporting customer RFPs, vendor questionnaires, or compliance reviews.