Key contact
Job Description
CMS Belgium is looking for a Senior Consultant in Cyber & Digital Law to reinforce its Technology, Media & Communications law practice between Brussels and Antwerp.
Profile:
Essential
- A Belgian law degree (Master in Laws or equivalent). Admission to the bar is not required — we welcome candidates from law firms, consultancies, in-house legal or compliance teams, regulators and public authorities alike
- At least 3–5 years of relevant professional experience in data protection, cybersecurity, technology or digital regulation
- Solid working knowledge of EU and Belgian digital law, and genuine interest in keeping that knowledge current in a field that changes constantly
- A keen interest in IT and cybersecurity — you enjoy understanding how the technology actually works, follow the threat landscape, and are curious about what sits behind the legal questions
- Fluency in Dutch and English, both written and spoken. French is a strong asset
- Self-propelled and pro-active: you identify what needs to happen and take it forward without waiting to be asked
- Strong communicator, able to explain legal and regulatory issues clearly to CISOs, IT teams, executives and boards — not only to lawyers
- Composure and sound judgment under time pressure, and the discretion that sensitive incident work demands
- Willingness to participate in a standby rota, given the unpredictable nature of incidents
Nice to have
- Prior involvement in live breach or incident response matters
- Familiarity with security frameworks and standards such as ISO/IEC 27001, NIS2 CyberFundamentals or the NIST CSF
- Certifications such as CIPP/E, CIPM, CISM or CISSP
- Experience in a regulated sector — financial services, healthcare, energy, telecoms or critical infrastructure
- Enough technical literacy to hold a credible conversation with a forensic team (you do not need to be an engineer)
The role:
We are looking for a Senior Consultant – Cyber & Digital Law to strengthen our cyber and digital regulatory team. You will work as a consultant alongside our lawyers, combining hands-on incident response support with regulatory advisory work.
The position has two clear halves.
Incident response (non-technical). You act as a calm, structured point of contact when clients are dealing with a cyber incident — coordinating the various workstreams (digital forensics, legal, communications, insurance, etc.).
Digital regulatory advisory. Between incidents, you advise clients on compliance with digital laws & regulations: data protection, cybersecurity regulation, AI, data governance and platform rules.
You will report to the partner leading the TMC practice and work closely with colleagues in the Belgian TMC team and across the CMS network on cross-border matters.
What you will do:
Incident response
- Serve as first point of contact for clients reporting a cyber incident, the intake and scoping process, manage the status update meetings and act as the liaison with cyber insurers
- Coordinate the incident workstream between the client, forensic investigators, IT and security providers, insurers, brokers and communications advisers
- Assess notification and reporting obligations across regimes — GDPR and the Belgian Data Protection Act, the Belgian NIS2 Law and CCB / CERT.be reporting, DORA, sectoral and contractual duties — and manage the timelines these create
- Draft notifications to the Data Protection Authority, the CCB, sectoral supervisors and other regulators, as well as communications to data subjects, customers and business partners
- Manage external service providers assisting clients (e.g. digital forensics providers; threat actor engagement providers; crisis communications consultants; etc.)
- Support decision-making in extortion and ransomware scenarios, including the legal and sanctions-related considerations around payment
- Run post-incident reviews and translate the findings into concrete improvements for the client
- Build and test client readiness: incident response plans and playbooks, escalation matrices, tabletop exercises and training for legal, IT and executive teams
- Help develop and manage our incident response retainers and standby arrangements
Regulatory advisory
- Advise on GDPR and Belgian data protection law: governance frameworks, DPIAs, international transfers, data subject rights, records and retention, and vendor management
- Advise on the cybersecurity regulatory landscape — NIS2 and its Belgian implementation, the CyberFundamentals framework, DORA, the Cyber Resilience Act and sectoral security requirements — including scoping, gap analyses and compliance roadmaps
- Advise on emerging digital regulation: the AI Act, the Data Act, the Data Governance Act, the DSA and DMA, eIDAS and cloud and outsourcing requirements
- Draft and negotiate the contractual layer: data processing agreements, security schedules and SLAs, information sharing arrangements, transfer mechanisms and incident cooperation clauses
- Prepare client-facing guidance, training and thought leadership, and represent the firm at client events, webinars and sector working groups
- Contribute to business development, proposals and the continued growth of the cyber practice
- Work with our support teams to organize internal training courses and awareness-raising initiatives on cyber security
What we offer:
- The chance to work for a tier-1 technology, data and cyber practice, on the kind of matters that define the market
- A team of friendly, genuinely fun lawyers around you — you will be supported, not left to sink or swim
- A senior, visible role in a growing practice, with real ownership of matters and direct client contact from day one
- Work at the point where law, technology and crisis management meet — no two incidents are the same
- The reach of the CMS international network: cross-border matters, sector-specialist colleagues in 50+ countries, and secondment opportunities
- Monthly remuneration with bonus opportunities and yearly remuneration revision
- A structured training and development path, including support for relevant certifications, with clear scope to grow into a leading role in the cyber practice
- Hybrid working and genuine flexibility around how and where you work
- A collegial, non-hierarchical team that takes the work seriously without taking itself too seriously
- Work facilities and offices in Antwerp and Brussels
- Participation in international CMS events, trainings, conferences, team building, well-being programs and sporting activities
The process:
The process consists of an introductory conversation, an interview with the practice leadership including a short case discussion, and a final meeting with the team.
For an informal, confidential conversation about the role before applying, contact Camille Vanhelleputte, HR Officer, at hr@cms-db.com or +32 2 743 69 28.
About CMS:
CMS is a founding member of the Legal Diversity and Inclusion Alliance (https://legaldiversityalliance.be/). Selection for recruitment is irrespective of gender, race or ethnicity, age, religion, sex, marital status, sexual orientation, gender identity or disability.
CMS Belgium has been granted a silver medal by Ecovadis, the world's most trusted business sustainability rating, recognizing our commitment to sustainability and business ethics.
CMS is one of the world’s largest law firms, with more than 7,400 lawyers across 90+ offices in over 50 countries. In Belgium, our Technology, Media & Communications (TMC) practice is consistently recognised as a market leader, advising technology companies, financial institutions, healthcare and life sciences groups, industrial manufacturers and public sector bodies on the full spectrum of digital regulation.
Cybersecurity has become one of the fastest-growing parts of that practice. Our clients call us when they are in the middle of a ransomware attack, a data breach or a supply chain compromise — and they call us long before that, to get their governance, contracts and reporting lines in order.
Read more about working for CMS here.
Application deadline: 26 Oct 2026
Apply now