Description:
Job Overview:Come join our amazing team of leaders, learners, and world-class legal professionals accelerating Intuit's mission of powering prosperity for consumers and small businesses all over the world. Our Data Privacy team works hand-in-hand with our business partners to develop cutting-edge products that use technology to both add value to our customers and uphold Intuit's Data Stewardship Principles.
We're seeking a Corporate Counsel-–Information Risk & Security to partner closely with our Security Operations team and other cybersecurity and anti-fraud professionals across the Company in their day-to-day efforts to secure Intuit's systems and our customers' and workers' data. Reporting to the leader of the Information Risk & Security organization within the Intuit Data Privacy team, this lawyer will make a meaningful contribution to the continued maturation of the function, and to privacy and security compliance of all of Intuit's products and services.
The ideal candidate will have gained experience in the legal and practical components of cybersecurity and fraud incident response through employment at a major law firm, public company or relevant unit of government, as well as a demonstrable history of solving complex, time-sensitive problems in close partnership with a variety of cross-functional stakeholders.
This role is hybrid with current on-site expectations of 3 days per week.
Responsibilities:
Working as a member of the Information Risk & Security team, you will:
- Partner with senior attorneys to provide legal counsel for day-to-day cybersecurity and fraud incident management, leveraging a privacy mindset to assess and advise on legal risk, and manage engagement with internal and external stakeholders.
- Assist with the enhancement and automation of Intuit's processes to track, report on and develop insights from security incidents.
- Assist with regulatory and compliance issues related to privacy and security.
Qualifications:
- Eligible to practice law where located and to obtain any multi-jurisdictional license required to support in-house practice in California or state where role is ultimately located.
- 5+ years of experience working at a major law firm, public technology/financial services company or division of federal or state government (or some combination of those), with experience related to cybersecurity and privacy/security compliance —e.g., incident response and prevention, cybersecurity investigations and litigation, forensic review.
- Familiarity with US and EU privacy notification and data protection frameworks.
- Demonstrable ability to work across teams to solve complex problems, to communicate for impact, and a drive to learn and grow in the role.
- Team mentality; high availability; able to respond quickly to urgent matters in a dynamic and complex environment.
Preferred Qualifications:
- Information security or other relevant technology background.
- CIPP or CIPT certifications are considered an asset.
- Familiarity with leading cybersecurity, privacy, and risk management frameworks and standards, including but not limited to NIST Cybersecurity Framework (CSF 2.0), NIST Risk Management Framework, ISO/IEC 27001 and 27701, SOC 2, PCI DSS, and the UK NCSC Cyber Assessment Framework (CAF).