CMS is an international law firm with more than 90 lawyers based in Brussels and Antwerp, providing clients with a full range of legal and tax solutions. CMS is an ambitious and growing international organization.
With more than 5,000 lawyers worldwide, we are present in 47 countries and 84 offices located throughout Europe, the Middle East, South America, Africa and China.
CMS is a founding member of the Legal Diversity and Inclusion Alliance (https://legaldiversityalliance.be/). Selection for recruitment is irrespective of gender, race or ethnicity, age, religion, sex, marital status, sexual orientation, gender identity or disability.
CMS Belgium has been granted a silver medal by Ecovadis, the world's most trusted business sustainability rating.
CMS Belgium is looking for a Senior Consultant in Cyber & Digital Law to reinforce its Technology, Media & Communications law practice between Brussels and Antwerp.
Profile
Essential
A Belgian law degree (Master in Laws or equivalent). Admission to the bar is not required — we welcome candidates from law firms, consultancies, in-house legal or compliance teams, regulators and public authorities alike
At least 3–5 years of relevant professional experience in data protection, cybersecurity, technology or digital regulation
Solid working knowledge of EU and Belgian digital law, and genuine interest in keeping that knowledge current in a field that changes constantly
A keen interest in IT and cybersecurity — you enjoy understanding how the technology actually works, follow the threat landscape, and are curious about what sits behind the legal questions
Fluency in Dutch and English, both written and spoken. French is a strong asset
Self-propelled and pro-active: you identify what needs to happen and take it forward without waiting to be asked
Strong communicator, able to explain legal and regulatory issues clearly to CISOs, IT teams, executives and boards — not only to lawyers
Composure and sound judgment under time pressure, and the discretion that sensitive incident work demands
Willingness to participate in a standby rota, given the unpredictable nature of incidents
Nice to have
Prior involvement in live breach or incident response matters
Familiarity with security frameworks and standards such as ISO/IEC 27001, NIS2 CyberFundamentals or the NIST CSF
Certifications such as CIPP/E, CIPM, CISM or CISSP
Experience in a regulated sector — financial services, healthcare, energy, telecoms or critical infrastructure
Enough technical literacy to hold a credible conversation with a forensic team (you do not need to be an engineer)
The role
We are looking for a Senior Consultant – Cyber & Digital Law to strengthen our cyber and digital regulatory team. You will work as a consultant alongside our lawyers, combining hands-on incident response support with regulatory advisory work.
The position has two clear halves.
Incident response (non-technical). You act as a calm, structured point of contact when clients are dealing with a cyber incident — coordinating the various workstreams (digital forensics, legal, communications, insurance, etc.).
Digital regulatory advisory. Between incidents, you advise clients on compliance with digital laws & regulations: data protection, cybersecurity regulation, AI, data governance and platform rules.
You will report to the partner leading the TMC practice and work closely with colleagues in the Belgian TMC team and across the CMS network on cross-border matters.
What you will do
Incident response
Serve as first point of contact for clients reporting a cyber incident, the intake and scoping process, manage the status update meetings and act as the liaison with cyber insurers
Coordinate the incident workstream between the client, forensic investigators, IT and security providers, insurers, brokers and communications advisers
Assess notification and reporting obligations across regimes — GDPR and the Belgian Data Protection Act, the Belgian NIS2 Law and CCB / CERT.be reporting, DORA, sectoral and contractual duties — and manage the timelines these create
Draft notifications to the Data Protection Authority, the CCB, sectoral supervisors and other regulators, as well as communications to data subjects, customers and business partners
Manage external service providers assisting clients (e.g. digital forensics providers; threat actor engagement providers; crisis communications consultants; etc.)
Support decision-making in extortion and ransomware scenarios, including the legal and sanctions-related considerations around payment
Run post-incident reviews and translate the findings into concrete improvements for the client
Build and test client readiness: incident response plans and playbooks, escalation matrices, tabletop exercises and training for legal, IT and executive teams
Help develop and manage our incident response retainers and standby arrangements
Regulatory advisory
Advise on GDPR and Belgian data protection law: governance frameworks, DPIAs, international transfers, data subject rights, records and retention, and vendor management
Advise on the cybersecurity regulatory landscape — NIS2 and its Belgian implementation, the CyberFundamentals framework, DORA, the Cyber Resilience Act and sectoral security requirements — including scoping, gap analyses and compliance roadmaps
Advise on emerging digital regulation: the AI Act, the Data Act, the Data Governance Act, the DSA and DMA, eIDAS and cloud and outsourcing requirements
Draft and negotiate the contractual layer: data processing agreements, security schedules and SLAs, information sharing arrangements, transfer mechanisms and incident cooperation clauses
Prepare client-facing guidance, training and thought leadership, and represent the firm at client events, webinars and sector working groups
Contribute to business development, proposals and the continued growth of the cyber practice
Work with our support teams to organize internal training courses and awareness-raising initiatives on cyber security.
What we offer
The chance to work for a tier-1 technology, data and cyber practice, on the kind of matters that define the market
A team of friendly, genuinely fun lawyers around you — you will be supported, not left to sink or swim
A senior, visible role in a growing practice, with real ownership of matters and direct client contact from day one
Work at the point where law, technology and crisis management meet — no two incidents are the same
The reach of the CMS international network: cross-border matters, sector-specialist colleagues in 50+ countries, and secondment opportunities
Monthly remuneration with bonus opportunities and yearly remuneration revision
A structured training and development path, including support for relevant certifications, with clear scope to grow into a leading role in the cyber practice
Hybrid working and genuine flexibility around how and where you work
A collegial, non-hierarchical team that takes the work seriously without taking itself too seriously
Work facilities and offices in Antwerp and Brussels
Participation in international CMS events, trainings, conferences, team building, well-being programs and sporting activities
The process
The process consists of an introductory conversation, an interview with the practice leadership including a short case discussion, and a final meeting with the team.
For an informal, confidential conversation about the role before applying, contact Camille Vanhelleputte, HR Officer, at hr@cms-db.com or +32 2 743 69 28.
About CMS
CMS is a founding member of the Legal Diversity and Inclusion Alliance (https://legaldiversityalliance.be/). Selection for recruitment is irrespective of gender, race or ethnicity, age, religion, sex, marital status, sexual orientation, gender identity or disability.
CMS Belgium has been granted a silver medal by Ecovadis, the world's most trusted business sustainability rating, recognizing our commitment to sustainability and business ethics.
CMS is one of the world’s largest law firms, with more than 7,400 lawyers across 90+ offices in over 50 countries. In Belgium, our Technology, Media & Communications (TMC) practice is consistently recognised as a market leader, advising technology companies, financial institutions, healthcare and life sciences groups, industrial manufacturers and public sector bodies on the full spectrum of digital regulation.
Cybersecurity has become one of the fastest-growing parts of that practice. Our clients call us when they are in the middle of a ransomware attack, a data breach or a supply chain compromise — and they call us long before that, to get their governance, contracts and reporting lines in order.