Compliance Legal Counsel (Legal, Compliance Governance & Privacy)
BASE Salary
plus profit share
plus RRSP
plus benefits
International travel - 3 x 2 weeks
Full description will be shared if accepted.
Job Summary
Our client is a rapidly growing organization that is going through an exciting organizational and systems transformation, and is creating a Compliance Audit Function with the purpose of ensuring that the organization adheres to, and evidences compliance with, all relevant laws, regulations, and internal policies across each of the business units. The role has evolved from a primarily audit-support position into a legal and compliance governance role supporting the General Counsel / Chief Compliance Officer across RMI legal matters, compliance program implementation, privacy and data governance, internal investigations, training, vendor risk, and escalation of legal and compliance risk.
We are recruiting for a Compliance Legal Counsel with a legal background, who will be responsible for supporting the Compliance department, monitoring adherence to legal and regulatory requirements, conducting compliance reviews and audits as required, and collaborating with departments to address and resolve compliance issues. The role also provides first-instance legal support on assigned RMI contractual matters, including MSAs, SOWs, NDAs, DPAs, vendor terms, liability provisions, subcontracting clauses, privacy obligations, and related commercial-risk allocation.
Qualifications and Experience
• Master’s Degree (Preferred) in Legal Studies (LLM), Compliance and Risk Management, or a related field.
• Certifications such as RIMS CRM or GRCP are an asset.
• Member of the Bar Association or Law Society from any jurisdiction is an asset.
• Commercial lawyer with experience in acting as a compliance officer is preferred.
Minimum of 2-5 years’ experience in legal, compliance, commercial contracting, privacy, governance, internal audit, risk management, or related corporate functions. Experience leading a full-cycle audit process is desirable but not the sole focus of the role.
• Experience reviewing commercial agreements, vendor terms, SaaS agreements, DPAs, privacy obligations, cybersecurity clauses, liability provisions, and risk-allocation language is preferred.
• Experience with compliance programs, policy implementation, training, internal investigations, privacy/data protection, AI or technology governance, and cross-functional stakeholder management is an asset.
This role requires strong analytical skills, attention to detail, and the ability to collaborate with various stakeholders to ensure effective compliance management and continuous development. It also requires proactive engagement, first-instance ownership, sound legal reasoning, clear escalation judgment, and the ability to operate in proximity to GC/CCO work while preserving appropriate legal and compliance governance.
Our ideal candidate must have a growth mindset, be continuous-improvement and development driven, be adaptable and agile to evolving business requirements, take accountability, be engaged, and deliver high-quality performance.
Role Scope and Authority
• Act as Compliance Officer for RMI in relation to assigned internal RMI compliance tasks, with delegated authority to proceed independently where the work is internal to RMI and within existing directives, policies, and approved compliance frameworks.
• As Legal Counsel, support RMI contractual work by originating reviews, proposing revisions, identifying legal and commercial risk, and providing legal reasoning and recommendations, while recognizing that final contractual positions and outcomes remain subject to GC approval.
• Escalate matters involving other regions, group structure, policy changes, sensitive legal positions, corporate risk allocation, non-RMI matters, or uncertainty regarding authority before taking action.
• Maintain clear written records of reasoning, recommendations, decisions, approvals, and escalation points for material matters.
Key Responsibilities
• Assist in mapping existing compliance policies and procedures to ensure comprehensive understanding and documentation of the compliance framework, focusing on legal aspects of the policies.
• Support the development and implementation of a testing matrix or solution for identified compliance obligations, ensuring effective monitoring across legal and regulatory requirements globally.
• Organize and analyze historical data, including internal audit results, to support compliance initiatives and identify areas for legal and operational improvement.
• Contribute to the creation of internal audit conclusions and reports, disseminating findings to management for timely communication of compliance status and potential legal ramifications.
• Participate in root-cause analysis of audit failures, proposing corrective measures to address identified issues and support compliance with legal standards.
• Assist in developing yearly integrated audit reports that summarize audit activities, findings, and corrective actions while addressing both legal compliance and broader organizational needs.
• Maintain a historical audit repository, tracking trends and analyzing data to support continuous improvement and informed strategic decision-making.
• Facilitate the creation of compliance reports compatible with ESP requirements and other reporting standards.
• Contribute to ongoing updates of compliance policies and procedures to reflect current regulations, legal standards, and organizational needs.
• Assist in preparing annual compliance reports, highlighting key activities, findings, and improvements related to both compliance and legal obligations.
• Collaborate with external auditors to facilitate audits, ensuring effective communication and resolution of identified legal or compliance issues.
• Support the GC/CCO in the development, implementation, interpretation, and maintenance of Our client compliance directives, policies, procedures, standards, and program documentation.
• Maintain and update compliance registers, action trackers, governance records, and evidence of completion for assigned compliance deliverables.
• Prepare, review, and improve compliance presentations, training materials, policy summaries, employee communications, and governance memoranda.
• Support management of compliance reporting processes, including evidence collection, status tracking, follow-up with stakeholders, and preparation of materials for management or board-level review.
Legal and Contract Support
• Review, draft, and negotiate assigned RMI commercial agreements, including MSAs, SOWs, NDAs, DPAs, vendor terms, SaaS agreements, technology agreements, service agreements, and related contractual documentation.
• Identify, assess, and escalate contractual issues involving limitation of liability, indemnities, warranties, confidentiality, data protection, cybersecurity, subcontracting, insurance, intellectual property, termination rights, governing law, dispute resolution, and change-control risk.
• Provide first-pass legal reasoning and recommended positions on contractual deviations, including where business approval, GC approval, or a formal risk-acceptance decision may be required.
• Challenge vendor positions where proposed terms are inconsistent, unsupported, incomplete, commercially unreasonable, or misaligned with Our client governance requirements.
• Verify contractual changes, identify hidden or undocumented changes, request editable or comparable versions where required, and ensure that legal review is based on reliable document control.
Privacy, Data Protection, AI and Technology Governance
• Support Our client’s privacy program, including controller/processor analysis, employee privacy, vendor processing, subprocessors, data-transfer considerations, data-processing safeguards, and privacy-related contractual controls.
• Review DPAs, privacy terms, vendor questionnaires, employee privacy notices, cybersecurity-related tools, AI-enabled systems, and technology arrangements that may involve employee data, personal information, monitoring, security filtering, or automated processing.
• Support the development and implementation of employee privacy, AI-use, cybersecurity, system-access, and technology-governance policies or communications in coordination with IT, HR,
Compliance, and Legal.
• Assess privacy and governance implications of tools such as security monitoring, AI-assisted systems, email security, data-loss prevention, and access-management workflows, and escalate matters requiring GC/CCO or senior-management approval.
Compliance Governance, RCO Support and Investigations
• Support the structure and administration of Regional Compliance Officer and Local Compliance Officer frameworks, including role clarity, independence, reporting expectations, training, appointment processes, and escalation requirements.
• Assist in reviewing and updating the compliance program, including the Code of Conduct, sanctions policy, modern slavery materials, reporting procedures, compliance directives, policy acknowledgements, and training requirements.
• Support compliance investigations, fact gathering, issue framing, document review, privilege-sensitive communications, remediation tracking, and preparation of investigation-related memoranda as assigned by the GC/CCO or Compliance Committee.
• Assist with the assessment of HR/legal/compliance overlap, including governance gaps, escalation thresholds, internal accountability, and appropriate framing of sensitive issues.
• Provide compliance training and guidance to targeted employee groups, Regional Compliance Officers, business units, and functional stakeholders as required.