Your mission: As our Group Legal and Privacy Manager, you'll be a key partner to Sales, Product, Finance, Security, and Leadership - supporting commercial agreements, enabling compliant growth, and leading our legal and privacy processes across Finland and Europe.
Mindset: This is a hands-on role for a pragmatic, business-oriented legal professional who enjoys working close to commercial and technical teams, balancing risk with business needs, and driving structured, scalable solutions.
Work setup: Flexible hybrid work in Finland with opportunities for in-person collaboration in Nomentia's Espoo office.
Reporting line: You will report to the Chief Financial Officer (CFO) and have direct people leadership responsibility for one team member.
Why you shouldn’t apply: If you prefer a narrowly scoped legal role or mainly reactive advisory work without ownership of commercial law, day-to-day sales contracting process, NDA reviews and privacy & compliance topics, this role may not be the right fit.
Why this role is your next career move
This is a central role in Nomentia's legal function, working at the intersection of SaaS, fintech, data privacy, and regulation. You'll lead commercial legal work and support international growth, with ownership of privacy and compliance areas. As Group Legal and Privacy Manager, you will work closely with Sales, Product, Security, and Finance, supporting complex customer engagements, leading GDPR and compliance topics, and shaping scalable legal practices across the business. If you're looking for ownership, variety, and real business impact, this could be a strong next step.
As Group Legal and Privacy Manager, you will:
- Lead commercial legal work by drafting, reviewing, and negotiating a wide range of agreements (customer, vendor, partnership, licensing, and SaaS), ensuring they are consistent, scalable, and commercially practical.
- Support business growth and deals by partnering closely with Sales, Product, Security, and Technology teams - aligning contracts with product capabilities and customer needs, including complex and regulated cases (e.g. DORA).
- Enable efficient decision-making by providing clear, practical legal guidance and driving alignment between legal, commercial, and technical stakeholders.
- Build scalable legal ways of working by developing and maintaining contract templates, frameworks, and best practices, and supporting the development of legal tools such as the CLM system.
- Own and drive compliance and regulatory topics, with a focus on GDPR and SaaS-related requirements - monitoring key regulations (e.g. GDPR, DORA, EU AI Act) and translating them into actionable business guidance.
- Act as the go-to expert on data privacy, including GDPR compliance, data subject requests, and embedding Privacy by Design into product development.
- Strengthen risk and compliance practices by identifying and mitigating legal and regulatory risks, supporting information security frameworks (e.g. ISO 27001), and leading or coordinating responses to data breaches and regulatory investigations.
- Develop and roll out internal policies and training to support a strong, practical compliance culture across the organization.
- Oversee third-party and vendor compliance, including legal due diligence processes.
- Support corporate governance matters in collaboration with the CFO.
- Lead and develop one direct report within the Legal and Privacy function, providing day-to-day guidance, prioritization support, coaching, and performance development to ensure high-quality delivery across legal, privacy, and compliance activities.
What we're looking for
Commercial legal expertise
- 5-8+ years of post-qualification experience, either in-house or at a law firm, ideally in a SaaS or technology environment
- Strong experience drafting and negotiating commercial and SaaS agreements
- Strong drafting skills with attention to detail and commercial context
Business partnering and communication
- Proven ability to work closely with commercial and technical teams, supporting deals and business decisions
- Ability to translate complex legal topics into clear, actionable guidance
- Collaborative, solution-oriented mindset with strong stakeholder management skills
Privacy, compliance, and regulatory knowledge
- Practical experience with GDPR and implementing privacy programs in a tech environment
- Hands-on experience with information security frameworks such as ISO 27001
- Good understanding of relevant EU regulations (e.g. GDPR, DORA, EU AI Act) and their business impact
Structured and scalable way of working
- Experience developing legal templates, frameworks, or processes that support scalability
- Familiarity with tools such as CLM systems is an advantage
Delivery and ownership
- Ability to manage multiple priorities and work independently in a fast-paced environment
- Proactive approach to identifying risks and driving practical, business-enabling solutions
Other requirements
- Master’s degree in Law (OTM/LL.M. or equivalent)
- Fluency in English and Finnish (other European languages are seen as a plus)
Practical information
- Salary: Salary starting from €7000 per month. The final salary will depend on experience, skills and role fit. Up to 10% annual bonus at target level (if company-wide goals are met).
- Work setup: Flexible hybrid work in Finland with opportunities for in-person collaboration.
Here's what to expect from the recruitment process
- Teams interview with Kukka Roine, Manager, Recruitment & HR
- Teams interview with Tami Halttunen, Chief Financial Officer
- Teams interview with Brian Hopkins, Chief Information Officer, and Lauri Bergström, Head of Sales Nordics.
- Short practical legal assignment
- Onsite interview with Tami Halttunen, Chief Financial Officer