VP & Associate GC, Cybersecurity & Privacy

MetLife

New York (NY)

Hybrid

USD 239,000 - 318,000

Full time

25 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule
Competitive compensation
Stock-based long-term incentives

Job summary

MetLife is seeking a senior legal leader with deep global cybersecurity and privacy expertise to serve as the enterprise lead for cybersecurity and privacy legal risk, and as a key member of the GEBI leadership team. This role acts as the principal legal advisor to Information Security and provides strategic guidance across regions and business lines.

You will partner with Government & Legal Affairs, Compliance, Privacy, and Technology leaders to shape risk-informed decision making, lead

Qualifications

  • 15+ years legal experience with deep cybersecurity and privacy/data protection expertise.
  • Significant cyber/privacy incident response experience.
  • Knowledge of global privacy/cybersecurity requirements (GDPR/CCPA/HIPAA; NYDFS/NAIC as applicable).

Responsibilities

  • Owns cybersecurity and privacy legal strategy and operating model across regions and business lines.
  • Advises Information Security leadership and cross-functional partners; influences senior decision-making.
  • Leads legal readiness for enterprise incident response and regulator engagement.
  • Provides strategic advice on privacy-by-design and security-by-design for tech initiatives.
  • negotiates cybersecurity/privacy terms in complex agreements and supports third-party risk.

Skills

Cybersecurity & privacy
Legal leadership
Regulatory engagement
Incident response
Risk assessment

Education

Juris Doctor (JD) or equivalent

Job description

In Government & Legal Affairs, you'll be an engaged and trusted partner - empowered to deliver innovative solutions, influence public policy, and achieve results that enable MetLife’s growth and protect its global interests. Applying a commercial and contemporary mindset, you'll advocate for what’s possible, overcome challenges, and embrace different perspectives. If you also pride yourself on acting with accountability, transparency, and respect, apply to join our Government & Legal Affairs team today.

The Opportunity

MetLife is seeking a senior legal leader with deep global cybersecurity and privacy expertise to serve as the enterprise lead for cybersecurity and privacy legal risk and as a key member of the GEBI leadership team. This role functions as the principal legal advisor to MetLife’s Information Security organization and provides strategic, enterprise wide legal guidance on cybersecurity, data protection, and privacy governance laws and regulations across all regions and business lines. The role partners closely with senior leaders across Government & Legal Affairs, Compliance, Privacy, Information Security, Global Technology & Operations, and the businesses to shape risk informed decision making and align legal strategy with MetLife’s broader business objectives.

Key Responsibilities

As a senior legal leader, serves as MetLife's enterprise lead for cybersecurity and privacy legal risk, setting strategy and priorities and delivering consistent, high-quality legal support across regions and business lines, including:

Enterprise Strategy, Governance And Leadership
  • Owns the cybersecurity and privacy legal strategy and operating model; establishes standards, playbooks, escalation paths, and risk tolerances aligned to enterprise objectives.
  • Acts as principal legal advisor to Information Security leadership and a key partner to the Chief Privacy Office, Compliance, Risk, Technology and business leadership; influences senior decision-making through risk-based guidance.
  • Represents Government & Legal Affairs in senior governance forums and drives alignment on complex, high-impact initiatives (e.g., cloud and transformation programs, data strategy, AI/analytics enablement, and enterprise resilience activities).
Incident Response And Regulatory Engagement (cybersecurity And Privacy)
  • Serves as lead legal point of contact for significant cybersecurity incidents and privacy incidents, directing legal response, strategy, investigation oversight, notification analysis, and remediation support in partnership with Information Security, Privacy, Compliance and Communications, and colleagues in other legal areas.
  • Leads legal readiness for enterprise incident response (tabletops, playbooks, training) and advises on third-party breach response, client ransomware events, and client-facing communications.
  • Owns legal strategy for regulator and law enforcement engagement related to cyber and privacy events; supports examinations, inquiries, and investigations and drives defensible, timely responses. Partners closely with Government Affairs colleagues on regulatory engagement.
Privacy-by-design, Product/technology Enablement And Data Protection
  • Provides strategic legal advice on global privacy and data protection requirements (e.g., GDPR, CCPA, HIPAA/HITECH and other applicable regimes) across products, services, marketing, HR, and operations.
  • Advises on privacy-by-design and cybersecurity-by-design for new and existing technologies, including cloud, digital channels, data sharing, cross-border transfers, analytics, and AI/ML use cases; partners on governance, controls, and documentation to enable compliant innovation.
Required Qualifications
Business Knowledge/Technical Skills
  • 15+ years legal experience with deep cybersecurity and privacy/data protection expertise; financial services and in-house experience preferred.
  • Significant cyber and privacy incident response experience (investigations, privilege strategy, remediation, breach notification and regulator engagement).
  • Strong knowledge of global privacy/data protection and cybersecurity requirements applicable to the role (e.g., GDPR, CCPA/CPRA, HIPAA/HITECH; NYDFS/NAIC-related requirements as applicable) and ability to translate them into practical guidance.
  • Ability to support complex technology and data-enabled initiatives (cloud, digital channels, data sharing, analytics and AI/ML), including privacy-by-design and security-by-design.
  • Familiarity with security frameworks and control environments (e.g., NIST, ISO 27001/27002) and enterprise policy/program development (standards, playbooks, training).
  • Experience negotiating cybersecurity and privacy terms in complex commercial/vendor agreements; supporting third-party risk and strategic sourcing; and leading cyber/privacy diligence for strategic transactions (including M&A).

Demonstrates baseline AI fluency, including the ability to effectively and responsibly use approved AI tools to enhance productivity, decision‑making, and work quality. Understands AI capabilities, limitations, and ethical considerations, and applies AI in alignment with company policies, data privacy standards, and business objectives.

Leadership/Management Competencies
  • Proven people leadership (including leading senior professionals and/or managers): sets strategy and priorities, allocates resources, develops talent and succession.
  • Trusted advisor with executive presence; influences outcomes in a matrixed, global environment through sound, risk-based judgment.
  • Excellent communication and negotiation skills; able to simplify complex cyber/privacy issues and drive timely decisions on high-risk matters.
  • Solution-oriented and operationally disciplined; leads through change while maintaining strong governance.
Preferred Qualifications
  • Prior in-house experience.
  • Experience in financial services and/or insurance
  • Prior leadership/management of attorneys.
Location Expectation

This is a hybrid role requiring a minimum of 3 days per week in office.

The expected salary range for this position is $238,800 - $318,300. This role may also be eligible for annual short-term incentive compensation and stock-based long-term incentives. All incentives and benefits are subject to the applicable plan terms.

Benefits We Offer

Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, paid time off, paid holidays, volunteer time off, tuition assistance and much more! For more information regarding MetLife’s U.S. benefits, please click here.

About MetLife

Recognized on Fortune magazine's list of the "World's Most Admired Companies", Fortune World’s 25 Best Workplaces™, as well as the Fortune 100 Best Companies to Work For®, MetLife, through its subsidiaries and affiliates, is one of the world’s leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.

As part of our New Frontier strategy, MetLife is building an AI-enabled, people-centered future. We’re looking for people who bring curiosity, adaptability, and a growth mindset as we use AI to enhance how we serve customers, support communities, and evolve the way work gets done. At MetLife, AI is a responsible partner that supports human judgment, creativity, and continuous improvement while helping us build trust, inclusion, and long‑term value.

Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we’re inspired to transform the next century in financial services. At MetLife, it’s #AllTogetherPossible. Join us!

MetLife is an Equal Opportunity Employer. All employment decisions are made without regards to race, color, national origin, religion, creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, marital or domestic/civil partnership status, genetic information, citizenship status (although applicants and employees must be legally authorized to work in the United States), uniformed service member or veteran status, or any other characteristic protected by applicable federal, state, or local law (“protected characteristics”).

If you need an accommodation due to a disability, please email us at accommodations@metlife.com. This information will be held in confidence and used only to determine an appropriate accommodation for the application process.

MetLife maintains a drug‑free workplace.

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liabilities.

This posting is for a current vacancy and is anticipated to remain open for at least 90 days from the listed posting date.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Head of Compliance Technology
Director, Head of Compliance Technology

MetLife • Cary (NC)

Hybrid
USD 160,000 - 200,000
Health plan with medical/prescription,
401(k) with employer matching
Life insurance
Principal Security Architect
Principal Security Architect

MetLife • Bridgewater (MA)

Hybrid
USD 120,000 - 190,000
Health plan
401(k) with employer matching
Life insurance
+1
Director, Head of Compliance Technology
Director, Head of Compliance Technology

MetLif • New York (NY)

Hybrid
USD 160,000 - 200,000
Comprehensive health plan
401(k) with employer matching
Life insurance & disability
+1
AVP, Technology Product Manager - Sales
AVP, Technology Product Manager - Sales

MetLife • Cary (NC)

Hybrid
USD 164,000 - 219,000
Hybrid work model
Comprehensive health plan
401(k) with company match
+1
Senior Software Development Engineer
Senior Software Development Engineer

MetLife • Cary (NC)

Hybrid
USD 90,000 - 120,000
Medical/dental/vision insurance
Disability insurance
Retirement plan + 401(k) with match
+3
SVP, Head of Global Infrastructure
SVP, Head of Global Infrastructure

MetLife • New York (NY)

Hybrid
USD 270,000 - 360,000
Client Service Consultant II
Client Service Consultant II

MetLife • Tampa (FL)

On-site
USD 76,000 - 86,000
401(k) with employer matching
Comprehensive health benefits
Paid time off and holidays
Auditor II
Auditor II

MetLife • Bridgewater (MA)

Hybrid
USD 54,000 - 72,000
Health plan
Disability insurance
Life insurance
+2
Senior IT Auditor
Senior IT Auditor

MetLif • Cary (NC)

Hybrid
USD 76,500 - 102,000
Health plan
401(k) with employer matching
Life insurance
Actuary, Insurance & Product Risk Mgmt
Actuary, Insurance & Product Risk Mgmt

MetLife • St. Louis (MO)

Hybrid
USD 116,000 - 155,000
Health plan
401(k) with match
Life insurance
+2