
Legal Manager – AI, Cybersecurity & Technology
Legal Manager – AI, Cybersecurity & Technology
About us:
The physical and digital worlds are merging. Vehicles, medical devices, industrial systems, critical infrastructure: security hasn't kept pace. AI is accelerating everything, from the capabilities of the systems we depend on to the sophistication of the threats targeting them. A software vulnerability can now have physical consequences. A physical breach can compromise entire digital ecosystems. Billions of devices operate with little to no protection, and traditional approaches can't keep up. Not at this scale, not at this speed, and not across this diversity of systems.
Exein exists to solve this. We build the security layer for a world where physical and digital threats are no longer separate problems, from kernel-level runtime protection on embedded devices to cloud-native platforms that analyze, protect, and prove compliance across entire device fleets. We're not patching the old model. We're building security from the core out.
Overview:
We’re looking for a Legal Manager ready to take ownership of the legal function in a fast-growing company operating at the intersection of AI, cybersecurity and connected technologies.
This role is ideal for a hands-on legal leader who is comfortable combining strategic responsibility with day-to-day legal execution. You will lead the Legal function autonomously, reporting directly to the CFO, and working closely with Product, Engineering, Security, Sales, Finance, and Leadership.
Your role
As Legal Manager, you will:
- Own and lead the Legal function, defining priorities, processes, templates, and standards.
- Act as the company’s internal legal advisor, supporting strategic, commercial, product, and operational decisions.
- Be the main legal point of contact for customers, partners, suppliers, investors, and external counsel.
- Partner closely with Product, Engineering and Security teams to identify and address legal and regulatory implications of new technologies and products.
- Support the business in scaling internationally while maintaining an appropriate legal and compliance framework.
What you’ll do
Commercial & Product Legal
- Negotiate and manage enterprise, technology, cybersecurity and SaaS agreements with customers, independently assessing legal and commercial risks.
- Draft and review agreements with suppliers, technology partners, strategic partners, and other third parties.
- Support Sales and Business Development in customer negotiations, RFPs, procurement processes, and customer due diligence.
- Work closely with Product, Engineering and Security teams on the legal implications of AI-enabled, embedded, connected and cybersecurity products and services.
- Advise on product-related legal matters, including product liability, warranties, indemnities, limitation of liability, licensing, and allocation of responsibilities across the technology supply chain.
- Support the company on intellectual property, software licensing, technology ownership, and commercialisation matters.
- Develop and maintain contract templates, playbooks, negotiation guidelines, and legal processes to enable the business to scale efficiently.
- Handle internal corporate documentation, including BoD minutes, resolutions, and other corporate matters.
- Support fundraising, investor negotiations, M&A activities, and related legal due diligence and data room processes.
Regulatory, Privacy & Compliance
- Monitor and support compliance with key EU and Italian regulations relevant to AI, cybersecurity, technology and data protection, including:
- GDPR and the Italian Privacy Code;
- Cyber Resilience Act (CRA);
- EU AI Act;
- NIS2 and relevant cybersecurity requirements;
- Whistleblowing;
- Legislative Decree 231/2001;
- other applicable technology and product-related regulations.
- Assess the legal and regulatory impact of new products, features, technologies, and business models.
- Work with Product, Engineering and Security to embed Privacy, Security and Compliance by Design into products and services.
- Own and maintain privacy documentation, including RoPA, DPIAs, LIAs, TIAs, vendor appointments, and related documentation.
- Support the Security Team during ISO 27001 and SOC 2 Type II certification and compliance processes.
- Support regulatory and customer-facing cybersecurity and compliance assessments.
- Deliver internal training on GDPR, contract standards, and relevant legal and regulatory requirements.
- Continuously monitor legal and regulatory developments and translate them into practical actions for the business.
Cross-functional support
- Partner with Sales, Product, Engineering, Security and Finance to provide practical, business-oriented legal advice.
- Collaborate on customer security and legal due diligence processes and RFPs.
- Contribute to the drafting, implementation and review of company policies.
- Help the company anticipate legal and regulatory risks rather than addressing them only after they arise.
- Manage relationships with external counsel and specialised legal advisors where required.
What we’re looking for
Must-have
- Master’s Degree in Law.
- Qualified lawyer (Bar admitted).
- 4+ years of experience in a top law firm and/or as in-house counsel.
- Proven ability to work autonomously, prioritize, and make sound business-oriented decisions.
- Strong experience negotiating technology, commercial, cybersecurity and S aaS contracts.
- Strong understanding of IT law, technology transactions and data protection.
- Good working knowledge of the EU regulatory landscape relevant to AI, cybersecurity and digital products, including GDPR, CRA, AI Act and NIS2.
- Ability to work effectively with Product, Engineering, Security and commercial teams, including on complex and highly technical topics.
- Strong communication and negotiation skills, with the ability to translate complex legal requirements into clear and practical business advice.
- Fluent in English.
- Comfortable working in a fast-paced, international and technology-driven environment.
Nice to have
- Previous experience in cybersecurity, AI, embedded systems, IoT, deep tech, software, hardware or other technology-driven environments.
- Experience with product legal matters, including product liability, software licensing and technology IP.
- Experience working with international enterprise customers and complex procurement processes.
- Familiarity with DORA Regulation and financial-sector regulatory requirements.
- Familiarity with Legislative Decree 231/2001 and Decree 24/2023.
- Experience supporting ISO 27001, SOC 2, or other security/compliance frameworks.
- Experience working in a high-growth startup or scale-up environment.
- Comfortable working with macOS and iOS devices.
Location: Rome - Hybrid (Piazzale Flaminio 19, 00196)
Salary range:
€50K - €60K
Exein is committed to creating an inclusive workplace. We evaluate all applications fairly regardless of gender, age, ethnicity, background, or orientation.
Apply for this job
*
indicates a required field