- Location
- Menara Maxis, Malaysia
- Type
- Full-time
- Department
- Legal
- Seniority
- Senior
- Experience
- 8+ years
- Education
- Bachelor
- Source
- Workday
Description
Are you ready to get ahead in your career?
- We want to empower you to turn your ambitions into achievements.
- We thrive in inclusiveness, diversity and embrace close collaborations for you to create impact for yourself and others.
- Together, we aim to bring the best of technology to help people, businesses and the nation to be ahead in a changing world.
- To realise our vision to become Malaysia’s leading converged solutions company, we are looking for a new talent to innovate and grow with us in a culture that values commitment, performance and possibilities.
Why does this job exist and why is it critical?
Maxis is seeking an experienced and strategic Senior Legal Counsel to support the Group's strategic, regulatory, governance and data protection agenda.
Working closely with senior stakeholders across the organisation, the role serves as a trusted legal advisor on complex business initiatives, regulatory matters and risk management issues, including personal data protection and privacy. The incumbent will provide expert legal guidance on compliance with the Personal Data Protection Act 2010 (PDPA), evolving regulatory requirements, strategic business projects, governance initiatives and digital transformation activities.
The role will also support the development and enhancement of privacy and governance frameworks, advise on complex data processing activities, manage legal and regulatory risks, and ensure that contractual arrangements, policies and business processes appropriately address legal, compliance and data protection obligations.
Key Responsibilities
Strategic Regulatory, Governance & Data Protection Advisory
- Serve as a trusted legal advisor to business and functional leaders on strategic initiatives, regulatory developments, governance matters, digital transformation programmes and enterprise risk management.
- Provide pragmatic, risk-based legal advice on compliance with the Personal Data Protection Act 2010 (PDPA), competition law, communications and multimedia regulatory requirements, export controls, sanctions, technology-related legal risks and evolving regulatory expectations.
- Support the development, implementation and continuous enhancement of the Group's data protection, governance and compliance frameworks.
- Advise business, technology, digital and corporate functions on legal, regulatory and data protection implications arising from new products, services, commercial arrangements, strategic partnerships and transformation initiatives.
- Provide legal guidance on personal data processing activities, including collection, use, disclosure, retention, sharing, automated processing and cross-border data transfers.
- Advise on competition law considerations, including anti-competitive conduct, information sharing, commercial collaborations, market practices and regulatory compliance requirements.
- Support the business on matters relating to the Communications and Multimedia Act 1998, licensing obligations, regulatory frameworks, consumer protection requirements and interactions with sector regulators.
- Advise on export control, sanctions and trade compliance requirements affecting technology, telecommunications equipment, software, services and cross-border business activities.
- Support the incorporation of appropriate legal, regulatory and data protection requirements into contractual arrangements, corporate policies, governance frameworks and operational processes.
Regulatory Investigations, Incident Management & Risk Response
- Advise on legal and regulatory issues arising from personal data incidents, data breaches, cybersecurity incidents and other regulatory matters.
- Support the assessment of regulatory risks, notification requirements, remediation measures and engagement strategies with regulators and relevant stakeholders.
- Partner with Regulatory, Risk, Cyber Security, Compliance and Business teams to strengthen organisational resilience and incident response capabilities.
- Support regulatory engagements, inspections, investigations and responses involving privacy, technology, governance, competition law, communications regulation and other regulatory matters.
- Provide legal support in responding to regulatory inquiries, audits, enforcement actions and investigations by regulators and governmental authorities.
- Assist in assessing and managing legal and regulatory risks arising from export control, sanctions, trade compliance and cross-border business activities.
Qualifications & Experience Required
Requirements
- Bachelor of Laws (LLB) or equivalent recognised legal qualification.
- Called to the Malaysian Bar or qualified to practise in a recognised common law jurisdiction.
- At least 8 years of relevant experience in data protection, privacy, regulatory advisory, or legal practice with significant exposure to privacy and data governance matters.
Preferred Experience
- Strong expertise in PDPA compliance, privacy governance, regulatory advisory, data breach management, technology regulation, cybersecurity and digital risk management.
- Experience advising on competition law, communications and multimedia regulation, regulatory investigations, enforcement matters and interactions with regulators.
- Experience supporting major transformation programmes, digital initiatives and enterprise-wide governance projects.
- Experience engaging with regulators and government agencies on complex regulatory and compliance matters.
- Experience advising on export controls, sanctions, trade compliance and strategic technology-related regulatory requirements would be highly advantageous.
- Experience gained through a combination of private practice and in-house legal roles, preferably within public-listed companies, regulated industries, multinational corporations (MNCs), or other complex corporate environments.
Professional Certifications (Advantageous)
- Relevant professional certifications in privacy, cybersecurity, technology governance, AI governance, competition law, export controls, sanctions and trade compliance, regulatory affairs, or related fields are highly desirable.
What’s next?
- Once you’ve applied online, our team will carefully review your application. Due to a high volume of applications, we appreciate your patience to allow for a fair and timely review process.
- Should you be shortlisted for the role, we will send you an invitation via email for a digital interview. You can also check on your application status by logging into your candidate account.
Maxis values diverse voices & people. We hire and reward our employees based on capability & performance — regardless of ethnicity, gender, age, education, religion, nationality or physical ability.