Assistant General Counsel (Dublin / London) at KBRA
Kroll Bond Rating Agency (KBRA)
last date
Open Access
Location/Place/Mode
Dublin, Ireland or London, England
Eligibility
Qualifying law degree (or equivalent) and admission to practise as a solicitor in Ireland or England & Wales, with a current (or eligible) practising certificate. 4-8 years post-qualification experience with hands-on exposure to privacy/data protection law. Strong experience in drafting, negotiating, and reviewing contracts (DPAs, vendor agreements, client contracts). Demonstrated knowledge of GDPR (EU & UK), cross-border data transfer mechanisms, ePrivacy laws, vendor/third-party risk, and cybersecurity basics. Exceptional verbal and written communication, research, analytical, organisational, and project management skills. Experience in regulated environments (financial services, tech, data/analytics) preferred. IAPP certification (CIPP/E, CIPP/US, CIPM) is a plus.

Opportunity
The New Frontier of Credit Rating Law: Privacy Takes Center Stage
In the fast-evolving world of financial services, the title 'Assistant General Counsel' is no longer confined to corporate governance and contract review. At KBRA (Kroll Bond Rating Agency), a globally recognized credit rating agency, the legal team is now seeking a professional who can navigate the intricate intersection of privacy, data protection, and commercial law. This is not just another in-house counsel opening; it is a strategic hire that underscores how deeply data privacy has become embedded in the credit rating ecosystem. With offices in Dublin and London, KBRA is looking for a lawyer who can seamlessly manage GDPR compliance, cross-border data transfers, and cutting-edge AI governance while also drafting and negotiating complex commercial agreements.
The role comes at a time when regulators across the EU, UK, and US are sharpening their focus on how financial institutions handle personal data. For legal professionals with a passion for privacy law, this position offers a rare opportunity to work at the heart of a system that rates the creditworthiness of global entities. But what does this role truly entail, and how can you position yourself as the ideal candidate? Let’s unpack the layers of this exceptional career opportunity.
Inside the Assistant General Counsel Mandate at KBRA
According to the job description, the successful candidate will join a Legal Department that handles all of KBRA’s legal matters except for actual ratings. This means you will collaborate with analysts, compliance, finance, technology, and senior management on a daily basis. The primary focus, however, is on privacy and data protection, alongside contract work. Your day-to-day responsibilities will span a wide spectrum, from advising on international data privacy laws like GDPR, UK GDPR, ePrivacy, and CCPA/CPRA to conducting privacy impact assessments and legitimate interest assessments. You will also be the go-to person for incident and breach response, vendor due diligence, and cross-border data transfer mechanisms such as Standard Contractual Clauses and Binding Corporate Rules.
One of the most exciting aspects of this role is the emphasis on technology trends, particularly artificial intelligence. The job description explicitly mentions 'keeping up to date with technology trends, including AI, and technology in use at KBRA and how they interact with privacy laws.' This is a forward-looking mandate. As AI becomes more pervasive in credit analysis and risk modeling, the legal framework around it is still being written. Being part of that process is both challenging and rewarding.
"You will collaborate closely with cross-functional teams (Compliance, Technology, Marketing, Business Development), as well as external counsel and regulators, as needed."
This isn’t a back-office legal role. You’ll be delivering training and awareness programs, preparing board materials, and liaising with external regulators and auditors. If you thrive on influence and visibility, this position delivers both.
Your Roadmap to Meeting the 4–8 Years PQE Sweet Spot
The eligibility criteria are specific, and for good reason. KBRA is seeking someone who is not just a legal technician but a trusted advisor with 4 to 8 years of post-qualification experience (PQE). This is the sweet spot for in-house roles: you have enough experience to hit the ground running, yet you are still hungry to grow. The role requires admission as a solicitor in Ireland or England & Wales, with a current practising certificate or eligibility to obtain one. However, there is an interesting exception: 'Exceptionally, highly experienced privacy professionals with significant legal advisory experience may also be considered.' This opens the door for compliance professionals and data protection officers who have built deep privacy expertise but may not have a traditional solicitor background.
From a technical standpoint, you must have demonstrated knowledge of GDPR (both EU and UK), cross-border data transfer mechanisms, ePrivacy laws, and vendor/third-party risk. Experience in regulated environments—especially financial services, tech, or data/analytics—will give you a competitive edge. The job description also mentions that IAPP certification (CIPP/E, CIPP/US, CIPM) is a plus. If you are serious about this path, that certification is worth pursuing.
How to Stand Out in a Crowded In-House Job Market
In-house legal roles at prestigious financial firms attract hundreds of applicants. To stand out, your CV needs to tell a compelling story that aligns your privacy expertise with commercial acumen. Here are some actionable strategies:
- Quantify your impact: Instead of merely listing 'drafted DPAs,' explain how you streamlined contract turnaround times or mitigated regulatory risk. For example, "Negotiated 50+ data processing agreements with global vendors, reducing legal review time by 30% while ensuring GDPR compliance."
- Showcase cross-border experience: KBRA operates in Dublin and London, so highlight any work involving EU-UK data transfers, international vendor management, or multi-jurisdictional privacy compliance.
- Demonstrate your AI literacy: With AI explicitly mentioned in the job description, show that you understand how technologies like machine learning and algorithmic decision-making intersect with privacy. Mention any projects where you advised on AI governance or data ethics.
- Highlight your training and communication skills: The role involves delivering training and acting as a resource for internal teams. Include examples of presentations, workshops, or policy rollouts you have led.
- Tailor your cover letter: Address how your experience specifically helps KBRA’s credit rating business. For instance, you could discuss how you would handle data subject access requests from issuers or how you would support the implementation of a global privacy framework across multiple entities.
Don’t forget to prepare for behavioral questions. Expect to explain how you’ve handled a privacy breach, managed a difficult vendor negotiation, or advised on a cross-border data transfer project with tight deadlines.
Beyond the Paycheck: Why This Role Accelerates Your Career
Taking on an Assistant General Counsel role at KBRA is more than a job; it’s a career accelerator. Here’s why:
1. Exposure to a Highly Regulated Industry: Credit rating agencies are subject to intense oversight from regulators like the SEC, ESMA, and the UK FCA. Understanding how legal frameworks operate in this environment makes you a more versatile lawyer, with skills that are transferable to banks, fintechs, and multinational corporations.
2. The Intersection of Law and Technology: By working on AI and data privacy issues within a financial context, you become a niche expert. The demand for lawyers who can straddle both legal and technological domains is skyrocketing. This role positions you as a thought leader in that niche.
3. Senior Management Visibility: You will be preparing board materials and advising senior management on privacy governance. That kind of exposure early in your in-house career builds a strong foundation for future General Counsel roles.
4. Hybrid Work-Life Balance: The role offers a flexible hybrid schedule with just three days in the office (Tuesday through Thursday). This suggests a culture that respects work-life balance, which is increasingly rare in high-pressure legal roles.
Moreover, KBRA’s global footprint means potential opportunities for secondments, cross-border projects, and even internal mobility across different legal functions. Many Assistant General Counsels go on to become Deputy General Counsel or General Counsel within a few years, especially if they prove indispensable in niche areas like privacy.
Quick FAQ: Navigating the KBRA Application Process
Q1: What is the immediate first step if I want to apply?
While the original application link is not specified in the public posting, you should visit the KBRA careers page directly or check LinkedIn jobs. The posting explicitly says 'Apply' on LinkedIn, so the most straightforward route is to submit your application through LinkedIn, ensuring your profile is updated and your CV is tailored to the job description. You can also set up a job alert to be notified of similar roles.
Q2: Can I still apply if I don’t have 4-8 years of PQE but have extensive privacy compliance experience?
Yes. The job description includes an exceptional clause: 'Exceptionally, highly experienced privacy professionals with significant legal advisory experience may also be considered.' If you are a privacy professional with deep experience but not a solicitor, you should highlight your advisory experience, certifications (like CIPP/E), and quantifiable accomplishments. However, be prepared for the company to prioritize solicitor-qualified candidates unless your background is truly exceptional.
Q3: Does the role require fluency in any specific data protection law frameworks?
Yes, the role requires working knowledge of GDPR (EU and UK), the ePrivacy Directive, and CCPA/CPRA. You must also be familiar with cross-border data transfer mechanisms, particularly Standard Contractual Clauses and Binding Corporate Rules. Given the Dublin/London base, EU-UK data transfer issues are especially relevant, so highlight any hands-on experience with those.
Q4: What are the biggest challenges someone might face in this role, and how can they prepare?
The biggest challenges include managing the complexity of international privacy laws, keeping up with AI-related regulatory changes, and balancing legal rigor with business objectives. To prepare, consider taking an IAPP certification if you don’t already have one, and stay updated on recent regulatory guidance from the Irish Data Protection Commission, the UK ICO, and the EU’s proposed AI Act. Also, practice negotiating contract clauses under time pressure, as the role involves both drafting and negotiation.