About Us
Sophos is a cybersecurity leader defending 600,000 organizations globally with an AI-driven platform and expert-led services. Sophos meets organizations wherever they are in their security maturity and grows with them to defeat cyberattacks. Its solutions combine machine learning, automation, and real-time threat intelligence with frontline human expertise from Sophos X-Ops to deliver advanced, 24/7 threat monitoring, detection, and response.
Sophos offers industry-leading managed detection and response (MDR) alongside a comprehensive portfolio of cybersecurity technologies — including endpoint, network, email, and cloud security, extended detection and response (XDR), identity threat detection and response (ITDR), and next-gen SIEM. Together with expert advisory services, these capabilities help organizations proactively reduce risk and respond faster, with the visibility and scalability needed to stay ahead of evolving threats.
Sophos goes to market with a global partner ecosystem, including Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), resellers and distributors, marketplace integrations, and cyber risk partners, giving organizations the flexibility to choose trusted relationships when securing their business. Sophos is headquartered in Oxford, U.K. More information is available at
www.sophos.com.
Role Summary
We are looking for a Contracts Negotiator to join our Legal team, focused on negotiating and managing customer-facing commercial agreements across the Americas. This role works closely with our sales, channel, and business teams to move deals forward while protecting Sophos's interests. You will handle a high volume of negotiations across a range of deal sizes and customer types, from mid-market businesses to large enterprises.
This is a commercial contracts role, not a practicing attorney position. Lawyers are welcome to apply, but a law degree is not required.
What You Will Do
Negotiate customer agreements including subscription agreements, order forms, SaaS terms, MSA/SOW structures, amendments, renewals, and channel partner agreements across the Americas region
Review, redline, and negotiate customer paper (including procurement terms, DPAs, and security addenda) against Sophos's approved positions and playbooks
Partner with Sales, Deal Desk, and other business stakeholders to support deal velocity while managing commercial and contractual risk
Escalate issues that require legal judgment to in-house counsel, with clear summaries of the issue, business context, and recommended path forward
Maintain and help improve contract templates, fallback language, and negotiation playbooks
Track and manage a pipeline of active negotiations, ensuring timely turnaround and clear communication with internal stakeholders
Identify trends in customer pushback and work with the Legal team to develop scalable responses
Support process improvements in contract lifecycle management, including workflow tools and approval processes
What You Will Bring
3+ years of experience negotiating commercial contracts, preferably in a technology, SaaS, or cybersecurity company
Demonstrated ability to read, interpret, and negotiate complex commercial agreements without direct supervision
Strong understanding of common commercial contract concepts: limitation of liability, indemnification, IP ownership, data protection, warranties, and termination rights
Familiarity with SaaS and subscription-based business models
Experience working with Sales teams in a fast-paced, deal-driven environment
Excellent written and verbal communication skills, with the ability to explain contract positions to non-legal stakeholders
Strong organizational skills and the ability to manage a high volume of concurrent negotiations
Comfort working across time zones in the Americas region
Preferred Qualifications
Experience negotiating with U.S., Canadian, and Latin American customers
Familiarity with government or public sector contracting in the Americas
Experience with contract lifecycle management (CLM) tools
Background in cybersecurity, IT infrastructure, or enterprise software
Paralegal certification, contract management certification (e.g., IACCM/WorldCC), or equivalent professional training