Michael Davie has spent his career working at the intersection of technology, security and increasingly, privacy and cybersecurity regulation. He currently manages cloud security at Wealthsimple and previously held cybersecurity and compliance leadership roles at Amazon Web Services (AWS) and the Communications Security Establishment (CSE). It was during his time at CSE, when major changes to Canada’s national security legislation were reshaping the legal framework around intelligence and cybersecurity, that he found himself increasingly interested in the legal and policy side of his work.
He had already completed an undergraduate certificate in law at Queen’s University and knew he enjoyed the subject. When he discovered Osgoode’s Professional LLM in Privacy and Cybersecurity Law, he says, “it was really exactly what I was looking for.”
Michael enrolled because he wanted a practical understanding of Canadian privacy and cybersecurity law. The timing turned out to be ideal. A few months before starting the LLM, he became Canada lead for compliance and security assurance at AWS, where he was closely involved in legislative and regulatory developments affecting cybersecurity, critical infrastructure and privacy.
The program gave him a legal vocabulary that proved useful almost immediately. Working with public policy teams, legislators, in-house counsel, external lawyers and government officials became much easier once he understood the legal frameworks they were working within.
“Being able to work with public policy people, with legislators, with legal, with internal lawyers and external lawyers, was definitely very helpful,” he says.
One of the biggest surprises was how useful the legal research training became. Before the program, he had little experience navigating legislation, case law or legal databases. Learning how to find, interpret and compare legal sources changed the way he approached his work.
“That was a whole black box if you don’t learn about it,” he says.
In his AWS role, Michael worked with counterparts across Australia, the United Kingdom, the United States and other jurisdictions, which made the program’s international perspective particularly valuable. Courses comparing Canadian, American, European and Australian legal frameworks helped him think beyond domestic legislation and evaluate how other countries had approached similar problems.
He found that looking at legislative history in other jurisdictions could be surprisingly practical. “Australia tried this, and it didn’t work, and two years later they had to amend it,” he says. “So why don’t we just skip to the end?”
Asked which parts of the program were most relevant, Michael struggles to choose. Privacy and cybersecurity law was directly applicable to his work, but national security, criminal law and international law also proved unexpectedly useful. His major research paper focused on the CSE, Bill C-59 and the oversight regime created through that legislation, while another paper examined international cooperation in cybercrime investigations through the Budapest Convention on Cybercrime.
What has stayed with him most is the broader perspective the program provided.
Cybersecurity teams are often highly technical, he says, and it can be easy to become narrowly focused on systems, controls and operational problems. Understanding the legal frameworks surrounding privacy and cybersecurity – from privacy legislation to international cooperation mechanisms – helps explain not only what organizations need to protect, but why those obligations exist in the first place.
“It gives me a much broader perspective,” he says. “That’s the main thing.”
The classroom itself also expanded his understanding of the legal profession. One Privacy and Cybersecurity Law course, Crime in the Digital Age, included prosecutors, defence lawyers and a justice of the peace among his classmates, giving him a perspective on criminal law that he had never encountered in his technical career. A discussion about whether a thumbs-up emoji could constitute acceptance of a contract became a memorable example of how quickly legal questions can emerge from everyday technology.
Today, as manager of cloud security at Wealthsimple, Michael still works primarily in cybersecurity, but with a much deeper understanding of the legal and regulatory environment surrounding it. The LLM gave him a stronger foundation for working across technical, legal and policy teams and a broader view of how cybersecurity fits into the larger legal landscape.
Wondering if the Professional LLM is right for you? Get information on course requirements, application dates, tuition and more!

Michael Davie – Manager of Cloud Security, Wealthsimple
Graduate of Osgoode’s Professional LLM in Privacy and Cybersecurity Law (2024)