Overview
This role is for a U.S.-based Director, Legal (Cybersecurity) serving as the organization’s lead cybersecurity counsel. Reporting to the General Counsel and SVP, Commercial Partnerships, you will be the primary legal partner to the CISO and Security organization.
You will work closely with teams across AI infrastructure, data center operations, engineering, commercial legal, procurement, privacy, finance, and the executive team.
Responsibilities
Cybersecurity legal leadership and governance
- Advise the Security team on security programs, policies, controls, and risk decisions as the CISO’s closest legal partner.
- Lead and manage external counsel as a hands-on, player-coach.
- Build and lead the cybersecurity legal and regulatory compliance program across the U.S., while supporting execution in the UK, EU, and other regions.
- Advise on the legal side of security frameworks and certifications, including SOC 2, ISO 27001, NIST CSF, FedRAMP, and CMMC.
- Support Board, Audit Committee, and executive reporting on cyber risk and governance.
Incident response and cyber disclosure
- Lead legal strategy for security incidents and investigations, including directing privileged investigations, engaging forensic firms and outside counsel, and coordinating with law enforcement.
- Own breach notification analysis and execution across U.S. state, federal, and international regimes, and customer contractual obligations.
- Partner with Finance, Securities counsel, and Investor Relations on SEC cybersecurity disclosure obligations, including materiality assessments, Form 8-K reporting, and annual 10-K governance disclosures.
- Design and run incident response playbooks and executive tabletop exercises, and maintain a response posture ready for ransomware and extortion events.
Regulatory and critical infrastructure
- Monitor and advise on the evolving cyber regulatory landscape, including CIRCIA, SEC rules, FTC and state enforcement, NIS2, DORA, and UK cyber resilience legislation.
- Advise on security obligations tied to critical infrastructure, data centers, and public sector and regulated-industry customers.
- Manage regulatory enquiries and engagement with cyber and data regulators.
Commercial and third-party risk
- Partner with commercial legal and procurement on security terms in customer and supplier contracts, including security addenda, audit rights, incident notification, liability, and SLAs.
- Lead security due diligence and contractual controls across the supply chain, including hardware, software, and colocation partners.
- Advise on cyber insurance coverage, claims, and renewals.
- Support M&A, investor diligence, and strategic partnerships as the cybersecurity subject matter expert.
Cross-functional advisory
- Advise on vulnerability disclosure, bug bounty, threat intelligence sharing, and security research programs.
- Partner with the Privacy & AI team on data protection, AI security, and model and data security issues.
- Build security-legal awareness across the business, and scale guidance through playbooks and training.
KPIs
- A mature, audit-ready cybersecurity legal and compliance program
- Timely, defensible incident response, notification, and SEC disclosure decisions
- Effective security risk allocation in customer and supplier contracts
- Board and executive confidence in cyber governance and reporting
Requirements
- U.S.-qualified attorney with 10+ years of experience, including significant in-house experience as cybersecurity or security counsel, preferably at a hyperscaler, cloud provider, AI lab, or high-growth tech company. Exceptional private practice candidates will also be considered.
- Proven track record leading legal response to significant security incidents, including privileged investigations, notifications, and regulator engagement.
- Working knowledge of SEC cybersecurity disclosure requirements and public company governance.
- Strong familiarity with U.S. federal and state cyber and data security laws, and international regimes such as NIS2, DORA, and UK and EU GDPR security obligations.
- Trusted partner to CISOs and security engineers, able to understand technical controls and translate risk into clear business decisions.
- Able to act as an independent legal voice while remaining an embedded partner to Security.
- Litigation or investigations experience is a strong plus.
- Calm, sound judgment under pressure, with a high degree of discretion.
- Excellent communicator who can influence at all levels, including executives and the Board.
- Comfortable operating with ambiguity in a fast-paced, high-growth environment.
Preferred Qualifications
- Experience with critical infrastructure, data centers, or public sector security (FedRAMP, CMMC, DFARS)
- Professional certifications such as CIPP/US, CISSP, or equivalent
- Pre- or post-IPO company experience
- Familiarity with AI and model security issues
Compensation & Benefits
- Salary Range: $210,000 USD - $340,000 USD
- Actual compensation may vary based on job-related factors such as skill set, experience, education, and location.
- In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs.
- Benefits may include medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
Location
U.S.-based