Overview
A corporate legal team is seeking a Senior Counsel to support the enterprise’s cybersecurity function. The preferred locations for this position are either the corporate office in Beachwood, OH or Moon Township, PA, with remote work available from the Eastern or Central time zones. Some travel is expected (approximately 10%).
This role leads a cross-functional cybersecurity legal program integrating security operations, incident response, governance, and regulatory/data privacy compliance, while advancing responsible AI security and risk management. The Senior Counsel acts as the legal liaison among Cybersecurity, IT, OT, Communications, HR, and Finance to help prevent, detect, respond to, and recover from cyber incidents and AI-related risks, ensuring compliance with global legal and regulatory obligations.
Responsibilities
Incident Readiness & Response
- Own legal aspects of the enterprise incident response (IR) program including preparation, detection, response, recovery, and lessons learned.
- Manage executive-ready IR playbooks defining roles and functions.
- Assist with planning, deployment, and debriefing of tabletop exercises with internal teams and external firms.
- Track remediation items through closure and report outcomes to senior leadership and the board.
- Serve as on-call executive advisor for material incidents, coordinating with security operations, corporate event response teams, outside counsel, insurers, regulators, and law enforcement.
- Ensure eDiscovery, privilege, and regulatory timeline considerations are embedded in IR workflows.
- Coordinate with Engineering and IT on AI incident reporting obligations under emerging regulations.
Security Governance, Risk & Compliance
- Participate in cross-functional Cybersecurity/IT/OT governance forums.
- Align policy and standards with Zero Trust, identity, network, cloud, and OT security programs.
- Oversee policy lifecycle including drafting, socializing, approval, and measurement.
- Manage AI security monitoring standards and privacy by design controls in partnership with Data Protection Privacy teams.
- Direct risk assessments for major programs and products; track risk treatment plans and key risk/ performance indicators in collaboration with Governance, Risk & Compliance (GRC) and Internal Audit.
Regulatory & Global Counsel Integration
- Act as executive point of contact for global cybersecurity and data protection laws (e.g., U.S. sectoral rules, EU NIS2/GDPR, China’s Cybersecurity Law).
- Coordinate with regional counsel and external advisors to interpret obligations and translate them into operational controls.
- Lead regulatory response readiness including notifications, supervisory inquiries, and exam preparation.
- Ensure documentation and attestations are accurate and defensible.
- Track and interpret AI-related regulatory developments (EU AI Act, U.S. state AI laws) and translate them into actionable compliance requirements.
Enterprise & Product Security Reviews
- Co-lead Cyber Product Review and security architecture gates for enterprise platforms and customer-facing products/solutions.
- Drive decision logs, actions, and risk acceptance processes with accountable owners (IT, Engineering, Product, Legal).
- Expand Cyber Product Reviews to include AI risk assessments for products and internal tools.
- Ensure secure model deployment and vendor risk evaluations.
- Oversee integration, vulnerability management, and cloud security roadmaps.
- Report progress, risks, and dependencies through executive dashboards.
Stakeholder Engagement & Communication
- Provide board and C-suite briefings on AI risk, cyber posture, material risks, control maturity, and incident updates.
- Craft clear, business outcome-focused narratives.
- Partner with Corporate Communications to prepare proactive/reactive statements and media strategies as part of incident response planning and exercises.
- Coach and enable business and function leaders to own cyber risk within their domains.
Requirements
Basic Qualifications:
- Juris Doctorate; licensed and in good standing to practice law in at least one U.S. state.
- Experience working in both a global law firm and a global corporation (in-house counsel).
- Minimum of 10 years in cybersecurity, cyber risk, incident response, or closely related domains with significant cross-functional leadership.
- Demonstrated experience leading complex incidents and tabletop exercises.
- Experience working directly with outside counsel, insurers, and regulators.
- Willingness to travel up to 10%.
- The employer will not consider applicants requiring employment immigration sponsorship or support.
Preferred Qualifications:
- Relevant certifications such as CISSP, CISM, CISA, CCSP, or privacy credentials (e.g., CIPP/E, CIPP/US, CIPM).
- Experience with OT security governance and enterprise Zero Trust transformations.
- Experience working within a complex, multinational company.
- Experience in manufacturing or other highly-engineered, physical product-based organizations is helpful.
Skills:
- Strong command of global cybersecurity and data protection frameworks.
- Proven ability to translate legal and regulatory obligations into executable controls and measurable program outcomes.
- Executive presence with excellent written and oral communication skills for board-level stakeholders.
Compensation & Benefits
- The expected annual salary range for this role is $182,000 to $266,000.
- This role is eligible for a variable incentive program.
- Competitive pay and a variety of benefit programs are offered for eligible employees.
Location
- Preferred locations: Beachwood, OH or Moon Township, PA.
- Remote work available from Eastern or Central time zones.
- Some travel required (approximately 10%).