Senior Counsel, Cyber Security and Incident Response
Listed on 2026-08-30
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Core Weave is The Essential Cloud for AI™. Built for pioneers by pioneers, Core Weave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, Core Weave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, Core Weave became a publicly traded company (Nasdaq: CRWV) in March 2025.
Learn more at .
The Legal and Government Affairs team at Core Weave is highly collaborative and partners closely with teams across the company to navigate complex legal landscapes while enabling innovation and growth. The team is pragmatic, solutions-oriented, and deeply engaged in strategic decision-making, with a strong emphasis on building trusted relationships across the organization.
As Senior Counsel, Cybersecurity & Incident Response, you will serve as a key legal partner to Security and other cross-functional teams on cybersecurity preparedness, incident response, and related regulatory compliance. If you thrive in a dynamic, fast-paced environment, enjoy solving complex problems, and are eager to make a significant impact, Core Weave is the place for you.
About the role:Reporting to the Senior Director & Lead Managing Counsel, Privacy, Regulatory & Compliance, you will provide practical, real-time advice during complex security events, help preserve legal privilege, assess legal and contractual notification obligations, and guide matters from initial investigation through remediation and post-incident review. You will also help strengthen incident response governance, playbooks, and exercises in a rapidly scaling, global cloud infrastructure environment.
Inthis role, you will:
- Provide timely, practical legal advice throughout the cybersecurity incident lifecycle, including triage, investigation, containment, remediation, recovery, and post-incident review.
- Partner closely with Security, Privacy, IT, Engineering, Product, Communications, Customer Support, Insurance, and business leaders to coordinate legally sound incident response and decision-making.
- Direct or support privileged investigations, including engagement of outside counsel and forensic firms, evidence preservation, root-cause analysis, documentation, and interactions with law enforcement.
- Assess notification and disclosure obligations under applicable cybersecurity, privacy, data breach, securities, and sector-specific laws, as well as customer, vendor, insurance, and other contractual requirements.
- Draft and review executive and Board updates, customer and regulatory notices, law-enforcement communications, and other incident-related communications for accuracy, consistency, and legal risk.
- Advise on cybersecurity laws, regulations, regulatory inquiries, and enforcement trends affecting cloud infrastructure and technology companies, and translate requirements into scalable controls and processes.
- Develop and maintain incident response plans, legal playbooks, notification matrices, escalation criteria, decision records, and training; design and participate in tabletop exercises and drive legal follow-up actions.
- 4+ years of relevant legal experience, including meaningful experience advising on cybersecurity incidents, data breaches, digital investigations, or cybersecurity regulatory matters; a mix of law firm and in-house experience is preferred.
- Demonstrated ability to independently manage complex and sensitive cybersecurity matters and provide clear advice in fast-moving, high-pressure situations with incomplete facts.
- Strong working knowledge of U.S. federal and state breach notification requirements, cybersecurity regulatory frameworks, and contractual incident notification obligations; familiarity with international requirements is a plus.
- Experience assessing incident materiality, escalation, notification, and disclosure issues and documenting defensible legal decisions.
- Experience conducting privileged investigations and working with cybersecurity professionals, forensic investigators, outside counsel, regulators, and law enforcement.
- Ability to understand technical facts, ask precise questions, and translate forensic findings, system architecture, logs, and security concepts into actionable legal guidance.
- Excellent drafting and communication skills, including experience preparing concise executive updates and accurate customer, regulator, and public-facing communications.
- Strong judgment, discretion, and composure, with the ability to prioritize competing demands and support significant incidents outside standard business hours when necessary.
- Proven ability to build trusted relationships and work cross-functionally with technical, operational, communications, commercial, and executive stakeholders.
- J.D. from an accredited law school and active membership in at least o
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).