Apply Now

You will be taken to job-boards.greenhouse.io to complete your application.

CoreWeave is The Essential Cloud for AI. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence.

As Senior Counsel, Cybersecurity & Incident Response, you will serve as a key legal partner to Security and other cross-functional teams on cybersecurity preparedness, incident response, and related regulatory compliance.

Responsibilities:

  • Provide timely, practical legal advice throughout the cybersecurity incident lifecycle, including triage, investigation, containment, remediation, recovery, and post-incident review.
  • Partner closely with Security, Privacy, IT, Engineering, Product, Communications, Customer Support, Insurance, and business leaders to coordinate legally sound incident response and decision-making.
  • Direct or support privileged investigations, including engagement of outside counsel and forensic firms, evidence preservation, root-cause analysis, documentation, and interactions with law enforcement.
  • Assess notification and disclosure obligations under applicable cybersecurity, privacy, data breach, securities, and sector-specific laws, as well as customer, vendor, insurance, and other contractual requirements.
  • Draft and review executive and Board updates, customer and regulatory notices, law-enforcement communications, and other incident-related communications for accuracy, consistency, and legal risk.
  • Advise on cybersecurity laws, regulations, regulatory inquiries, and enforcement trends affecting cloud infrastructure and technology companies, and translate requirements into scalable controls and processes.
  • Develop and maintain incident response plans, legal playbooks, notification matrices, escalation criteria, decision records, and training; design and participate in tabletop exercises and drive legal follow-up actions.

Requirements:

  • 4+ years of relevant legal experience, including meaningful experience advising on cybersecurity incidents, data breaches, digital investigations, or cybersecurity regulatory matters; a mix of law firm and in-house experience is preferred.
  • Demonstrated ability to independently manage complex and sensitive cybersecurity matters and provide clear advice in fast-moving, high-pressure situations with incomplete facts.
  • Strong working knowledge of U.S. federal and state breach notification requirements, cybersecurity regulatory frameworks, and contractual incident notification obligations; familiarity with international requirements is a plus.
  • Experience assessing incident materiality, escalation, notification, and disclosure issues and documenting defensible legal decisions.
  • Experience conducting privileged investigations and working with cybersecurity professionals, forensic investigators, outside counsel, regulators, and law enforcement.
  • Ability to understand technical facts, ask precise questions, and translate forensic findings, system architecture, logs, and security concepts into actionable legal guidance.
  • Excellent drafting and communication skills, including experience preparing concise executive updates and accurate customer, regulator, and public-facing communications.
  • Strong judgment, discretion, and composure, with the ability to prioritize competing demands and support significant incidents outside standard business hours when necessary.
  • Proven ability to build trusted relationships and work cross-functionally with technical, operational, communications, commercial, and executive stakeholders.
  • J.D. from an accredited law school and active membership in at least one U.S. state bar (NY, NJ, CA, DC, or WA preferred).

Preferred Qualifications:

  • Experience advising a high-growth cloud, SaaS, data center, infrastructure, or other technology company.
  • Experience with public-company cybersecurity materiality, governance, and disclosure processes.
  • Experience advising on ransomware, insider threats, supply-chain incidents, credential compromise, and cloud security events.
  • Experience developing and testing incident response plans, legal playbooks, and tabletop exercises.
  • Privacy or cybersecurity credentials such as CIPP/US, CIPP/E, CIPM, CISSP, or comparable training.

What We Offer:

  • The base salary range for this role is $157,000 to $210,000.
  • A comprehensive benefits program, including medical, dental, and vision insurance, company-paid Life Insurance, short and long-term disability insurance, flexible spending account, health savings account, tuition reimbursement, employee stock purchase program, mental wellness benefits, family-forming support, paid parental leave, flexible childcare support, 401(k) with a generous employer match, flexible PTO, catered lunch each day in our office and data center locations, a casual work environment, and a work culture focused on innovative disruption.