Senior Counsel, Cyber Security and Incident Response
$157k - $210kCoreWeave
Job Description
Job Description
CoreWeave is The Essential Cloud for AI™. Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at
What You'll Do:The Legal and Government Affairs team at CoreWeave is highly collaborative and partners closely with teams across the company to navigate complex legal landscapes while enabling innovation and growth. The team is pragmatic, solutions-oriented, and deeply engaged in strategic decision-making, with a strong emphasis on building trusted relationships across the organization.
As Senior Counsel, Cybersecurity & Incident Response, you will serve as a key legal partner to Security and other cross-functional teams on cybersecurity preparedness, incident response, and related regulatory compliance. If you thrive in a dynamic, fast-paced environment, enjoy solving complex problems, and are eager to make a significant impact, CoreWeave is the place for you.
About the role:Reporting to the Senior Director & Lead Managing Counsel, Privacy, Regulatory & Compliance, you will provide practical, real-time advice during complex security events, help preserve legal privilege, assess legal and contractual notification obligations, and guide matters from initial investigation through remediation and post-incident review. You will also help strengthen incident response governance, playbooks, and exercises in a rapidly scaling, global cloud infrastructure environment.
In this role, you will:
- Provide timely, practical legal advice throughout the cybersecurity incident lifecycle, including triage, investigation, containment, remediation, recovery, and post-incident review.
- Partner closely with Security, Privacy, IT, Engineering, Product, Communications, Customer Support, Insurance, and business leaders to coordinate legally sound incident response and decision-making.
- Direct or support privileged investigations, including engagement of outside counsel and forensic firms, evidence preservation, root-cause analysis, documentation, and interactions with law enforcement.
- Assess notification and disclosure obligations under applicable cybersecurity, privacy, data breach, securities, and sector-specific laws, as well as customer, vendor, insurance, and other contractual requirements.
- Draft and review executive and Board updates, customer and regulatory notices, law-enforcement communications, and other incident-related communications for accuracy, consistency, and legal risk.
- Advise on cybersecurity laws, regulations, regulatory inquiries, and enforcement trends affecting cloud infrastructure and technology companies, and translate requirements into scalable controls and processes.
- Develop and maintain incident response plans, legal playbooks, notification matrices, escalation criteria, decision records, and training; design and participate in tabletop exercises and drive legal follow-up actions.
Who You Are:
- 4+ years of relevant legal experience, including meaningful experience advising on cybersecurity incidents, data breaches, digital investigations, or cybersecurity regulatory matters; a mix of law firm and in-house experience is preferred.
- Demonstrated ability to independently manage complex and sensitive cybersecurity matters and provide clear advice in fast-moving, high-pressure situations with incomplete facts.
- Strong working knowledge of U.S. federal and state breach notification requirements, cybersecurity regulatory frameworks, and contractual incident notification obligations; familiarity with international requirements is a plus.
- Experience assessing incident materiality, escalation, notification, and disclosure issues and documenting defensible legal decisions.
- Experience conducting privileged investigations and working with cybersecurity professionals, forensic investigators, outside counsel, regulators, and law enforcement.
- Ability to understand technical facts, ask precise questions, and translate forensic findings, system architecture, logs, and security concepts into actionable legal guidance.
- Excellent drafting and communication skills, including experience preparing concise executive updates and accurate customer, regulator, and public-facing communications.
- Strong judgment, discretion, and composure, with the ability to prioritize competing demands and support significant incidents outside standard business hours when necessary.
- Proven ability to build trusted relationships and work cross-functionally with technical, operational, communications, commercial, and executive stakeholders.
- J.D. from an accredited law school and active membership in at least one U.S. state bar (NY, NJ, CA, DC, or WA preferred).
- Experience advising a high-growth cloud, SaaS, data center, infrastructure, or other technology company.
- Experience with public-company cybersecurity materiality, governance, and disclosure processes.
- Experience advising on ransomware, insider threats, supply-chain incidents, credential compromise, and cloud security events.
- Experience developing and testing incident response plans, legal playbooks, and tabletop exercises.
- Privacy or cybersecurity credentials such as CIPP/US, CIPP/E, CIPM, CISSP, or comparable training.
We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams – even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk.
- You remain calm under pressure and can make sound, defensible decisions when facts are still developing.
- You're curious about technology and enjoy working closely with security and engineering teams to understand how systems operate.
- You communicate complex legal risk clearly and concisely, with a practical focus on protecting customers and enabling the business.
At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values:
- Be Curious at Your Core
- Act Like an Owner
- Empower Employees
- Deliver Best-in-Class Client Experiences
- Achieve More Together
We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us!
The base salary range for this role is $157,000 to $210,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).
What We Offer
The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location.
In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include:
- Medical, dental, and vision insurance - 100% paid for by CoreWeave
- Company-paid Life Insurance
- Voluntary supplemental life insurance
- Short and long-term disability insurance
- Flexible Spending Account
- Health Savings Account
- Tuition Reimbursement
- Ability to Participate in Employee Stock Purchase Program (ESPP)
- Mental Wellness Benefits through Spring Health
- Family-Forming support provided by Carrot
- Paid Parental Leave
- Flexible, full-service childcare support with Kinside
- 401(k) with a generous employer match
- Flexible PTO
- Catered lunch each day in our office and data center locations
- A casual work environment
- A work culture focused on innovative disruption
California Applicants
California Consumer Privacy Act
Equal Opportunity & Accommodations
CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.
As part of this commitment and consistent with the Americans with Disabilities Act (ADA) , CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: View email address on ziprecruiter.com.
Export Control Compliance
This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.
- Solutions³ LLC is seeking an Incident Manager III to lead investigations for a U.S. Government client, coordinating incident response actions, evaluating data, and drafting leadership summaries across the lifecycle. You will work with internal and external partners, maintain...Senior
- Gunnison Consulting Group in the United States is seeking a senior cybersecurity incident response leader to coordinate and drive enterprise IR activities... ..., exercises, and executive reporting to strengthen security posture. Applicants should have a Master’s in IT/...Senior
- BCMC is seeking a Cyber Incident Response Expert to support the DHS Hunt and Incident Response Team (HIRT). The role involves advanced host and... ...and technical reports, guide response activities with senior teams, and help maintain process documentation across branches...Senior
- Everforth ECS seeks a Senior Cyber Incident Analyst to join our Arlington team, coordinating incident response and threat intelligence for government partners. You will design playbooks, guide mitigation strategies, and deliver clear reports to executives and stakeholders...SeniorLocal area
- Tetrad Digital Integrity LLC is seeking a Senior Incident Response Analyst to join our Security Operations Center. This hybrid position will involve monitoring, detecting, and responding to cybersecurity threats affecting a large-scale environment, especially within mission...Senior
$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our New... ...data breachDefending privacy lawsuitsDrafting privacy and security policies and procedures pursuant to HIPAA, GLBA, CCPA,...SeniorFull timeWork at officeRemote workFlexible hours- Gunnison Consulting Group is seeking a senior cybersecurity leader to coordinate enterprise incident response activities within the CSIRT. Hybrid work arrangement with 2-3 on-site days per week in Alexandria, VA, with the first month on-site. You will oversee IR operations...Senior2 days per week3 days per week
- A cybersecurity and intelligence firm is seeking a Cyber Eviction Analyst to support critical incident response missions. The role requires extensive expertise in threat actor tools, incident mitigation, and collaborative problem-solving. Ideal candidates will possess...
- ...Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves driving business development initiatives, engaging key stakeholders, and managing strategic partner relationships...SeniorWork at officeRemote work
- ...National Fraud Enforcement Division. The role requires meeting specialized IT qualifications at the GS-15 level and overseeing incident response and system certification reviews. Applicants must demonstrate experience at GS-14 level or equivalent, and be prepared to meet...SeniorWork at office
$100k - $120k
Bering Straits Native Corporation is seeking a Sr. Cybersecurity Incident Response Specialist in Washington, DC. This role involves monitoring cyber threats and ensuring the security of networks and systems. The ideal candidate should have a deep understanding of cybersecurity...Senior- Saliense in Alexandria, VA is seeking a senior cybersecurity leader with 10+ years of experience in incident response, security operations, and penetration testing to guide a high-impact security program. You will lead a team, develop strategic security initiatives, and...Senior
$100k - $125k
...cybersecurity solutions provider is seeking an Incident Response Expert III in Arlington, VA. This role... ...the field, with expertise in network security and a proven ability to communicate... ...to work on critical national security missions. #J-18808-Ljbffr Argo Cyber SystemsSenior- Wilson Elser is seeking a Cyber Incident Response Associate Attorney in Washington, D.C. to handle incident response for cybersecurity and data privacy matters, with responsibilities spanning regulatory analysis, breach notification, and crisis communications. The role...
- ...Attorney Search in Washington, DC seeks an Incident Response Associate with 4-6 years of experience... ...within a top-tier privacy and cyber practice. The ideal candidate will coordinate... ...with law enforcement and regulators, and counsel clients on privacy programs and data...
$86.8k - $198k
Incident Response Analyst, SeniorThe Opportunity:Respond to cybersecurity incidents and proactively prevent the reoccurrence of these incidents. Apply specific functional knowledge to resolve cybersecurity incidents. Analyze or contribute to solutions to a variety of problems...SeniorFull timeContract workPart timeWork at officeLocal areaRemote work$130k - $152.5k
...Senior Associate/Cybersecurity & Incident Response (Forensic Services Practice) Boston, MA, United... ...them and their counsel in independently responding... ...limited to): Executing security and privacy investigations... ...clients on the adequacy of cyber security controls in...SeniorWork at officeLocal areaWork from home3 days per week$80.2k - $111.3k
...Creates cyber-intelligence tools / methods and performs research... ...eliminate high level data and cyber security risks. Designs, tests and... ...and information security incidents to determine extent of compromise... ...assessment programs. Responsible for the formal Security Test...SeniorContract workWork at office$140k - $170k
...Principal/Cybersecurity & Incident Response (Forensic Services... ...assisting them and their counsel in independently... ...leader in the forensic & cyber investigations space,... ...limited to): Leading security and privacy... ...coaching from an assigned senior colleague. Additional...Work at officeLocal areaRemote workWork from home3 days per week$120k - $135k
...Senior Incident Response Analyst Tetrad Digital Integrity (TDI) is a cybersecurity firm built for... ...Our single focus has been delivering cyber solutions to effectively manage risk &... ...critical government program. As part of the Security Operations Center, you will help...SeniorPermanent employmentContract workRemote work2 days per week$155k - $200k
...valued and empowered, then we invite you to apply to our Senior Cyber Incident Response Attorney position. While the position is based in our... ...breach Defending privacy lawsuits Drafting privacy and security policies and procedures pursuant to HIPAA, GLBA, CCPA,...SeniorFull timeWork at officeRemote workFlexible hours- ...Washington, DC is seeking a Digital Forensics and Incident Analyst to support the Threat Analysis &... ...digital evidence and investigates computer security incidents to mitigate vulnerabilities in enterprise systems. Responsibilities span analyzing logs, collecting artifacts,...Senior
- Nightwing Group seeks a Cyber Host Forensic Analyst IV to join ourStrike team in Arlington... ..., VA. The role requires serving as an incident response SME, leading high-priority... ...forensic analysis, and proactive defense to secure critical infrastructure. A TS/SCI clearance...Senior
$131.3k - $237.35k
Leidos Inc is seeking a Senior Incident Response Analyst to join their team in Arlington, Virginia. The role involves coordinating incident response efforts, analyzing cyber threats, and developing security protocols for the Department of Homeland Security's CISA Program...Senior- Leidos is seeking a Security Operations Center Lead for the DISA GSM-O program in Alexandria, VA. The role... ...day-to-day SOC activities, coordinates 24x7 incident handling, and ensures strict adherence to incident response processes. Qualified candidates will have TS/SCI...Senior
- Leidos is seeking a Security Operations Center (SOC) Lead in Alexandria, VA, to direct day-to-day SOC activities and manage 24x7 incident response operations for the DISA GSM-O program. The role requires a TS/SCI clearance, a strong background in cybersecurity, and hands...Senior
- Base One Technologies is seeking a seasoned Cyber Threat Hunter to serve as the hunt and incident response SME in a high-security environment. You will apply in-depth knowledge of threat actor tools and TTPs, distill findings into executive summaries and deep technical...Senior
- cFocus Software seeks an Incident Response Analyst (Tier 2) to join our program supporting the AOUSC. This role is Hybrid with onsite in Washington... ...clearance. You will perform in-depth IR activities, analyze security incidents, and coordinate with federal teams. Candidates...Senior
- Saliense Consulting LLC is seeking a veteran security professional to lead incident response and security operations. The role requires 10+ years of hands-on experience across IR, threat intelligence, and forensics, with 5+ years directing teams and coordinating with leadership...Senior
- Nightwing Group seeks a Cyber Network Forensic Analyst III to support a U.S. Government client in Arlington, VA. You will lead on-site incident response, coordinate with government teams, and determine containment and remediation steps for breaches. The role requires U...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Counsel, Cyber Security and Incident Response. Be the first to apply!
- senior network engineer remote Washington DC
- senior app developer Washington DC
- senior manager legal Washington DC
- senior retail sales associate Washington DC
- sr project manager Washington DC
- senior account executive Washington DC
- senior manager strategic initiatives Washington DC
- senior staff systems engineer Washington DC
- senior commercial counsel Washington DC
- senior data manager Washington DC

