Nscale

Director, Legal (Cybersecurity)

New York, New York · Posted today

Opens job-boards.eu.greenhouse.io

Get a version of your resume written for this job.

Salary
Not listed
Job type
Not specified
Work mode
Not specified
Source
Greenhouse (employer's hiring system)

Skills mentioned

Cybersecurity, Incident Response, Procurement, SOC 2, ISO 27001, Supply Chain

About the role

.

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.

About the Role

We're looking for a U.S.-based Director, Legal (Cybersecurity) to serve as Nscale's lead cybersecurity counsel as we scale into a publicly listed global AI infrastructure company. Reporting to the General Counsel and SVP, Commercial Partnerships, you'll be the primary legal partner to our CISO and Security organization. You'll also work closely with AI infrastructure, data center operations, engineering, commercial legal, procurement, privacy, finance, and the executive team.

This role is critical to building trust with customers, regulators, and investors. You'll own the legal strategy for incident response and cyber disclosure and help embed security-by-design across our cloud and data center footprint. You'll help shape how Nscale meets the security expectations of hyperscalers, AI labs, enterprises, regulated industries, and the public sector.

You'll be a pragmatic, commercially minded leader who can move from the war room to the boardroom with equal credibility.

What You'll Be Doing

Cybersecurity legal leadership and governance

  • Serve as the CISO's closest legal partner, advising the Security team on security programs, policies, controls, and risk decisions.
  • Lead and manage external counsel as a hands-on, player-coach leader.
  • Build and lead Nscale's cybersecurity legal and regulatory compliance program across the U.S., and support execution in the UK, EU, and other regions.
  • Advise on the legal side of security frameworks and certifications, including SOC 2, ISO 27001, NIST CSF, FedRAMP, and CMMC.
  • Support Board, Audit Committee, and executive reporting on cyber risk and governance.

Incident response and cyber disclosure

  • Lead legal strategy for security incidents and investigations, including directing privileged investigations, engaging forensic firms and outside counsel, and coordinating with law enforcement.
  • Own breach notification analysis and execution across U.S. state, federal, and international regimes, and customer contractual obligations.
  • Partner with Finance, Securities counsel, and Investor Relations on SEC cybersecurity disclosure obligations, covering materiality assessments, Form 8-K reporting, and annual 10-K governance disclosures.
  • Design and run incident response playbooks and executive tabletop exercises, and maintain a response posture ready for ransomware and extortion events.

Regulatory and critical infrastructure

  • Monitor and advise on the evolving cyber regulatory landscape, including CIRCIA, SEC rules, FTC and state enforcement, NIS2, DORA, and UK cyber resilience legislation.
  • Advise on security obligations tied to critical infrastructure, data centers, and public sector and regulated-industry customers.
  • Manage regulatory enquiries and engagement with cyber and data regulators.

Commercial and third-party risk

  • Partner with commercial legal and procurement on security terms in customer and supplier contracts, including security addenda, audit rights, incident notification, liability, and SLAs.
  • Lead security due diligence and contractual controls across the supply chain, including hardware, software, and colocation partners.
  • Advise on cyber insurance coverage, claims, and renewals.
  • Support M&A, investor diligence, and strategic partnerships as the cybersecurity subject matter expert.

Cross-functional advisory

  • Advise on vulnerability disclosure, bug bounty, threat intelligence sharing, and security research programs.
  • Partner with the Privacy & AI team on data protection, AI security, and model and data security issues.
  • Build security-legal awareness across the business, and scale guidance through playbooks and training.

KPIs

  • A mature, audit-ready cybersecurity legal and compliance program
  • Timely, defensible incident response, notification, and SEC disclosure decisions
  • Effective security risk allocation in customer and supplier contracts
  • Board and executive confidence in cyber governance and reporting

About You

  • U.S.-qualified attorney with 10+ years of experience, including significant in-house experience as cybersecurity or security counsel, preferably at a hyperscaler, cloud provider, AI lab, or high-growth tech company. Exceptional private practice candidates will also be considered.
  • Proven track record leading legal response to significant security incidents, including privileged investigations, notifications, and regulator engagement.
  • Working knowledge of SEC cybersecurity disclosure requirements and public company governance.
  • Strong familiarity with U.S. federal and state cyber and data security laws, and with international regimes such as NIS2, DORA, and UK and EU GDPR security obligations.
  • A trusted partner to CISOs and security engineers, able to understand technical controls and translate risk into clear business decisions.
  • Able to act as an independent legal voice while remaining an embedded partner to Security.
  • Litigation or investigations experience is a strong plus.
  • Calm, sound judgment under pressure, with a high degree of discretion.
  • Excellent communicator who can influence at all levels, including executives and the Board.
  • Comfortable operating with ambiguity in a fast-paced, high-growth environment.

Nice to have

  • Experience with critical infrastructure, data centers, or public sector security (FedRAMP, CMMC, DFARS)
  • Professional certifications such as CIPP/US, CISSP, or equivalent
  • Pre- or post-IPO company experience
  • Familiarity with AI and model security issues

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$210,000—$340,000 USD

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Nscale does not accept unsolicited candidate submissions from recruitment agencies.

Job ID gh-nscaleoperationsukltd-4989976101 · Original posting ↗