Director, Legal (Cybersecurity)

Nscale•San Francisco, NY
•Remote

About The Position

Nscale is seeking a U.S.-based Director, Legal (Cybersecurity) to serve as the lead cybersecurity counsel for the company as it scales into a publicly listed global AI infrastructure company. This role reports to the General Counsel and SVP, Commercial Partnerships and will be the primary legal partner to the CISO and Security organization. The position involves close collaboration with AI infrastructure, data center operations, engineering, commercial legal, procurement, privacy, finance, and the executive team. This role is crucial for building trust with customers, regulators, and investors. The Director will own the legal strategy for incident response and cyber disclosure, and will help embed security-by-design across Nscale's cloud and data center footprint. They will also help shape how Nscale meets the security expectations of hyperscalers, AI labs, enterprises, regulated industries, and the public sector. The ideal candidate is a pragmatic, commercially minded leader who can operate effectively in both high-pressure situations and strategic discussions.

Requirements

  • U.S.-qualified attorney with 10+ years of experience.
  • Significant in-house experience as cybersecurity or security counsel, preferably at a hyperscaler, cloud provider, AI lab, or high-growth tech company.
  • Exceptional private practice candidates will also be considered.
  • Proven track record leading legal response to significant security incidents, including privileged investigations, notifications, and regulator engagement.
  • Working knowledge of SEC cybersecurity disclosure requirements and public company governance.
  • Strong familiarity with U.S. federal and state cyber and data security laws, and with international regimes such as NIS2, DORA, and UK and EU GDPR security obligations.
  • Ability to understand technical controls and translate risk into clear business decisions.
  • Ability to act as an independent legal voice while remaining an embedded partner to Security.
  • Calm, sound judgment under pressure, with a high degree of discretion.
  • Excellent communicator who can influence at all levels, including executives and the Board.
  • Comfortable operating with ambiguity in a fast-paced, high-growth environment.

Nice To Haves

  • Experience with critical infrastructure, data centers, or public sector security (FedRAMP, CMMC, DFARS).
  • Professional certifications such as CIPP/US, CISSP, or equivalent.
  • Pre- or post-IPO company experience.
  • Familiarity with AI and model security issues.
  • Litigation or investigations experience.

Responsibilities

  • Serve as the CISO's closest legal partner, advising the Security team on security programs, policies, controls, and risk decisions.
  • Lead and manage external counsel as a hands-on, player-coach leader.
  • Build and lead Nscale's cybersecurity legal and regulatory compliance program across the U.S., and support execution in the UK, EU, and other regions.
  • Advise on the legal side of security frameworks and certifications, including SOC 2, ISO 27001, NIST CSF, FedRAMP, and CMMC.
  • Support Board, Audit Committee, and executive reporting on cyber risk and governance.
  • Lead legal strategy for security incidents and investigations, including directing privileged investigations, engaging forensic firms and outside counsel, and coordinating with law enforcement.
  • Own breach notification analysis and execution across U.S. state, federal, and international regimes, and customer contractual obligations.
  • Partner with Finance, Securities counsel, and Investor Relations on SEC cybersecurity disclosure obligations, covering materiality assessments, Form 8-K reporting, and annual 10-K governance disclosures.
  • Design and run incident response playbooks and executive tabletop exercises, and maintain a response posture ready for ransomware and extortion events.
  • Monitor and advise on the evolving cyber regulatory landscape, including CIRCIA, SEC rules, FTC and state enforcement, NIS2, DORA, and UK cyber resilience legislation.
  • Advise on security obligations tied to critical infrastructure, data centers, and public sector and regulated-industry customers.
  • Manage regulatory enquiries and engagement with cyber and data regulators.
  • Partner with commercial legal and procurement on security terms in customer and supplier contracts, including security addenda, audit rights, incident notification, liability, and SLAs.
  • Lead security due diligence and contractual controls across the supply chain, including hardware, software, and colocation partners.
  • Advise on cyber insurance coverage, claims, and renewals.
  • Support M&A, investor diligence, and strategic partnerships as the cybersecurity subject matter expert.
  • Advise on vulnerability disclosure, bug bounty, threat intelligence sharing, and security research programs.
  • Partner with the Privacy & AI team on data protection, AI security, and model and data security issues.
  • Build security-legal awareness across the business, and scale guidance through playbooks and training.

Benefits

  • medical
  • dental
  • vision
  • flexible paid time off
  • parental leave
  • retirement plan participation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service