Associate General Counsel, Cybersecurity

Anduril Anduril · Defense · Costa Mesa, CA · Legal and Business Affairs : Legal : Legal

Anduril Industries is a defense technology company seeking an Associate General Counsel, Cybersecurity to be their primary legal expert on cybersecurity law and compliance. This role will advise on government contract cybersecurity requirements (CMMC, NIST 800-171, DFARS 7012), manage data breach response, support compliance frameworks, and negotiate security terms in contracts. The successful candidate will partner with CISO, IT Security, Engineering, and Compliance teams to build and own the cybersecurity legal program.

What you'd actually do

  1. Serve as Anduril's primary legal expert on cybersecurity law, providing strategic advice to executive leadership, the CISO, and business units on complex cybersecurity legal and regulatory issues
  2. Advise on cybersecurity requirements in government contracts including FAR/DFARS cybersecurity clauses (DFARS 7012, 7019, 7020), CMMC compliance pathways, NIST 800-171 obligations, contractor classified infrastructure regulations (NISPOM, DAAG) and agency-specific security requirements (DoD, DHS, DoE)
  3. Design, implement, and continuously improve Anduril's cybersecurity compliance program, policies, and internal controls in partnership with the CISO and Security team
  4. Lead legal aspects of cybersecurity incident response, including assessment of notification and reporting obligations under federal regulations (e.g., DFARS 252.204-7012, Cyber Incident Reporting for Critical Infrastructure Act) and state breach notification laws
  5. Partner with IT Security, Engineering, and Product teams on cybersecurity requirements for product development, cloud architecture, data handling, and system access controls

Skills

Required

  • Juris Doctor (JD) degree from an accredited law school
  • Admission to at least one state bar
  • 5+ years of experience as a practicing attorney, with a significant focus on cybersecurity law and compliance
  • Deep understanding of government contract cybersecurity requirements (e.g., CMMC, NIST 800-171, DFARS 7012)
  • Experience with data breach response and notification obligations
  • Familiarity with cybersecurity compliance frameworks and regulations
  • Ability to negotiate complex security terms in contracts
  • Excellent written and verbal communication skills
  • Ability to work independently and manage multiple priorities in a fast-paced environment

Nice to have

  • Experience in the defense technology industry
  • Experience building and managing a cybersecurity legal program from the ground up
  • Familiarity with autonomous systems and AI/ML related legal issues

What the JD emphasized

  • government contract cybersecurity requirements
  • CMMC
  • NIST 800-171
  • DFARS 7012
  • data breach response
  • cybersecurity compliance frameworks
  • negotiating security terms
  • cybersecurity law
  • cybersecurity regulations