Principal Counsel, Cybersecurity Legal

Netflix Netflix · Big Tech · Los Gatos, CA +2 · Legal

Netflix is seeking a Principal Counsel, Cybersecurity Legal to provide strategic legal counsel on cybersecurity issues impacting the company's business and products globally. The role involves advising on laws and regulations, supporting information security programs, assisting during investigations and incident response, guiding audits, and drafting agreements. Requires significant experience in cybersecurity legal practice, a deep understanding of global laws, frameworks, and emerging cyber laws, and experience with security by design, incident response, and managing legal responses to cyber incidents.

What you'd actually do

  1. Monitoring, assessing and advising on cyber security laws and regulations and their impact in collaboration with our government affairs and legal compliance teams,
  2. Provide legal counseling in support of our information security programs, including risk assessments, vulnerability management, threat modeling, bug bounty program, etc.
  3. Providing support and counsel during cybersecurity-related investigations and the response to cybersecurity and data privacy incidents, including breach notification and mitigation strategies,
  4. Providing legal guidance on regulatory, third-party, and internal security audits, and working with teams to scope and perform periodic security hygiene assessments, mitigation and remediation,
  5. Drafting and negotiating data protection and cybersecurity agreements

Skills

Required

  • cybersecurity legal practice
  • global cybersecurity laws
  • JD or equivalent
  • US state bar admission
  • cyber frameworks and standards
  • global regulatory landscapes
  • emerging national security cyber laws
  • security by design principles
  • incident response management
  • legal response to cyber incidents
  • collaboration with diverse business units
  • legal judgment under pressure
  • leading and providing direction
  • partnering at all levels

What the JD emphasized

  • Significant experience in cybersecurity legal practice
  • deep knowledge of global cybersecurity laws
  • JD or equivalent and admission to at least one US state bar
  • Deep understanding of applicable cyber frameworks and standards, global regulatory landscapes, and emerging national security cyber laws
  • Experience advising on security by design principles, incident response management, and developing strategies to implement requirements from new laws and regulations
  • Experience managing legal response to cyber incidents, including coordination across the enterprise with interdisciplinary teams
  • Proven track record of working collaboratively with diverse business units and across regional legal teams, translating complex legal concepts into simple and actionable items for the business
  • A proactive, pragmatic and positive mindset toward emerging challenges and a proven ability to exercise sound business and risk-based legal judgment under pressure within tight timeframes
  • Ability to lead, take action, and provide direction in the face of ambiguity
  • Ability to partner at all levels of the organization