Sr. Cybersecurity Corporate Counsel
Job Description
Synopsys is seeking a Sr. Cybersecurity Corporate Counsel based in Sunnyvale, CA (onsite). The role acts as a primary legal advisor for cybersecurity incidents and provides legal guidance across cybersecurity, privacy, data protection, and related regulatory and contractual obligations.
Role Overview
As the lead counsel for cybersecurity matters, you will support incident response and forensic-response activities, interpret and advise on applicable U.S. and international cybersecurity and breach-notification requirements, and help translate the company’s security capabilities and risk posture into clear contractual language. You will also contribute to cybersecurity governance and compliance initiatives while providing practical day-to-day counsel for enterprise IT operations and related technology risks.
Key Responsibilities
- Serve as a primary legal advisor during actual or suspected cybersecurity incidents, coordinating with Information Security, Privacy, Compliance, Communications, HR, and relevant business teams.
- Evaluate legal, regulatory, contractual, and business obligations triggered by incidents, including notification obligations to customers, regulators, business partners, senior management, and the Board as appropriate.
- Advise on investigation and forensic-response processes, including preservation of privilege, engagement of external counsel and forensic vendors, documentation of key decisions, and support for post-incident remediation.
- Provide guidance on U.S. and international cybersecurity laws, breach-notification requirements, regulatory inquiries, and related compliance obligations affecting company systems, data, products, customers, partners, and vendors.
- Draft, review, and negotiate cybersecurity, information security, privacy, and data-protection provisions in customer, partner, and vendor agreements.
- Negotiate provisions covering security controls, encryption, data handling, incident reporting and response times, audit rights, security standards, vulnerability management, responsibility allocation, and third-party risk.
- Partner with technical and compliance subject-matter experts to develop contract language and negotiation strategies aligned to security capabilities and risk positions.
- Support cybersecurity governance and compliance initiatives.
- Provide practical day-to-day counseling regarding cybersecurity, data protection and governance, enterprise IT operations, and related technology risks.
- Collaborate across Legal, Information Security, Privacy, Compliance, Engineering, Product Management, Commercial, Procurement, and other functions to progress business objectives while managing risk thoughtfully.
Required Qualifications
- J.D. from an accredited law school and active membership in at least one U.S. state bar.
- 8 to 10 years of legal experience, with cybersecurity matters representing a substantial part of the practice.
- Significant experience advising on cybersecurity incident response, forensic investigations, breach-notification analysis, customer notifications, and regulatory reporting.
- Demonstrated experience drafting and negotiating cybersecurity, information security, privacy, and data-protection provisions in customer and vendor agreements.
- Working knowledge of cybersecurity principles, information security practices, cloud environments, data governance, and commonly used security frameworks and standards.
- Ability to independently manage complex, time-sensitive legal matters involving multiple technical, legal, and business stakeholders.
- Excellent written and verbal communication skills, including the ability to explain complex legal and technical issues to legal and non-legal audiences.
- Ability to interpret and address U.S. and international cybersecurity, data-protection, and incident-response requirements.
- Experience advising a global technology company, whether in-house or in private practice, is strongly preferred.
Preferred and Additional Skills
- Experience in semiconductor, software, SaaS, cloud, AI, or other technology businesses is a plus.
- Ability to work closely with cybersecurity engineers, forensic investigators, business leaders, and communications professionals while keeping legal strategy focused and actionable.
- Demonstrated ability to remain calm and exercise sound judgment when an incident is moving quickly and facts are incomplete.
- Ability to ask precise questions, identify legally significant facts, and document decisions without slowing response efforts.
- Ability to write clearly and efficiently for incident-response analysis, security addendum negotiations, and explanations of obligations to senior leadership.
- Ability to determine when to escalate and when to engage outside experts, using a practical risk-management approach.
- Ability to evaluate and negotiate proposed contractual commitments related to cybersecurity, data protection, and incident notification requirements.
Relevant Technologies
- Cloud environments
- SaaS
- AI
Compensation and Location
- Location: Sunnyvale, CA (onsite)
- Salary: USD 220,000 - 330,000 per year
Benefits
- Comprehensive range of health, wellness, and financial benefits
- Total rewards include both monetary and non-monetary offerings
- In addition to base salary, eligibility for an annual bonus, equity, and other discretionary bonuses
Export Control Eligibility (Additional Requirements)
- This position requires access to or use of information subject to export restrictions, including the International Traffic in Arms Regulations (ITAR).
- All applicants must be “U.S. Persons” as defined by ITAR.
- “U.S. Persons” include U.S. Citizens, U.S. Lawful Permanent Residents (Green Card Holders), Political Asylees, Refugees, or other protected individuals defined by 8 U.S.C. 1324b(a)(3).