Cybersecurity Counsel
Booz Allen HamiltonAbout the role
The Opportunity:
Bring your cybersecurity and data protection expertise to a role that helps protect Booz Allen’s people, clients, and mission while enabling innovation at enterprise scale. At Booz Allen, you’ll join a team of experienced professionals motivated to excel and realize values-driven change for our clients, colleagues, and communities. We bring bold thinking to complex challenges across analytics and artificial intelligence, cyber, digital solutions, engineering, and consulting, and with industries ranging from defense and national security to health, energy to international development.
As a member of our Data Privacy, AI, and Cybersecurity legal team, you’ll help propel our forward-thinking and purpose-driven team as we advance our clients’ missions and protect our internal operations. As Cybersecurity Counsel, you will have direct responsibility for legal matters related to Booz Allen’s cybersecurity and data protection program and activities. You will advise Booz Allen and its businesses on all aspects of cybersecurity law, focusing on compliance, policy, incident response, transactions and contracts.
In this role, you will provide day-to-day legal support to the Chief Information Office (CIO) and Enterprise Cybersecurity (ECS) team and advise on processes and controls to ensure compliance with applicable laws, regulations, and contract requirements. You’ll help shape governance, advise during incident response and investigations, and negotiate data security terms that align with evolving laws, regulations, and contractual obligations, especially those relevant to federal contracting environments. This position is located in McLean, VA. Due to the nature of work performed within this facility, U.S. citizenship is required.
Work with us as we empower the future.
What You'll Work On:
Serve as trusted counsel to leaders on compliance strategy, policies or standards, and risk-based decision making across the enterprise.
Advise on incident response and cyber events, including escalation decisions, investigations, notifications or reporting considerations, and post-incident remediation activities.
Guide government-contracting cybersecurity obligations such as FAR DFARS and agency supplements, including flow-down considerations and alignment to recognized frameworks such as NIST, CMMC, FedRAMP, or ISO.
Partner cross-functionally with Security, Privacy, Compliance, Procurement, Risk, and business teams to translate complex requirements into practical, durable controls and playbooks.
Support enterprise initiatives such as audits or assessments, cyber risk mitigation planning, third-party risk, and cyber insurance-related legal matters.
Counsel on contractual cybersecurity requirements and risk allocation, including reviewing, drafting, and negotiating data security and privacy terms with customers, vendors, and partners.
Join us. The world can’t wait.
You Have:
5+ years of experience practicing cybersecurity law in a law firm or corporate environment
Experience with U.S. and global cybersecurity requirements and data protection laws applicable to publicly traded companies that perform work for government and commercial customers
Experience providing legal and strategic advice on cybersecurity and data protection issues, including current and evolving regulatory and contractual obligations, incident response, cybersecurity-related investigations, audits, cyber risk identification and mitigation efforts, and cybersecurity insurance matters
Experience advising on contractual requirements and drafting and negotiating data security terms in contracts with customers, vendors, and business partners
Experience collaborating with cross-functional teams to evaluate risks and root causes and to aid in designing and implementing practical mitigation strategies or action plans
Experience working under pressure, managing multiple complex matters simultaneously, and meeting deadlines in a fast-paced environment
Knowledge of cybersecurity aspects of U.S. government acquisition regulations such as FAR, DFARS, or HSAR and security certifications and frameworks such as CMMC, ISO, FedRAMP, and NIST
Ability to listen actively to ensure that the right questions are being asked and answered, translate legalese or regulations into succinct, clear, and workable business solutio
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s