The opportunity
Waymo is an autonomous driving technology company with the mission to be the world's most trusted driver. Since its start as the Google Self-Driving Car Project in 2009, Waymo has focused on building the Waymo Driver—The World's Most Experienced Driver™—to improve access to…
What you'll do
Develop risk-based approaches to cybersecurity compliance that balance legal: risk mitigation and regulatory requirements with business objectives.
Partner effectively with Security, Engineering, Safety, and Product teams on: vulnerability management, threat analyses, and cybersecurity risk assessments.
Spearhead the evolution of Waymo’s cybersecurity incident response and: reporting program in connection with the domestic and international expansion of its autonomous vehicle operations.
Drive efforts to manage cybersecurity risk effectively within the company’s: supplier and partner ecosystem and promote supply chain security.
Support internal and external audits, assessments, and regulatory inquiries: related to cybersecurity compliance.
Monitor emerging cybersecurity laws, regulations, executive orders, and: agency guidance, and lead business-focused compliance efforts.
What they're looking for
- Law degree (LLB, LLM, or JD), plus at least 5 years of experience counseling: on cybersecurity matters with a law firm, government agency, or in-house legal department.
- Excellent written and oral communication skills with ability to explain: complex legal and cybersecurity issues cogently to technical and non-technical audiences, including executives.
- Experience advising clients on cybersecurity compliance and incident response: programs (e.g., ransomware events, supply chain compromises, and insider threats), including incident containment, forensic investigations, and reporting programs for complying with federal, state, and international laws and regulations.
- Experience with supply chain cybersecurity risk management, including: advising on third-party security risk assessments, preparation of SBOMs and HBOMs, and supply chain cybersecurity.