Of 250 interviews, 71 involved lawyers who had moved from government-contracts or privacy seats into cybersecurity-vendor counsel roles in the previous three years, our Northern Virginia research shows. In 12 closed in-house searches in Northern Virginia over 24 months, our mandate telemetry shows 9 offers went to lawyers already counseling CMMC or FedRAMP at a cyber vendor or federal contractor. Nine of 12 recent offers went to lawyers already sitting in CMMC or FedRAMP seats. A chief legal officer at a Falls Church prime contractor said the cybersecurity counsel seat needed someone who had already lived through a CMMC Level 2 flow-down, not a campus privacy docket.
Day to day, this in-house seat drafts and negotiates FAR/DFARS and commercial SaaS, reseller, and MSP-MSSP paper; advises on CMMC, FedRAMP, NIST, CUI, Section 889, TAA, and supply-chain risk; and sits with the CISO, FSO, product, and capture on incident response and SPRS affirmations. Adjacent feeders are government-contracts counsel, privacy and data-protection counsel, IP and technology-transactions lawyers, and cleared federal-procurement counsel — not data-center real-estate lawyers. Vendor cyber dockets do not travel from a campus privacy file.
Sartori's Northern Virginia mandate telemetry records counter-offer incidence of 26% on this in-house cybersecurity-counsel line. We have closed 15 such searches over three years. Secret-clearable government-contracts counsel still crowd shortlists; true vendor-cyber lawyers do not.