Job DescriptionThe Director of Information Security leads the development, operation, and continuous improvement of the firm's information security, cybersecurity, privacy, compliance, and technology risk programs. This role safeguards firm and client information by defining security strategy, governance, architecture, controls, and operational capabilities across cloud services, identity, applications, endpoints, networks, email, data, artificial intelligence ("AI"), and third-party services.
Working closely with administrative departments, attorneys, clients, and external providers, the Director enables responsible technology adoption while maintaining acceptable risk levels. The role oversees security policy and standards, ISO certification, regulatory compliance, AI and emerging-technology risk, vendor security, security operations, incident response, identity and access management, data protection, security awareness, client audits, business continuity, and security program performance.
Strategy, Governance, and Risk
- Develop and execute the firm's information security strategy, governance framework, policies, standards, and annual security roadmap to protect firm, client, and employee information.
- Lead enterprise cybersecurity, privacy, risk management, and compliance programs in alignment with applicable laws, regulations, client requirements, and frameworks such as ISO/IEC 27001, ISO/IEC 27002, ISO 22301, and NIST.
- Establish security requirements and governance for cloud services, AI, generative AI, machine learning, autonomous agents, and other emerging technologies, balancing innovation with the protection of confidential and proprietary information.
- Direct enterprise risk assessments, security architecture reviews, and control evaluations to identify, prioritize, and remediate cybersecurity, technology, vendor, and operational risks.
Security Operations and Technology
- Oversee security operations, including threat monitoring and detection, vulnerability management, incident response, forensic investigations, and security engineering.
- Provide governance and oversight for identity and access management, data protection, network security, endpoint security, application security, cloud security, and third-party technology integrations.
- Support the development and oversight of the firm's business continuity, disaster recovery, and physical security programs.
Advisory, Client, and Vendor Responsibilities
- Serve as the firm's primary security advisor to leadership, business stakeholders, clients, auditors, and vendors on cybersecurity, privacy, regulatory, and technology risk matters.
- Lead client security audits, security questionnaires, Outside Counsel Guidelines reviews, Requests for Proposal, and other client-driven security assessments.
- Direct vendor security reviews and due diligence for managed security services, cloud providers, software platforms, and AI-enabled solutions.
- Partner with Technology Services, Innovation, administrative departments, and business leaders to integrate security into enterprise projects, system development, operational processes, and technology-enabled initiatives.
Leadership and Program Management
- Promote a culture of security awareness through training, communication, policy enforcement, and ongoing education for attorneys, staff, and technology personnel.
- Define and report cybersecurity metrics, program maturity, emerging risks, and strategic initiatives to executive leadership.
- Manage security budgets, contracts, projects, and strategic investments.
Minimum QualificationsEducation and Certifications- Bachelor's degree in a related field, specialized training, or equivalent professional experience.
- Relevant industry certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or a comparable credential.
Experience- Eight or more years of progressively responsible experience in cybersecurity, information security, technology risk, privacy, compliance, security architecture, or related discipline, including at least three years in a leadership role.
- Demonstrated success leading a multidisciplinary security program in a legal, professional services, financial services, healthcare, or similarly sensitive and regulated environment; law firm or professional services experience is strongly preferred.
- Experience developing and operating enterprise security capabilities across Microsoft 365, Azure, Entra ID, cloud applications, email, endpoints, networks, data, APIs, and third-party services, using platforms such as ReliaQuest, Proofpoint, Abnormal Security, Netskope, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Microsoft Intune.
- Experience evaluating the security, privacy, compliance, and operational impact of AI and AI-enabled applications.
- Experience governing OAuth applications, Microsoft Graph permissions, enterprise application registrations, privileged and workload identities, certificates, service accounts, secrets, and role-based access controls.
- Experience leading incident response, vendor assessments, remediation efforts, client and ISO audits, security awareness initiatives, and executive risk reporting.
- Experience applying ISO/IEC 27001, ISO/IEC 27002, the NIST Cybersecurity Framework, the NIST AI Risk Management Framework, CIS Controls, and Zero Trust principles.
- Experience managing security teams and providers, budgets, contracts, implementation projects, and service levels.
Because cybersecurity risks and technologies continue to evolve, the responsibilities and qualifications for this role may change over time based on the firm's needs and the complexity of its information security environment.
This is an exempt position and can be based in our NY, DC, or Chicago office. The anticipated good-faith base salary range for this position is:
- DC/CHI: $231,000 to $318,000 per year.
- NYC: $270,000 to $371,000 per year
Your exact offer will be based on a variety of factors, including but not limited to, your experience, skills, and overall qualifications. We also review compensation regularly against industry benchmarks and performance outcomes, so you can grow your career here with confidence-knowing your pay recognizes both your impact and our commitment to an equitable approach.
In addition to a competitive base salary, certain positions are eligible for a comprehensive performance-based bonus, payable monthly or annually.
BenefitsWe know that the needs of our employees vary and can change throughout the different stages of life. That's why we offer a wide array of flexible benefit options designed to help you live healthy, live well, and live for tomorrow. In addition to medical, dental, vision, profit-sharing, generous paid time off, and numerous other benefits, we also provide a flexible reimbursement account that helps pay for the things that contribute to your personal well-being, in your own way.