About the Role
The Enterprise Security Compliance Lead is an integral part of Latham’s Global Security and Risk Management team. This role will be responsible for coordinating activities related to client security audits, vendor security audits, and other security compliance needs including ISO 27001 assessments, penetration test remediations, and other client responses, while leading assigned client security reviews from intake through closure by identifying necessary internal stakeholders based on the request (e.g., security survey, audit, review.), assembling relevant and appropriate documentation, and completing the appropriate forms and questionnaires required by Latham clients. This role will be located in our Global Services Office in downtown Los Angeles. Please note that this role may be eligible for a flexible working schedule that allows for a hybrid and in-office presence.
Responsibilities & Qualifications
Other key responsibilities include:
- Maintaining relationships with third-party audit services that audit firm vendors, conduct audits of the firm on behalf of clients, or otherwise audit or evaluate the firm (e.g., ISO 27001 assessors, independent consultants)
- Acting as a project manager to ensure the success of ISO 27001, client and vendor audits, and other assessments (e.g., identifying internal stakeholders, establishing schedules and coordinating with others to meet deadlines, assembling relevant and appropriate documentation, completing necessary responses, and tracking necessary follow-up)
- Supporting compliance activities related to penetration testing and vulnerability testing, including the identification of critical systems, external testing requirements and frequency, coordination with Security Operations, and follow-up on remediation activities to ensure established processes are followed and required SLAs are met
- Coordinating team activities and reviews work for consistency and quality
- Creating reports and presentations for senior management
- Protecting and maintaining any highly sensitive, confidential, privileged, financial, and/or proprietary information that Latham & Watkins retains
We’d love to hear from you if you:
- Exhibit an understanding of business security practices and procedures
- Possess knowledge of information security technologies
- Demonstrate knowledge of a variety of communication protocols and encryption techniques/tools
And have:
- A bachelor's degree or equivalent; a minimum of five (5) years of Security and Technology experience may be considered in lieu of a degree
- A bachelor’s degree in Information Systems, Computer Science, Engineering or related field, preferably
- Recognized security certifications (e.g., CISA, CRISC, CDPSE, CISSP), preferably
- A minimum of five (5) years of experience in IT audit or IT risk management
- A minimum of three (3) years of experience in performing security assessments, IT vendor risk assessments, and vulnerability management reviews
- A minimum of two (2) years of experience applying project management concepts
Benefits & Additional Information
Successful candidates will not only be provided with an outstanding career opportunity and welcoming environment, but will also be provided with a generous total compensation package with bonuses awarded in recognition of both individual and firm performance. Eligible employees can participate in Latham’s comprehensive benefit program which includes:
- Healthcare, life and disability insurance
- A generous 401k plan
- At least 11 paid holidays per year, and a PTO program that accrues 23 days during the first year of employment and grows with tenure
- Well-being programs (e.g. mental health services, mindfulness and resiliency, medical resources, well-being events, and more)
- Professional development programs
- Employee discounts
- Affinity groups, networks, and coalitions for lawyers and staff
#Associate
#LI-EK1
Pay RangeUSD $160,000.00 - USD $180,000.00 /Yr.