Aderant

Manager, Information Security

Aderant$120K — $145K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in information security, with 3+ years in security operations or incident response.
  • 2+ years of experience managing a security team.
  • Hands-on experience securing AWS and Azure cloud environments.
  • Practical experience in cloud security posture management and remediation.
  • Experience with SIEM, EDR, and CSPM tools, preferably CrowdStrike.
  • Knowledge of attack techniques and MITRE ATT&CK framework.
  • Strong communication skills, including technical status reporting to non-technical stakeholders.

Responsibilities

  • Lead daily security operations, monitoring, and threat detection across various platforms.
  • Own the incident response program, coordinating investigations and remediation across functions.
  • Continuously improve incident response plans and conduct tabletop exercises.
  • Establish and track key operational metrics for security performance reporting.
  • Oversee vulnerability management operations, prioritizing risk and coordinating remediation efforts.
  • Serve as an on-call leader for active security incidents, including after-hours responsibilities.
  • Manage cloud security operations for AWS and Azure, including threat response and posture management.

Benefits

  • Comprehensive health, dental, and vision insurance plans.
  • Generous paid time off and flexible work schedules.
  • Professional development opportunities and certifications support.
  • Retirement savings plan with company match.
  • Collaborative and dynamic work environment with a focus on innovation.
Full Job Description
Position Summary

Aderant is the leading global provider of business management software for law firms, and the Information Security team protects the systems, data, and client trust that underpin that mission. The Manager, Information Security leads Aderant's security operations and incident response function, directing a team of analysts and engineers responsible for detecting, investigating, and responding to threats across the company's global environment.

Reporting to the Director, Head of Information Security, this role translates security strategy into day-to-day operational execution - owning the security operations function, incident response program, and threat detection capabilities, while building and developing a high-performing team.
Key Responsibilities

Security Operations & Incident Response
  • Lead day-to-day security operations, including monitoring, threat detection, and alert triage across the SIEM, EDR, cloud-native security services, and related security tooling.
  • Own the incident response program: lead investigation and response for security incidents, coordinate cross-functional response (IT, Legal, Privacy, Communications), and drive post-incident root-cause analysis and remediation.
  • Maintain and continuously improve incident response plans, playbooks, and tabletop exercises, cloud- and identity-specific response scenarios.
  • Establish and track key operational metrics (mean time to detect/respond, alert volumes, false-positive rates) and report on security operations performance to the Director.
  • Oversee vulnerability management operations across cloud infrastructure, endpoints, containers, and applications, including risk-based prioritization and coordination of remediation with Engineering and IT.
  • Serve as an escalation point and on-call leader during active security incidents, including after hours as required.

Cloud Security (AWS & Azure)
  • Own day-to-day cloud security operations across Aderant's production AWS and Azure environments, including detection, triage, and response to cloud control-plane and workload threats.
  • Manage cloud security posture management (CSPM) operations: monitor for misconfiguration and drift, prioritize findings by real-world risk, and drive remediation with Cloud Engineering and IT.
  • Establish and maintain cloud security guardrails and baselines - logging and telemetry coverage, network segmentation, encryption, secrets handling, and secure-by-default configuration standards.
  • Lead identity and access security operations in the cloud and across the enterprise: privileged access, role and permission hygiene, conditional access, MFA enforcement, and detection of identity-based attack techniques such as token theft, session hijacking, and consent abuse.
  • Ensure comprehensive security telemetry from both cloud platforms is ingested, normalized, and covered by detections in the SIEM.
  • Partner with Cloud Engineering on the security of container and orchestration platforms, infrastructure-as-code pipelines, and the edge/WAF layer protecting customer-facing services.
  • Support cloud security architecture reviews for new services, regions, and platform changes, and translate the outcomes into operational monitoring requirements.

Application & Product Security
  • Partner with Engineering and Product to embed security detection, logging, and response requirements into application and infrastructure changes.

Detection Engineering, Automation & AI Enablement
  • Build and tune detection content mapped to MITRE ATT&CK (including cloud and identity techniques), measuring and closing coverage gaps rather than only responding to vendor-supplied alerts.
  • Drive automation of repeatable detection, enrichment, and response tasks to improve team efficiency and reduce mean time to respond.
  • Apply AI tools - including Claude and Aderant-approved AI assistants - to accelerate investigation, detection development, documentation, and reporting, and establish sound team practices for their use.
  • Contribute to the secure and responsible use of AI across Aderant, including deployment and management of our AIDR solution and monitoring for AI-related risks such as data leakage and shadow AI usage.
  • Evaluate and recommend security operations tooling (SIEM, SOAR, EDR, CSPM, threat intelligence) to improve detection and response capability.
  • Stay current on the threat landscape relevant to legal technology, SaaS, and cloud environments, and translate intelligence into detection use cases.

Team Leadership
  • Manage, mentor, and develop a team of security analysts and engineers, including hiring, performance management, and career development.
  • Establish on-call rotations, staffing coverage, and workload distribution to ensure 24/7 operational readiness.
  • Build a culture of accountability, continuous learning, and operational rigor within the team.

Cross-Functional Collaboration
  • Partner with IT, Engineering, and Product teams to embed security detection and response requirements into infrastructure and application changes.
  • Support the Director, Head of Information Security in preparing security posture updates for executive leadership and, where applicable, customer and audit inquiries.
  • Coordinate with Legal and Compliance on regulatory or contractual incident notification obligations.
Required Qualifications
  • 5+ years of experience in information security, with at least 3 years in security operations, incident response, or threat detection.
  • 2+ years of experience directly managing or leading a security team, including hiring and performance management.
  • Hands-on experience securing and monitoring public cloud environments - substantive depth in both AWS and Azure (or deep expertise in one with demonstrated working knowledge of the other), including cloud logging and telemetry, IAM, and cloud-native security services.
  • Practical experience with cloud security posture management and remediating misconfiguration at scale in a production environment.
  • Hands-on experience with SIEM platforms EDR, and CSPM tools (CrowdStrike preferred)
  • Experience managing the incident response processes in a production environment.
  • Working knowledge of common attack techniques, threat actor behavior, and the MITRE ATT&CK framework, including cloud and identity techniques..
  • Experience developing or maturing incident response plans, playbooks, and post-incident reviews.
  • Demonstrated use of AI tools (such as Claude or comparable assistants) to improve security operations quality and efficiency, with sound judgment about where they are and are not appropriate.
  • Strong written and verbal communication skills, including experience communicating incident status to non-technical stakeholders and leadership.
  • Proficiency securing Cloud environments (AWS and Azure).
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
Preferred Qualifications
  • Experience in a SaaS, legal technology, or software company handling sensitive or regulated client data.
  • Relevant certifications such as CISSP, GCIH, GCIA, CISM, or equivalent.
  • Cloud security certifications such as AWS Certified Security - Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), GCSA, or GCLD.
  • Experience with a unified endpoint and cloud security platform such as CrowdStrike Falcon (Aderant's preferred platform), or comparable EDR/CNAPP tooling.
  • Experience with edge security and web application firewall platforms such as Cloudflare.
  • Familiarity with cloud-native security services (AWS GuardDuty, Security Hub, CloudTrail; Microsoft Defender for Cloud, Entra ID Protection, Azure Monitor/Sentinel).
  • Experience securing containers and orchestration platforms (Docker, Kubernetes, EKS/AKS) and infrastructure-as-code (Terraform) pipelines.
  • Experience with SOAR platforms and security automation/orchestration.
  • Experience managing a co-managed SOC or MSSP relationship.
  • Familiarity with SOC 2, ISO 27001, or similar compliance frameworks and how operational security supports audit readiness.
  • Experience operating in a global, multi-region environment.

About Aderant

Aderant is a global provider of comprehensive business management software for law firms and professional services organizations. The company offers a suite of solutions that includes time and billing, financial management, practice management, business intelligence, and CRM. Aderant serves more than 3,200 clients in over 30 countries.
Learn more about Aderant
Size
1,100 employees
Industry
Net Income
$10 million
Founded
1978
5 Year Trend
+5%
Revenue
$100 million
NASDAQ

Similar Jobs

More Jobs at Aderant

More Information Technology Jobs

Find similar Manager, Information Security jobs: