McGuireWoods

Sr. Information Security Engineer

McGuireWoods$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Minimum of 5 years of hands-on information security engineering experience.
  • Bachelor's Degree in IT, Cybersecurity, or equivalent experience preferred.
  • CISSP, GIAC, or CCSP certification strongly preferred.
  • Experience in a law firm or regulated professional services environment is advantageous.
  • Proficiency with EDR, SIEM, firewalls, and identity management tools with scripting knowledge.
  • Ability to manage project priorities and navigate security requirements relative to business risk.
  • Familiarity with AI-enabled tools is a plus.

Responsibilities

  • Serve as the technical lead for security platform implementations across multiple environments.
  • Manage daily operations and optimization of various security controls.
  • Lead integration efforts for SaaS configurations and security log management.
  • Conduct vulnerability assessments and threat modeling per the MITRE ATT&CK framework.
  • Provide technical support during security incidents and data analysis.
  • Develop automation scripts and detection logic for incident response.
  • Collaborate with infrastructure teams on secure backup and recovery solutions.

Benefits

  • Opportunity to work in a prestigious law firm environment.
  • Exposure to advanced security technologies and integration efforts.
  • Collaborative team atmosphere promoting technological innovation.
  • Professional development opportunities and certifications support.
  • Access to cutting-edge AI tools and methodologies.
Full Job Description
Overview

McGuireWoods is hiring a Senior Information Security Engineer. This is a hands-on technical lead position responsible for designing, implementing, and maintaining security technologies that protect the confidentiality, integrity, and availability of firm, client, and personal data. This role provides technical leadership across security platforms, architecture, automation, and SaaS integrations. The person in this position must be a self-starter who can drive projects independently, collaborate across teams, and effectively communicate technical decisions to all levels of firm personnel.

Responsibilities

  • Serve as technical lead for security platform implementations across endpoint, network, cloud, SaaS, and identity platforms.
  • Administer day-to-day operations and optimization of security controls, including EDR/AV, firewalls, DLP, email security, web filtering, and identity/access systems.
  • Lead platform integration efforts, including refining SaaS configurations, IAM, and SIEM log onboarding, parsing, and correlation rule development.
  • Manage vulnerability assessment tooling, build attack-surface visibility, and conduct risk/threat modeling aligned with the MITRE ATT&CK framework.
  • Provide engineering support during security incidents, including host isolation, forensic collection, and log retrieval.
  • Develop automated playbooks, API integrations, and detection logic to accelerate triage and reduce false positives.
  • Perform root-cause analysis post-incident and partner with infrastructure teams on air-gapped/immutable backup and recovery architecture.
  • Translate security policies and regulatory requirements into technical baselines and secure configuration standards.
  • Support internal and external audits by producing technical evidence, architecture documentation, and remediation solutions.
  • Evaluate and recommend new security products, SaaS tools, and AI integrations to improve firm security and address business needs.


Qualifications

  • Minimum of 5 years of progressive, hands-on information security engineering experience.
  • Bachelor's Degree in IT, Cybersecurity, or equivalent hands-on experience preferred.
  • CISSP, GIAC, or CCSP certification strongly preferred.
  • Prior experience in a law firm or heavily regulated professional services environment preferred.
  • Demonstrated proficiency with EDR, SIEM, firewalls, identity management (MFA/PAM), scripting (APIs/Microsoft Graph), and vulnerability tools.
  • Ability to work independently, manage project priorities, and balance security requirements with firm risk tolerance.
  • Experience leveraging AI-enabled productivity or security tools is a plus.

Have more questions? Connect with a recruiter directly. #LI-KB1

About McGuireWoods

McGuireWoods LLP is a US-based international law firm. Their largest offices are in Richmond, Virginia, Charlotte, North Carolina and Chicago, Illinois.
Learn more about McGuireWoods
Industry
Founded
1834

Similar Jobs

More Jobs at McGuireWoods

More Information Technology Jobs

Find similar Sr. Information Security Engineer jobs: