Director of Information Security

ArentFox Schiff LLPNew York City, Washington, New York, District of ColumbiaOn-siteFull-timeStaff, 8–12 yearsListed 4 hours ago

Apply now

About this role

Who We Are

ArentFox Schiff is an award-winning, globally recognized law firm that delivers sophisticated, innovative, and practical legal solutions to clients around the world. With more than 600 lawyers and policy professionals, ArentFox Schiff's expertise is sought out by Fortune 500s, start-ups, international governments, non-profits and trade associations, and private individuals.  Our work spans highly complex, global matters as well as the deeply personal issues that shape the lives of individuals and communities.

Why Join Us

At ArentFox Schiff, we know that diverse backgrounds produce different perspectives, richer thinking, and more creative solutions to the challenges our clients face. We hope you share that vision. Join us and take on the challenge of doing meaningful work while helping us build upon a culture that reflects our dedication to diversity, equity, and inclusion. We base all of our employment decisions on merit and do not discriminate on the basis of any legally protected characteristic.

Job Description

The Director of Information Security leads the development, operation, and continuous improvement of the firm’s information security, cybersecurity, privacy, compliance, and technology risk programs. This role safeguards firm and client information by defining security strategy, governance, architecture, controls, and operational capabilities across cloud services, identity, applications, endpoints, networks, email, data, artificial intelligence (“AI”), and third-party services.

Working closely with administrative departments, attorneys, clients, and external providers, the Director enables responsible technology adoption while maintaining acceptable risk levels. The role oversees security policy and standards, ISO certification, regulatory compliance, AI and emerging-technology risk, vendor security, security operations, incident response, identity and access management, data protection, security awareness, client audits, business continuity, and security program performance.

Strategy, Governance, and Risk

- Develop and execute the firm’s information security strategy, governance framework, policies, standards, and annual security roadmap to protect firm, client, and employee information.

- Lead enterprise cybersecurity, privacy, risk management, and compliance programs in alignment with applicable laws, regulations, client requirements, and frameworks such as ISO/IEC 27001, ISO/IEC 27002, ISO 22301, and NIST.

- Establish security requirements and governance for cloud services, AI, generative AI, machine learning, autonomous agents, and other emerging technologies, balancing innovation with the protection of confidential and proprietary information.

- Direct enterprise risk assessments, security architecture reviews, and control evaluations to identify, prioritize, and remediate cybersecurity, technology, vendor, and operational risks.

##

Security Operations and Technology

- Oversee security operations, including threat monitoring and detection, vulnerability management, incident response, forensic investigations, and security engineering.

- Provide governance and oversight for identity and access management, data protection, network security, endpoint security, application security, cloud security, and third-party technology integrations.

- Support the development and oversight of the firm’s business continuity, disaster recovery, and physical security programs.

##

Advisory, Client, and Vendor Responsibilities

- Serve as the firm’s primary security advisor to leadership, business stakeholders, clients, auditors, and vendors on cybersecurity, privacy, regulatory, and technology risk matters.

- Lead client security audits, security questionnaires, Outside Counsel Guidelines reviews, Requests for Proposal, and other client-driven security assessments.

- Direct vendor security reviews and due diligence for managed security services, cloud providers, software platforms, and AI-enabled solutions.

- Partner with Technology Services, Innovation, administrative departments, and business leaders to integrate security into enterprise projects, system development, operational processes, and technology-enabled initiatives.

##

Leadership and Program Management

- Promote a culture of security awareness through training, communication, policy enforcement, and ongoing education for attorneys, staff, and technology personnel.

- Define and report cybersecurity metrics, program maturity, emerging risks, and strategic initiatives to executive leadership.

- Manage security budgets, contracts, projects, and strategic investments.

Minimum Qualifications

Education and Certifications

- Bachelor’s degree in a related field, specialized training, or equivalent professional experience.
- Relevant industry certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or a comparable credential.

Experience

- Eight or more years of progressively responsible experience in cybersecurity, information security, technology risk, privacy, compliance, security architecture, or related discipline, including at least three years in a leadership role.
- Demonstrated success leading a multidisciplinary security program in a legal, professional services, financial services, healthcare, or similarly sensitive and regulated environment; law firm or professional services experience is strongly preferred.

- Experience developing and operating enterprise security capabilities across Microsoft 365, Azure, Entra ID, cloud applications, email, endpoints, networks, data, APIs, and third-party services, using platforms such as ReliaQuest, Proofpoint, Abnormal Security, Netskope, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Microsoft Intune.

- Experience evaluating the security, privacy, compliance, and operational impact of AI and AI-enabled applications.

- Experience governing OAuth applications, Microsoft Graph permissions, enterprise application registrations, privileged and workload identities, certificates, service accounts, secrets, and role-based access controls.

- Experience leading incident response, vendor assessments, remediation efforts, client and ISO audits, security awareness initiatives, and executive risk reporting.

- Experience applying ISO/IEC 27001, ISO/IEC 27002, the NIST Cybersecurity Framework, the NIST AI Risk Management Framework, CIS Controls, and Zero Trust principles.

- Experience managing security teams and providers, budgets, contracts, implementation projects, and service levels.

Because cybersecurity risks and technologies continue to evolve, the responsibilities and qualifications for this role may change over time based on the firm’s needs and the complexity of its information security environment.

This is an exempt position and can be based in our NY, DC, or Chicago office. The anticipated good-faith base salary range for this position is:

- DC/CHI: $231,000 to $318,000 per year.

- NYC: $270,000 to $371,000 per year

Your exact offer will be based on a variety of factors, including but not limited to, your experience, skills, and overall qualifications.  We also review compensation regularly against industry benchmarks and performance outcomes, so you can grow your career here with confidence—knowing your pay recognizes both your impact and our commitment to an equitable approach.

In addition to a competitive base salary, certain positions are eligible for a comprehensive performance-based bonus, payable monthly or annually.

Benefits

We know that the needs of our employees vary and can change throughout the different stages of life.  That’s why we offer a wide array of flexible benefit options designed to help you live healthy , live well , and live for tomorrow .  In addition to medical, dental, vision, profit-sharing, generous paid time off, and numerous other benefits, we also provide a flexible reimbursement account that helps pay for the things that contribute to your personal well-being, in your own way.

Commitment to Equal Opportunity

ArentFox Schiff is committed to equal employment opportunity and diversity in the workplace.  We base all employment decisions on merit and maintain a policy of considering all qualified applicants for employment without regard to race, color, religion or creed, sex, gender, sexual orientation, gender identity or expression, age, citizenship status, order of protection status, national origin, ancestry, medical condition, genetic information, marital status, physical or mental disability, parental status, source of income, military or veteran status, unfavorable discharge from military service, or any other basis protected by applicable law.  We will consider qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chance Ordinance.

* The job description is a general summary of the major duties.  It may not specify all duties, tasks, and assignments associated with a job.  It does not limit or in any way modify the right of management to direct, assign, and control the work of employees in a unit.  Accuracy, attention to detail, ability to work effectively in a team environment, and ability to work in an atmosphere of multiple projects and shifting priorities are requirements of all jobs at ArentFox Schiff LLP.  Additional job-related qualifications may be specified for some openings.  Job descriptions are subject to periodic review and modification.