Director, Information Security

22 hours ago


Washington DC United States WilmerHale Full time

WilmerHale is a leading, full-service international law firm with 1,000 lawyers located throughout 12 offices in the United States, Europe and Asia. Our lawyers work at the intersection of government, technology and business, and we remain committed to our guiding principles of providing quality, excellent legal and client services; developing diversity among our lawyers and staff and cultivating an environment that promotes an ambitious spirit, collaboration and collegiality by drawing on the extraordinary talents and dynamic experience of our lawyers. Our goal is to reflect the diversity of our clients and the communities in which we practice.


What You Will Be Doing


The Director, Information Security is responsible for directing IS strategy and activities related to information security. The Director provides leadership and direction to a team responsible for developing and implementing an overall enterprise security strategy, program, and architecture that minimizes information related loss and meets client and regulatory requirements. Develops, monitors and enforces firm-wide information security policies to ensure that appropriate access to, and the confidentiality of firm, client and private information is maintained. Conducts information risk assessments as an integral part of business planning involving General Counsel, internal experts and business owners as required. Serves as a liaison to firm clients in all matters of information security including completion of client audits and review of RFPs and outside counsel guidelines. Leads and coordinates the firm's tactical and operational response to information security incidents. Identifies and reports on information security incidents to firm management. Manages organizational risk by ensuring the protection of the enterprise infrastructure with a layered system of technical defenses including firewalls, intrusion detection and prevention, antivirus, and content monitoring. Provides risk review and approval of changes to systems, applications and facilities. Leads the evaluation and recommendation of security products, services and/or procedures to enhance productivity and effectiveness. Leads risk assessments of firm vendors and solution providers. Oversees and conducts security awareness programs and provides education on security policies and practices.


Ensures that staff members are providing quality service to internal members/departments of the Firm as well as external clients and vendors by displaying professionalism via electronic and print correspondence, over the telephone and in-person and by encouraging an atmosphere that rewards a "can do" attitude.


About The Role


  • Manages Information Security staff, including scheduling, performance evaluation, salary recommendation and related personnel actions.
  • Identifies areas of risk to firm, client and private information and leads risk assessments to determine appropriate remediation, serving as a liaison to General Counsel in this regard.
  • Works directly with firm clients to address information security concerns and complete written and in-house security audits, negotiating and implementing requested security training and technical measures.
  • Works with the business to review Outside Counsel Guidelines and Requests for Proposal, confirming the firm's ability to meet requirements and requesting changes as warranted.
  • Directs firm activities and resources to achieve and maintain compliance with information security standards such as state and federal privacy laws, ISO 27002/1, and General Data Protection Regulation.
  • Leads and coordinates the firm's operational response to information security incidents that threaten firm, client and private information, directing forensics and organizing communications. Identifies and reports on information security incidents to firm management.
  • Approves changes to firm systems, applications and policies that may affect the security of firm, client and private information. Serves as the internal auditor for information security processes.
  • Works closely with senior leaders, line-of-business managers, the IT organization, and others to establish an effective security governance framework, support the delegation of authority, manage budgets, ensure effective enterprise risk management and support the establishment of measurable controls.
  • Serves as an internal information security consultant to the Department and Firm. Advises the department with current information about information security technologies and related regulatory issues.
  • Develops a strategic vision for the security program; organizes resources for effective security policies, practices and processes; and develops an annual security plan. Identifies enterprise systems, processes, and information resources that require security protections.
  • Identifies areas where existing security architecture requires change or development. Ensures local security standards align with international and national standards. Stays up to date with Security (legal requirements, policy and technology) developments in the commercial world and especially in the area of the law so that the firm remains at the forefront of any security related developments affecting the firm and the firm's clients.
  • Monitors multiple logs across diverse platforms to uncover specific activities as they occur from platform to platform. Analyzes security analysis reports for security vulnerabilities and recommends feasible and appropriate options. Reports on significant trends and vulnerabilities.
  • Develops, maintains, publishes, and communicates enterprise-wide security standards, procedures and guidelines. Ensures that adherence to those standards is monitored and enforced.
  • Oversees the security infrastructure; for example identity and access management, firewalls, antivirus and intrusion detection system/intrusion prevention system. Monitors internal control systems to ensure that appropriate information access levels and security clearances are maintained. Monitors the security infrastructure for policy violations or security events, conducts security engineering, assists with resolution of escalated incidents and participates in problem management activities.
  • Improves security awareness and instills a risk-aware culture in the organization, ensuring that personnel fully understand the risk implications of their IT assets.
  • Measures and reports on the effectiveness and efficiency of security activities and capabilities. Manages, monitors, and matures security processes (for example, identity and access management; and threat and vulnerability management).
  • Oversees IT security within the system development lifecycle, change management, production systems support and technology-enabled projects (user administration, security logging, secure process flow, security best practices).
  • Develops and leads information security projects, adhering to budgets, project plans, and business objectives.
  • Negotiates security-related software licensing and support agreements.
  • Oversees security reviews of potential new firm technology tools as part of the broader due diligence process.
  • Assumes additional responsibilities as assigned.

What You Will Bring/Your Qualifications


  • Strategic thinking and planning abilities required.
  • Analytical thinking:
    • Able to breakdown raw information and undefined problems into specific, workable components that in-turn clearly identify the issues at hand.
    • Makes logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision making process.
  • Demonstrated team player with ability to effectively meet challenges, influence and drive consensus within the team.
  • Enterprise business knowledge:
    • Solicits information on enterprise direction, goals and industry competitive environment to determine how own function can add value to the organization and to customers.
    • Makes decisions and recommendations clearly linked to the organization's strategy and financial goals, reflecting an awareness of external dynamics.
  • Risk management:
    • Identifies risks and obstacles to plans. Defines scarcity and conflicts of resource needs, and potential constraints.
    • Investigates risks within various project elements, assesses impact, and develops contingency plans to address major risks.
  • Deep knowledge of security issues, techniques, and implications across all existing computer platforms required.
  • Deep knowledge of networking, databases and systems operations is required.
  • Proven leadership skills are required.
  • Collaboration and influence skills are required.
  • Proven interpersonal and communication skills. Strong ability to communicate clearly and succinctly with firm leadership, lawyers and business professionals, as well as external clients.
  • Demonstrated ability to prioritize tasks and effectively manage multiple responsibilities in a dynamic environment.
  • Demonstrated problem solving abilities, analytical skills, and proven ability to meet challenging deadlines required.
  • Strong work ethic; excellent use of discretion and judgment.
  • Excellent written communication skills.
  • Ability to work under pressure and multi-task on various assignments; Detail orientation is a must.

Education


  • Bachelor's Degree in Computer Science, Cybersecurity, Management or related work experience.
  • CISSP or other major security certification preferred.

Experience:


  • Minimum of 10 years' work experience managing information security in a large and complex environment; or other equivalent combination of education and experience that provides the required knowledge and skills.
  • Strong experience managing an Information Security team, to include demonstrated experience communicating with senior stakeholders.

This job description is intended to describe the general nature and level of the work being performed by employees in the position. It is not intended to be a complete list of all responsibilities, duties, and skills for positions. The firm reserves the right at all times, in its sole discretion, to add or subtract duties and responsibilities, as it deems necessary.


WilmerHale is an Equal Opportunity Employer. All qualified applicants will receive consideration without regard to race, color, religion, gender, sexual orientation, gender identity, national origin or ancestry, age, disability or veteran status, or other protected status.


#L1-MB1


#L1-Hybrid

#J-18808-Ljbffr

  • , CA, United States JBA International Full time

    The Director of Information Security reports to the Chief Information Officer (CIO) and is responsible for information security policy assessments, enforcing compliance with firm security policies and applicable law, vendor management and security incident management. Working with the firm’s Information Technology teams, including Network Operations,...


  • Washington, United States Wilmerhale Full time

    Job Description WilmerHale is a leading, full-service international law firm with 1,000 lawyers located throughout 12 offices in the United States, Europe and Asia. Our lawyers work at the intersection of government, technology and business, and we remain committed to our guiding principles of providing quality, excellent legal and client services;...


  • Washington, DC, United States Conference of State Bank Supervisors Full time

    CSBS Corporate, Washington, District Of Columbia, United States of America Job Description Posted Thursday, April 11, 2024 at 4:00 AM This position is responsible for providing vision, leadership, oversight, and management of CSBS cyber security policies, procedures, and practices. He/she directs, coordinates, plans, and organizes security activities...


  • Washington, DC, United States TekSynap Full time

    Responsibilities & Qualifications RESPONSIBILITIES The Information Systems Security Engineer is expected to be able to: Support Engineering and Operations network solutions and strategic adherence to all aspects of the Information Assurance (IA) program as stipulated by various U.S. Government requirements including (but not limited to): Director of Central...


  • Washington, DC, United States TekSynap Full time

    Responsibilities & Qualifications RESPONSIBILITIES Support Engineering and Operations network solutions and strategic adherence to all aspects of the Information Assurance (IA) program as stipulated by various U.S. Government requirements including (but not limited to): Director of Central Intelligence Directives (DCID), IC Directive (ICD) 503 and...


  • Washington, DC, United States KamisPro Full time

    Kamis has been retained by The National Community Reinvestment Coalition to assist their search for an experienced IT Director. Candidates must have prior non-profit experience and be willing to go onsite 3 days per week in Washington, DC.This is a full time, direct hire position.*The National Community Reinvestment Coalition is a network of organizations...


  • Stockbridge, VT, United States Radius Staffing Solutions Full time

    Seeking an ONSITE Director of HIM in the hospital setting to oversee in the beautiful state of Vermont. Interested candidates should have a Bachelor's degree in HIM, Health Informatics, Information Security or related field. Specialty certification is desired-RHIA, CHPS, CISSP, CISM and/or CIPP, CIPT or CISM. You will oversee 6 FTE's. 3+ years of HIM...


  • Stockbridge, VT, United States Radius Staffing Solutions Full time

    Seeking an ONSITE Director of HIM in the hospital setting to oversee in the beautiful state of Vermont. Interested candidates should have a Bachelor's degree in HIM, Health Informatics, Information Security or related field. Specialty certification is desired-RHIA, CHPS, CISSP, CISM and/or CIPP, CIPT or CISM. You will oversee 6 FTE's. 3+ years of HIM...


  • Washington, DC, United States European Interagency Security Forum Full time

    POSITION SUMMARY: The Global Security Officer (GSO) serves as the HQ Security representative to develop and coordinate activities in support of Project HOPE’s duty of care policy which endeavor to protect the safety and security of employees against reasonably foreseeable dangers in the workplace. The GSO proactively supports the HQ Security department...


  • Washington, DC, United States Artech Information System LLC Full time

    Artech is the 10th Largest IT Staffing Company in the US, according to Staffing Industry Analysts' 2012 annual report. Artech provides technical expertise to fill gaps in clients' immediate skill-sets availability, deliver emerging technology skill-sets, refresh existing skill base, allow for flexibility in project planning and execution phases, and provide...


  • Washington, United States Atlantic Council Full time

    Job Location: Atlantic Council Headquarters - Washington, DC Employment Type: Full-Time Seniority Level: Deputy Director Job Category: Staff Overview The Office of Finance and Operations (OFO) serves the 16 programs and centers of the Atlantic Council. Operational efficiency within OFO is critical to the success of the Council and the Deputy Director,...


  • Washington, United States Atlantic Council Full time

    Job Location: Atlantic Council Headquarters - Washington, DC Employment Type: Full-Time Seniority Level: Deputy Director Job Category: Staff Overview The Office of Finance and Operations (OFO) serves the 16 programs and centers of the Atlantic Council. Operational efficiency within OFO is critical to the success of the Council and the Deputy Director,...


  • Washington, United States Atlantic Council of the United States Full time

    Job Location: Atlantic Council Headquarters - Washington, DCEmployment Type: Full-TimeSeniority Level: Deputy DirectorJob Category: StaffOverviewThe Office of Finance and Operations (OFO) serves the 16 programs and centers of the Atlantic Council. Operational efficiency within OFO is critical to the success of the Council and the Deputy Director, Security,...


  • Washington, United States Atlantic Council Full time

    Job Location: Atlantic Council Headquarters – Washington, DCEmployment Type: Full-TimeSeniority Level: Deputy DirectorJob Category: StaffOverviewThe Office of Finance and Operations (OFO) serves the 16 programs and centers of the Atlantic Council. Operational efficiency within OFO is critical to the success of the Council and the Deputy Director, Security,...


  • Washington, DC, United States Iron Bow Technologies Full time

    Iron Bow Technologies is for people who believe trust is paramount , transformation is embraced , and the future is here , because "What we do matters !" We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on our passionate people , long standing...


  • Washington, DC, United States Department Of Transportation Full time

    DutiesThe Director, System Operations Security located in the Air Traffic Organization (ATO) is responsible for managing all programs related to air traffic national security and leads System Operations Services in protecting the United States and its interests from security threats involving the Air Domain. The Director leads, manages, and executes the...


  • Washington, DC, United States Booz Allen Hamilton Full time

    Your growth matters to us - explore our career development opportunities. A PLACE WHERE YOU BELONG Bring your whole self to work in our culture of respect and inclusivity. SUPPORT YOUR WELLBEING Learn how we’ll support you as you pursue a balanced, fulfilling life. YOUR CANDIDATE JOURNEY Discover what to expect during your journey as a candidate with us....


  • Washington, DC, United States Gilder Search Group Full time

    Summit Technologies, Inc. is looking for a talented Information System Security Officer. In this role you will research, develop, implement, test, and review our client’s information security to protect information and prevent unauthorized access. Candidates must be eligible for a Public Trust clearance. This is an on-site position based in Washington,...


  • Washington, DC, United States Chenega Corporation Full time

    Overview Come join a company that strives for Extraordinary People and Exceptional PerformanceEagle One Solutions, Inc., a Chenega Professional Services’ company, is looking for a Lead Information Security Analyst to lead and support a large federal IT organization.The Lead Information Security Analyst will provide information security expertise in support...


  • Washington, DC, United States Planet Technology Full time

    Hours: 40 hoursInterview Process: 3 stepsLocation: Washington DC - hybrid role (2-3 days onsite)Chief Information Security OfficerMust Haves:* 15-20 years of security experience* Must have strong technical knowledge of IP networking, networking protocols and related technologies including encryption, IPSec, PKI, VPNs, firewalls, proxy services, DNS and...