ForgeApply
Try it free

ForgeApply · Job listing

Chief Information Security Officer

DLA Piper

Reston, VA | Atlanta, US$550k – $650khybrid

See all 141 open roles at DLA Piper

Tailor your resume for this DLA Piper job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for DLA Piper's site. Free trial, no card required.

About this role

DLA Piper is, at its core, bold, exceptional, collaborative and supportive.  Our people are the backbone, heart and soul of our firm.  Wherever you are in your professional journey, DLA Piper is a place you can engage in meaningful work and grow your career.  Let’s see what we can achieve. Together.

Summary The Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives , is a senior executive responsible for protecting DLA Piper’s clients, people, data, reputation, and global business operations by leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response, third-party security, data protection, and security awareness programs.

Operating as a trusted advisor to firm leadership, the Office of General Counsel, Information Technology, Information Governance, Risk Management, practice leadership, and global counterparts, the CISO ensures the confidentiality, integrity, and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience, and exceptional client service. The CISO works closely with, but independently from, the Information Technology function to provide objective risk oversight, policy leadership, executive reporting, and continuous improvement of the firm’s security posture.

Location This position can sit in our Atlanta, Baltimore, Boston, Miami, New York, Northern Virginia, Philadelphia, Raleigh, Short Hills, Washington D.C., or Wilmington office. Candidates must reside within a reasonable commuting distance of their assigned office and be available for periodic travel.

Responsibilities • Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations, and operational resilience objectives. • Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations, and operational resilience objectives. • Leads the firm’s Information Security Management System and security governance framework, including policy development, risk assessment, control monitoring, executive reporting, audit readiness, certification support, and continuous improvement. • Serves as the senior incident response leader for information security events, ensuring prompt triage, containment, investigation, evidence preservation, root-cause analysis, remediation, lessons learned, and appropriate coordination with the Office of General Counsel, firm leadership, insurers, regulators, law enforcement, vendors, and affected clients when required. • Partners with executive leadership, Information Technology, AI Innovation, AI Governance, Information Governance, Risk Management, Privacy, Procurement, Finance, Human Resources, practice leaders, and global counterparts to embed security-by-design into firm operations, technology investments, client service delivery, and major transformation initiatives. • Provides objective cyber risk advice to firm leadership and governance bodies, translating complex technical risk into clear business, legal, reputational, operational, and client-impact terms that enable timely and informed decision-making. • Oversees enterprise cyber risk identification, assessment, treatment, acceptance, and reporting, including vulnerabilities, threat intelligence, identity and access risk, cloud and infrastructure security, application security, data loss prevention, endpoint protection, email security, ransomware preparedness, and business continuity dependencies. • Leads security oversight of client and firm confidential information, including data classification, access controls, encryption, retention, secure disposal, cross-border data considerations, ethical walls, client outside counsel guidelines, and matter-specific security obligations. • Directs third-party and supplier security risk management in partnership with Procurement, Information Technology, Information Governance, and business owners, ensuring vendors that access firm or client data are assessed, monitored, and held to appropriate security, privacy, contractual, and operational standards. • Guides security review and risk oversight for emerging technologies, cloud services, legal technology, artificial intelligence, automation, analytics, and internally developed tools, ensuring innovation is deployed responsibly and in compliance with firm policies, client requirements, and applicable legal and ethical obligations. • Builds, develops, and leads a high-performing information security organization with the expertise, credibility, accountability, and service orientation required to support a complex, global, partner led professional services environment. • Defines and manages the Information Security team’s operating model, including functional roles, accountability structures, governance routines, service levels, intake and prioritization processes, escalation protocols, on-call expectations, and coordination with Information Technology, Risk, Information Governance, Privacy, Procurement, Human Resources, and practice leadership. • Recruits, develops, coaches, and retains a high-caliber Information Security team with the technical depth, risk judgment, executive presence, discretion, and client-service mindset required to operate effectively in a global law firm environment. • Sets clear goals and performance expectations for the Information Security team, regularly assesses performance against strategic objectives and operational metrics, addresses performance gaps, recognizes strong contributions, and ensures the team has the training, tools, r

Salary insight

The midpoint of this range ($600k) is about 350% above the median disclosed salary for Atlanta roles listed on ForgeApply ($133k across 684 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this DLA Piper role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)