ForgeApply · Job listing
Chief Information Security Officer
Morganmorganjobsapplynow
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People.
About the Role
Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability.
We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms.
This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt.
This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust.
Key Responsibilities
Security Strategy & Risk Leadership
• Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale
• Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment
• Translate cyber risk into clear business impact for executive leadership and the Board
• Guide security investment decisions that balance velocity, resilience, and client trustRisk
Management & Compliance
• Lead firm-wide risk assessments, threat modeling, and control maturity evaluations
• Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning
• Partner closely with Legal, Privacy, and Compliance leaders to ensure:
• Protection of sensitive client and case data
• Defensible security practices suitable for litigation discovery
• Alignment with regulatory, contractual, and ethical obligations
• Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement
• Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology
• Embed security into:
• Agile software development and CI/CD pipelines
• Cloud-native platforms and SaaS ecosystems
• AI-enabled legal workflows and analytics platforms
• Implement Zero Trust principles using pragmatic, developer-friendly controls
• Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys
Security Operations
• Oversee security operations including:
• Identity & Access Management (IAM)
• Endpoint, network, and cloud security
• Security monitoring, detection, and response
• Continuously improve detection, response time, and operational resilience
• Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations
• Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture
• Build, lead, and mentor a high-caliber, hands-on security organization
• Establish strong operating models between Security, IT, Engineering, and the business
• Set clear expectations and a high bar for execution, accountability, and follow-through across the security function
• Champion a culture where security is designed in early, not bolted on late
• This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed
• Act as a visible, trusted executive leader approachable, decisive, and credible
Required Experience
• 10+ years in cybersecurity, including senior leadership roles in large, complex environments
• Proven success leading security programs in high-data-sensitivity, fast-moving organizations
• Demonstrated ability to communicate cyber risk clearly to executive leadership and
Boards
• Strong working knowledge of:
• NIST Cybersecurity Framework (CSF) and/or ISO 27001
• Zero Trust architecture
• Incident response and crisis leadership
• Cloud and SaaS security at scaleExecutive Mindset
• Business-first approach to security focused on outcomes, not checklists
• Comfort making tradeo/s and defending decisions at the executive level
• Calm, credible leadership during high-pressure situations
• High integrity, sound judgment, and strong ethical foundationPreferred Qualifications
• CISSP, CISM, or equivalent credentials
• Experience supporting AI platforms, analytics, or large-scale dig
Ready to apply to Morganmorganjobsapplynow?
Apply in about a minuteSimilar jobs
- Chief Information Security Officer — Nubank · Remote
- Chief Information Security Officer (CISO) — Mastercontrol · Salt Lake City (Hybrid)
- Chief Information Security Officer (CISO) — Hippo70 · Austin, TX / Morristown, NJ (hybrid)
- Chief Information Security Officer (CISO) — Floatme · San Antonio, TX or Jacksonville, FL
- Chief Information Security Officer (CISO) — Cais · New York City
- Information Security Officer — Robin-radar · Remote
- Deputy Chief Information Security Officer — Sardine · Remote
- Senior Information Systems Security Officer — Captivation · Annapolis Junction, MD
More like this: More jobs at Morganmorganjobsapplynow · Browse all jobs