Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director of Information Security

$231k - $318k

ArentFox Schiff LLP

Who We Are

ArentFox Schiff is an award-winning, globally recognized law firm that delivers sophisticated, innovative, and practical legal solutions to clients around the world. With more than 600 lawyers and policy professionals, ArentFox Schiff's expertise is sought out by Fortune 500s, start-ups, international governments, non-profits and trade associations, and private individuals. Our work spans highly complex, global matters as well as the deeply personal issues that shape the lives of individuals and communities.

Why Join Us

At ArentFox Schiff, we know that diverse backgrounds produce different perspectives, richer thinking, and more creative solutions to the challenges our clients face. We hope you share that vision. Join us and take on the challenge of doing meaningful work while helping us build upon a culture that reflects our dedication to diversity, equity, and inclusion. We base all of our employment decisions on merit and do not discriminate on the basis of any legally protected characteristic.

Job Description

The Director of Information Security leads the development, operation, and continuous improvement of the firm's information security, cybersecurity, privacy, compliance, and technology risk programs. This role safeguards firm and client information by defining security strategy, governance, architecture, controls, and operational capabilities across cloud services, identity, applications, endpoints, networks, email, data, artificial intelligence ("AI"), and third-party services.

Working closely with administrative departments, attorneys, clients, and external providers, the Director enables responsible technology adoption while maintaining acceptable risk levels. The role oversees security policy and standards, ISO certification, regulatory compliance, AI and emerging-technology risk, vendor security, security operations, incident response, identity and access management, data protection, security awareness, client audits, business continuity, and security program performance.

Strategy, Governance, and Risk
  • Develop and execute the firm's information security strategy, governance framework, policies, standards, and annual security roadmap to protect firm, client, and employee information.
  • Lead enterprise cybersecurity, privacy, risk management, and compliance programs in alignment with applicable laws, regulations, client requirements, and frameworks such as ISO/IEC 27001, ISO/IEC 27002, ISO 22301, and NIST.
  • Establish security requirements and governance for cloud services, AI, generative AI, machine learning, autonomous agents, and other emerging technologies, balancing innovation with the protection of confidential and proprietary information.
  • Direct enterprise risk assessments, security architecture reviews, and control evaluations to identify, prioritize, and remediate cybersecurity, technology, vendor, and operational risks.
Security Operations and Technology
  • Oversee security operations, including threat monitoring and detection, vulnerability management, incident response, forensic investigations, and security engineering.
  • Provide governance and oversight for identity and access management, data protection, network security, endpoint security, application security, cloud security, and third-party technology integrations.
  • Support the development and oversight of the firm's business continuity, disaster recovery, and physical security programs.
Advisory, Client, and Vendor Responsibilities
  • Serve as the firm's primary security advisor to leadership, business stakeholders, clients, auditors, and vendors on cybersecurity, privacy, regulatory, and technology risk matters.
  • Lead client security audits, security questionnaires, Outside Counsel Guidelines reviews, Requests for Proposal, and other client-driven security assessments.
  • Direct vendor security reviews and due diligence for managed security services, cloud providers, software platforms, and AI-enabled solutions.
  • Partner with Technology Services, Innovation, administrative departments, and business leaders to integrate security into enterprise projects, system development, operational processes, and technology-enabled initiatives.
Leadership and Program Management
  • Promote a culture of security awareness through training, communication, policy enforcement, and ongoing education for attorneys, staff, and technology personnel.
  • Define and report cybersecurity metrics, program maturity, emerging risks, and strategic initiatives to executive leadership.
  • Manage security budgets, contracts, projects, and strategic investments.
Minimum Qualifications

Education and Certifications
  • Bachelor's degree in a related field, specialized training, or equivalent professional experience.
  • Relevant industry certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or a comparable credential.
Experience
  • Eight or more years of progressively responsible experience in cybersecurity, information security, technology risk, privacy, compliance, security architecture, or related discipline, including at least three years in a leadership role.
  • Demonstrated success leading a multidisciplinary security program in a legal, professional services, financial services, healthcare, or similarly sensitive and regulated environment; law firm or professional services experience is strongly preferred.
  • Experience developing and operating enterprise security capabilities across Microsoft 365, Azure, Entra ID, cloud applications, email, endpoints, networks, data, APIs, and third-party services, using platforms such as ReliaQuest, Proofpoint, Abnormal Security, Netskope, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Microsoft Intune.
  • Experience evaluating the security, privacy, compliance, and operational impact of AI and AI-enabled applications.
  • Experience governing OAuth applications, Microsoft Graph permissions, enterprise application registrations, privileged and workload identities, certificates, service accounts, secrets, and role-based access controls.
  • Experience leading incident response, vendor assessments, remediation efforts, client and ISO audits, security awareness initiatives, and executive risk reporting.
  • Experience applying ISO/IEC 27001, ISO/IEC 27002, the NIST Cybersecurity Framework, the NIST AI Risk Management Framework, CIS Controls, and Zero Trust principles.
  • Experience managing security teams and providers, budgets, contracts, implementation projects, and service levels.
Because cybersecurity risks and technologies continue to evolve, the responsibilities and qualifications for this role may change over time based on the firm's needs and the complexity of its information security environment.

This is an exempt position and can be based in our NY, DC, LA or Chicago office. The anticipated good-faith base salary range for this position is:
  • DC/CHI/LA: $231,000 to $318,000 per year.
  • NYC: $270,000 to $371,000 per year

Your exact offer will be based on a variety of factors, including but not limited to, your experience, skills, and overall qualifications. We also review compensation regularly against industry benchmarks and performance outcomes, so you can grow your career here with confidence-knowing your pay recognizes both your impact and our commitment to an equitable approach.

In addition to a competitive base salary, certain positions are eligible for a comprehensive performance-based bonus, payable monthly or annually.

Benefits

We know that the needs of our employees vary and can change throughout the different stages of life. That's why we offer a wide array of flexible benefit options designed to help you live healthy, live well, and live for tomorrow. In addition to medical, dental, vision, profit-sharing, generous paid time off, and numerous other benefits, we also provide a flexible reimbursement account that helps pay for the things that contribute to your personal well-being, in your own way.

Commitment to Equal Opportunity

ArentFox Schiff is committed to equal employment opportunity and diversity in the workplace. We base all employment decisions on merit and maintain a policy of considering all qualified applicants for employment without regard to race, color, religion or creed, sex, gender, sexual orientation, gender identity or expression, age, citizenship status, order of protection status, national origin, ancestry, medical condition, genetic information, marital status, physical or mental disability, parental status, source of income, military or veteran status, unfavorable discharge from military service, or any other basis protected by applicable law. We will consider qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chance Ordinance.

* The job description is a general summary of the major duties. It may not specify all duties, tasks, and assignments associated with a job. It does not limit or in any way modify the right of management to direct, assign, and control the work of employees in a unit. Accuracy, attention to detail, ability to work effectively in a team environment, and ability to work in an atmosphere of multiple projects and shifting priorities are requirements of all jobs at ArentFox Schiff LLP. Additional job-related qualifications may be specified for some openings. Job descriptions are subject to periodic review and modification.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Director of Information Security in New York, NY vacancy
  • $136.5k - $350k

     ...We’re seeking a future team member for the role of Senior Director of Network Security - Engineering Lead to join our Network Security team....  ...required; advanced degree preferred15+ years of experience in information security or related technology experience required;... 
    Suggested
    Temporary work
    Work experience placement
    Remote work
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    New York, NY
    1 day ago
  • Zillow Group is seeking a Director of Information Security to drive strategy across Application Security and Security Architecture. This leadership role requires a hands-on background in security engineering and software development, with the ability to recruit senior... 
    Suggested
    Remote job

    Zillow Group

    New York, NY
    5 days ago
  • $144.25k - $256.25k

     ...customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a...  ...future of a Fortune 100 company.Trust. Service. Security.Director, Cybersecurity provides leadership and guidance to senior... 
    Suggested
    Visa sponsorship

    American Express

    New York, NY
    1 day ago
  • $200k - $240k

    Overview Director of Cloud-Native Security Operations - 245347 Medix is seeking a Director of Cloud-Native Security Operations for one of our top...  ...Response (SOAR) practices Leveraging data from Security Information and Event Management (SIEM) platforms to drive proactive... 
    Suggested
    Hourly pay
    Full time
    Contract work
    Remote work
    Shift work

    Medix Technology

    New York, NY
    19 hours ago
  •  ...Overview The Director of Security will be responsible for overseeing all security operations of a Class A commercial building. This position...  ...on appropriate QPS documents and preserve all evidence/information including, but not limited to, records, witness statements,... 
    Suggested
    Permanent employment
    Full time
    For contractors
    Work at office
    Shift work

    Quality Protection Services (QPS)

    New York, NY
    3 days ago
  •  ...SWIFT , alongside FX, treasury management, and bank-issued stablecoin capabilities. Seeking a hands-on Head of Security to build and lead the company's information security function from the ground up. This is a founding-team-level role with significant ownership and... 
    Full time
    Contract work

    Phaxis

    New York, NY
    5 days ago
  • $75k - $85k

     ...illness, some dually with chemical addictions as well. Position Director of Security & Operations Reports To: Vice President Location: Brooklyn,...  ...security and privacy of individually identifiable health information. Understand all aspects of contract requirements and... 
    Permanent employment
    Full time
    Contract work
    Immediate start

    CAMBA

    New York, NY
    2 days ago
  • $170k - $210k

    A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy. This role involves leading a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance.... 

    The Security Executive Council

    New York, NY
    1 day ago
  • $205k - $230k

     ...Role overview The Director of Security Operations leads the day-to-day cybersecurity operations function across traditional and AI-enabled environments. Reporting to the Chief Information Security Officer, this hands-on technical leadership role partners closely with... 
    Full time
    Flexible hours

    Backblaze

    New York, NY
    1 day ago
  •  ...We're looking for a highly technical Security Engineering leader to join a world-leading quantitative investment firm in New York, operating in an environment with an exceptionally high engineering bar and some of the strongest technical talent in the market. We're... 
    Full time
    Work at office
    Relocation

    Iceberg

    New York, NY
    2 days ago
  • DescriptionCompany Overviewiboss is a cloud security company that enables the modern...  ...more, visit .Job DescriptionThe Manager of Information Security & Compliance is a key leadership...  ...protecting information systems and data. The Director of Information Security & Compliance... 

    iBoss

    New York, NY
    1 day ago
  •  ...Head of Information Security About the Company Innovative cloud technology provider specializing in regulatory solutions for the healthcare industry Industry Computer Software Type Privately Held Founded 2025 Employees 51-200 Specialties... 

    Confidential

    New York, NY
    1 day ago
  • $260k - $275k

     ...data and research to educate and empower investors. For more information on CoinDesk media and events, please visit [ [coindesk.com]](...  ...protect journalistic independence. Reports to: Chief Information Security Officer About the Role We are looking for an exceptional... 
    Full time
    Contract work
    Work at office

    CoinDesk

    New York, NY
    11 days ago
  • $77.36k - $87.36k

     ...Job Description Job Description ARROW SECURITY is one of the largest privately held...  ...mission focus we are looking to add a  Director of Security  to support one of our prestigious...  ..., national origin, disability, genetic information, pregnancy, or any other protected... 
    Local area

    Arrow Security

    New York, NY
    a month ago
  • $215k - $290k

    Head of Information Security Risk - Chief Risk Office Location New York Business Area Legal, Compliance, and Risk Ref # 1...  ...to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required. * Act as a strategic thought... 
    Temporary work
    For contractors
    Work experience placement
    Work at office

    Bloomberg

    New York, NY
    4 days ago
  • United States Digital Space LLC is seeking a Director of Security Compliance and Trust to lead governance, risk and compliance across ISO 27001/27701, SOC 1/2, PCI DSS and FedRAMP. You will drive privacy, data protection and AI governance while partnering with Legal, Engineering... 

    United States Digital Space LLC

    New York, NY
    2 days ago
  • VikingCloud seeks a Director, Product Manager for Managed Security Services to lead the GTM strategy, revenue growth, and market positioning for the MSS and endpoint security portfolios. This senior role engages with customers, partners, and internal teams to drive commercial... 

    Jobvite, Inc.

    New York, NY
    2 days ago
  • McAfee seeks a visionary Director of Product Management for Web Protection & Browser Security to shape strategy, roadmap, and execution across Web Advisor and browser-based protections. This hybrid role requires leadership across engineering, design, threat research, and... 

    McAfee

    New York, NY
    19 hours ago
  • AccorHotel in New York City seeks a Security & Safety Director to lead protective services for a luxury property. You will oversee training, policy implementation, investigations, and day-to-day safety operations to ensure exceptional guest experiences. Ideal candidates... 
    Afternoon shift

    AccorHotel

    New York, NY
    5 days ago
  • Everforth ECS seeks a Director of Security Operations to lead SOC analysts, detection engineers, and cyber threat intelligence teams in a remote, senior leadership role. You will define security operations strategy, maintain service delivery across customer and enterprise... 
    Remote job

    Everforth, Inc.

    New York, NY
    19 hours ago
  • $225k - $337.5k

    SVP, Head of Cyber & Information Security OversightWhy this role is important to usEnterprise Technology Risk Management (ETRM) is responsible...  ..., Group CRO, regional CROs and the State Street Board of Directors to manage Cyber Risk adequately.Strong Executive Presence:... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    New York, NY
    3 days ago
  • $80k - $90k

     ...socialization, and other support services . Position: Program Director of Security and Operations Reports To: Vice President of Security and...  ...security and privacy of individually identifiable health information. Immediately report to the appropriate Vice-President/... 
    Permanent employment
    Full time
    Work at office
    Immediate start

    CAMBA

    New York, NY
    19 hours ago
  • $275k - $315k

     ...Counsel & Strategic Partnerships, the Vice President, Head of Privacy (Privacy, Cyber Security, Consumer Compliance) is responsible for all legal aspects of data privacy, information security, and consumer marketing and subscriptions-related compliance across the company... 
    Work at office
    Local area
    Flexible hours
    3 days per week

    The New York Times

    New York, NY
    2 days ago
  • $250k - $350k

     ...Director of Engineering (AI Security) New York,NY, US Job Description Experience: Senior Level Salary: $250,000 - $350,000 per year Job Details What You'll Do Lead multiple engineering teams and provide leadership and mentorship to Engineering Managers... 
    Remote work
    Flexible hours

    Jobleads-US

    New York, NY
    5 days ago
  • $110k - $125k

     ...New York Institutional Commodity Services Corp. (ICS) Director of Building Operations and Security Position Summary The Director of Building Operations...  ...records, inventories, floor plans, equipment information, warranties, and departmental databases. Coordinate with... 
    Contract work
    For contractors
    Work at office
    Relocation
    Weekend work

    Archny

    New York, NY
    3 days ago
  • $109.37k - $123.04k

     ...skilled and motivated Senior Manager, IT Security Operations to join our team. As the...  ...integrity and confidentiality of sensitive information, and maintaining the overall security posture...  ...with Chief Technology Officer, Senior Director of Information Technology, and Virtual... 
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    National Audubon Society

    New York, NY
    2 days ago
  • $200k - $250k

     ...partnerships, our client is seeking a sharp, execution-focused Head of Security & Risk. This is a foundational, individual contributor (IC)...  ...position, the Head of Security & Risk will build and own the information security and enterprise risk management functions from the... 
    Full time
    Contract work
    Remote work
    Flexible hours

    MLabs

    New York, NY
    3 days ago
  • $250k - $330k

     ...and for your life outside it. Our employee NPS sits in the high 80s. We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire. About the role You’ll be our first Head of... 
    Remote work
    Worldwide
    Shift work

    Tremendous

    New York, NY
    1 day ago
  •  ...We're partnering with Quant , a global leader in digital transformation and technology solutions, seeking a Head of Security to join their team. Securing a chain platform that moves regulated money is not the same problem as securing an enterprise. The Clearing House... 
    Immediate start

    Cielo

    New York, NY
    5 days ago
  •  ...technical skills. You can read code, reason about modern cloud architectures (AWS, Kubernetes), threat-model real systems, and ship security tooling yourself when the moment calls for it Experience in running a security program at a fintech, trading firm, or financial... 

    Moment

    New York, NY
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!