Director of Information Security
$231k - $318kArentFox Schiff LLP
Who We Are ArentFox Schiff is an award-winning, globally recognized law firm that delivers sophisticated, innovative, and practical legal solutions to clients around the world. With more than 600 lawyers and policy professionals, ArentFox Schiff's expertise is sought out by Fortune 500s, start-ups, international governments, non-profits and trade associations, and private individuals. Our work spans highly complex, global matters as well as the deeply personal issues that shape the lives of individuals and communities. Why Join Us At ArentFox Schiff, we know that diverse backgrounds produce different perspectives, richer thinking, and more creative solutions to the challenges our clients face. We hope you share that vision. Join us and take on the challenge of doing meaningful work while helping us build upon a culture that reflects our dedication to diversity, equity, and inclusion. We base all of our employment decisions on merit and do not discriminate on the basis of any legally protected characteristic. Job Description The Director of Information Security leads the development, operation, and continuous improvement of the firm's information security, cybersecurity, privacy, compliance, and technology risk programs. This role safeguards firm and client information by defining security strategy, governance, architecture, controls, and operational capabilities across cloud services, identity, applications, endpoints, networks, email, data, artificial intelligence ("AI"), and third-party services. Working closely with administrative departments, attorneys, clients, and external providers, the Director enables responsible technology adoption while maintaining acceptable risk levels. The role oversees security policy and standards, ISO certification, regulatory compliance, AI and emerging-technology risk, vendor security, security operations, incident response, identity and access management, data protection, security awareness, client audits, business continuity, and security program performance. Strategy, Governance, and Risk
- Develop and execute the firm's information security strategy, governance framework, policies, standards, and annual security roadmap to protect firm, client, and employee information.
- Lead enterprise cybersecurity, privacy, risk management, and compliance programs in alignment with applicable laws, regulations, client requirements, and frameworks such as ISO/IEC 27001, ISO/IEC 27002, ISO 22301, and NIST.
- Establish security requirements and governance for cloud services, AI, generative AI, machine learning, autonomous agents, and other emerging technologies, balancing innovation with the protection of confidential and proprietary information.
- Direct enterprise risk assessments, security architecture reviews, and control evaluations to identify, prioritize, and remediate cybersecurity, technology, vendor, and operational risks.
- Oversee security operations, including threat monitoring and detection, vulnerability management, incident response, forensic investigations, and security engineering.
- Provide governance and oversight for identity and access management, data protection, network security, endpoint security, application security, cloud security, and third-party technology integrations.
- Support the development and oversight of the firm's business continuity, disaster recovery, and physical security programs.
- Serve as the firm's primary security advisor to leadership, business stakeholders, clients, auditors, and vendors on cybersecurity, privacy, regulatory, and technology risk matters.
- Lead client security audits, security questionnaires, Outside Counsel Guidelines reviews, Requests for Proposal, and other client-driven security assessments.
- Direct vendor security reviews and due diligence for managed security services, cloud providers, software platforms, and AI-enabled solutions.
- Partner with Technology Services, Innovation, administrative departments, and business leaders to integrate security into enterprise projects, system development, operational processes, and technology-enabled initiatives.
- Promote a culture of security awareness through training, communication, policy enforcement, and ongoing education for attorneys, staff, and technology personnel.
- Define and report cybersecurity metrics, program maturity, emerging risks, and strategic initiatives to executive leadership.
- Manage security budgets, contracts, projects, and strategic investments.
- Bachelor's degree in a related field, specialized training, or equivalent professional experience.
- Relevant industry certification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or a comparable credential.
- Eight or more years of progressively responsible experience in cybersecurity, information security, technology risk, privacy, compliance, security architecture, or related discipline, including at least three years in a leadership role.
- Demonstrated success leading a multidisciplinary security program in a legal, professional services, financial services, healthcare, or similarly sensitive and regulated environment; law firm or professional services experience is strongly preferred.
- Experience developing and operating enterprise security capabilities across Microsoft 365, Azure, Entra ID, cloud applications, email, endpoints, networks, data, APIs, and third-party services, using platforms such as ReliaQuest, Proofpoint, Abnormal Security, Netskope, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Microsoft Intune.
- Experience evaluating the security, privacy, compliance, and operational impact of AI and AI-enabled applications.
- Experience governing OAuth applications, Microsoft Graph permissions, enterprise application registrations, privileged and workload identities, certificates, service accounts, secrets, and role-based access controls.
- Experience leading incident response, vendor assessments, remediation efforts, client and ISO audits, security awareness initiatives, and executive risk reporting.
- Experience applying ISO/IEC 27001, ISO/IEC 27002, the NIST Cybersecurity Framework, the NIST AI Risk Management Framework, CIS Controls, and Zero Trust principles.
- Experience managing security teams and providers, budgets, contracts, implementation projects, and service levels.
- DC/CHI/LA: $231,000 to $318,000 per year.
- NYC: $270,000 to $371,000 per year
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Director of Information Security in New York, NY vacancy
$136.5k - $350k
...We’re seeking a future team member for the role of Senior Director of Network Security - Engineering Lead to join our Network Security team.... ...required; advanced degree preferred15+ years of experience in information security or related technology experience required;...SuggestedTemporary workWork experience placementRemote workWorldwideFlexible hours- Zillow Group is seeking a Director of Information Security to drive strategy across Application Security and Security Architecture. This leadership role requires a hands-on background in security engineering and software development, with the ability to recruit senior...SuggestedRemote job
$144.25k - $256.25k
...customer experience every day. At the heart of this mission is our Information Security organization, enabling exceptional experiences built on a... ...future of a Fortune 100 company.Trust. Service. Security.Director, Cybersecurity provides leadership and guidance to senior...SuggestedVisa sponsorship$200k - $240k
Overview Director of Cloud-Native Security Operations - 245347 Medix is seeking a Director of Cloud-Native Security Operations for one of our top... ...Response (SOAR) practices Leveraging data from Security Information and Event Management (SIEM) platforms to drive proactive...SuggestedHourly payFull timeContract workRemote workShift work- ...Overview The Director of Security will be responsible for overseeing all security operations of a Class A commercial building. This position... ...on appropriate QPS documents and preserve all evidence/information including, but not limited to, records, witness statements,...SuggestedPermanent employmentFull timeFor contractorsWork at officeShift work
- ...SWIFT , alongside FX, treasury management, and bank-issued stablecoin capabilities. Seeking a hands-on Head of Security to build and lead the company's information security function from the ground up. This is a founding-team-level role with significant ownership and...Full timeContract work
$75k - $85k
...illness, some dually with chemical addictions as well. Position Director of Security & Operations Reports To: Vice President Location: Brooklyn,... ...security and privacy of individually identifiable health information. Understand all aspects of contract requirements and...Permanent employmentFull timeContract workImmediate start$170k - $210k
A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy. This role involves leading a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance....$205k - $230k
...Role overview The Director of Security Operations leads the day-to-day cybersecurity operations function across traditional and AI-enabled environments. Reporting to the Chief Information Security Officer, this hands-on technical leadership role partners closely with...Full timeFlexible hours- ...We're looking for a highly technical Security Engineering leader to join a world-leading quantitative investment firm in New York, operating in an environment with an exceptionally high engineering bar and some of the strongest technical talent in the market. We're...Full timeWork at officeRelocation
- DescriptionCompany Overviewiboss is a cloud security company that enables the modern... ...more, visit .Job DescriptionThe Manager of Information Security & Compliance is a key leadership... ...protecting information systems and data. The Director of Information Security & Compliance...
- ...Head of Information Security About the Company Innovative cloud technology provider specializing in regulatory solutions for the healthcare industry Industry Computer Software Type Privately Held Founded 2025 Employees 51-200 Specialties...
$260k - $275k
...data and research to educate and empower investors. For more information on CoinDesk media and events, please visit [ [coindesk.com]](... ...protect journalistic independence. Reports to: Chief Information Security Officer About the Role We are looking for an exceptional...Full timeContract workWork at office$77.36k - $87.36k
...Job Description Job Description ARROW SECURITY is one of the largest privately held... ...mission focus we are looking to add a Director of Security to support one of our prestigious... ..., national origin, disability, genetic information, pregnancy, or any other protected...Local area$215k - $290k
Head of Information Security Risk - Chief Risk Office Location New York Business Area Legal, Compliance, and Risk Ref # 1... ...to senior leadership committees, internal audit, Board of Directors, and regulatory bodies as required. * Act as a strategic thought...Temporary workFor contractorsWork experience placementWork at office- United States Digital Space LLC is seeking a Director of Security Compliance and Trust to lead governance, risk and compliance across ISO 27001/27701, SOC 1/2, PCI DSS and FedRAMP. You will drive privacy, data protection and AI governance while partnering with Legal, Engineering...
- VikingCloud seeks a Director, Product Manager for Managed Security Services to lead the GTM strategy, revenue growth, and market positioning for the MSS and endpoint security portfolios. This senior role engages with customers, partners, and internal teams to drive commercial...
- McAfee seeks a visionary Director of Product Management for Web Protection & Browser Security to shape strategy, roadmap, and execution across Web Advisor and browser-based protections. This hybrid role requires leadership across engineering, design, threat research, and...
- AccorHotel in New York City seeks a Security & Safety Director to lead protective services for a luxury property. You will oversee training, policy implementation, investigations, and day-to-day safety operations to ensure exceptional guest experiences. Ideal candidates...Afternoon shift
- Everforth ECS seeks a Director of Security Operations to lead SOC analysts, detection engineers, and cyber threat intelligence teams in a remote, senior leadership role. You will define security operations strategy, maintain service delivery across customer and enterprise...Remote job
$225k - $337.5k
SVP, Head of Cyber & Information Security OversightWhy this role is important to usEnterprise Technology Risk Management (ETRM) is responsible... ..., Group CRO, regional CROs and the State Street Board of Directors to manage Cyber Risk adequately.Strong Executive Presence:...Full timeTemporary workFlexible hours$80k - $90k
...socialization, and other support services . Position: Program Director of Security and Operations Reports To: Vice President of Security and... ...security and privacy of individually identifiable health information. Immediately report to the appropriate Vice-President/...Permanent employmentFull timeWork at officeImmediate start$275k - $315k
...Counsel & Strategic Partnerships, the Vice President, Head of Privacy (Privacy, Cyber Security, Consumer Compliance) is responsible for all legal aspects of data privacy, information security, and consumer marketing and subscriptions-related compliance across the company...Work at officeLocal areaFlexible hours3 days per week$250k - $350k
...Director of Engineering (AI Security) New York,NY, US Job Description Experience: Senior Level Salary: $250,000 - $350,000 per year Job Details What You'll Do Lead multiple engineering teams and provide leadership and mentorship to Engineering Managers...Remote workFlexible hours$110k - $125k
...New York Institutional Commodity Services Corp. (ICS) Director of Building Operations and Security Position Summary The Director of Building Operations... ...records, inventories, floor plans, equipment information, warranties, and departmental databases. Coordinate with...Contract workFor contractorsWork at officeRelocationWeekend work$109.37k - $123.04k
...skilled and motivated Senior Manager, IT Security Operations to join our team. As the... ...integrity and confidentiality of sensitive information, and maintaining the overall security posture... ...with Chief Technology Officer, Senior Director of Information Technology, and Virtual...Full timeWork experience placementWork at officeLocal areaRemote work$200k - $250k
...partnerships, our client is seeking a sharp, execution-focused Head of Security & Risk. This is a foundational, individual contributor (IC)... ...position, the Head of Security & Risk will build and own the information security and enterprise risk management functions from the...Full timeContract workRemote workFlexible hours$250k - $330k
...and for your life outside it. Our employee NPS sits in the high 80s. We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire. About the role You’ll be our first Head of...Remote workWorldwideShift work- ...We're partnering with Quant , a global leader in digital transformation and technology solutions, seeking a Head of Security to join their team. Securing a chain platform that moves regulated money is not the same problem as securing an enterprise. The Clearing House...Immediate start
- ...technical skills. You can read code, reason about modern cloud architectures (AWS, Kubernetes), threat-model real systems, and ship security tooling yourself when the moment calls for it Experience in running a security program at a fintech, trading firm, or financial...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!
Related searches
- director of security New York, NY
- head of security New York, NY
- director of corporate security New York, NY
- chief security officer New York, NY
- senior director information security New York, NY
- director information security New York, NY
- information security compliance analyst New York, NY
- sr information security engineer New York, NY
- data center security officer New York, NY
- information technology security engineer New York, NY




