Chief Information Security Officer
Jobleads-US
DLA Piper is, at its core, bold, exceptional, collaborative and supportive. Our people are the backbone, heart and soul of our firm. Wherever you are in your professional journey, DLA Piper is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.
Summary
The Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive responsible for protecting DLA Piper's clients, people, data, reputation and global business operations by leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response, third-party security, data protection and security awareness programs. Operating as a trusted advisor to firm leadership, the Office of General Counsel, Information Technology, Information Governance, Risk Management, practice leadership, and global counterparts, the CISO ensures the confidentiality, integrity and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience and exceptional client service. The CISO works closely with, but independently from, the Information Technology function to provide objective risk oversight, policy leadership, executive reporting and continuous improvement of the firm’s security posture.
Location
This position can sit in our Atlanta, Baltimore, Boston, Miami, New York, Northern Virginia, Philadelphia, Raleigh, Short Hills, Washington D.C. or Wilmington office. Candidates must reside within a reasonable commuting distance of their assigned office and be available for periodic travel.
Responsibilities
- Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations and operational resilience objectives.
- Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations and operational resilience objectives.
- Leads the firm’s Information Security Management System and security governance framework, including policy development, risk assessment, control monitoring, executive reporting, audit readiness, certification support and continuous improvement.
- Serves as the senior incident response leader for information security events, ensuring prompt triage, containment, investigation, evidence preservation, root-cause analysis, remediation, lessons learned and appropriate coordination with the Office of General Counsel, firm leadership, insurers, regulators, law enforcement, vendors and affected clients when required.
- Partners with executive leadership, Information Technology, AI Innovation, AI Governance, Information Governance, Risk Management, Privacy, Procurement, Finance, Human Resources, practice leaders and global counterparts to embed security-by-design into firm operations, technology investments, client service delivery and major transformation initiatives.
- Provides objective cyber risk advice to firm leadership and governance bodies, translating complex technical risk into clear business, legal, reputational, operational and client-impact terms that enable timely and informed decision-making.
- Oversees enterprise cyber risk identification, assessment, treatment, acceptance and reporting, including vulnerabilities, threat intelligence, identity and access risk, cloud and infrastructure security, application security, data loss prevention, endpoint protection, email security, ransomware preparedness and business continuity dependencies.
- Leads security oversight of client and firm confidential information, including data classification, access controls, encryption, retention, secure disposal, cross-border data considerations, ethical walls, client outside counsel guidelines and matter-specific security obligations.
- Directs third-party and supplier security risk management in partnership with Procurement, Information Technology, Information Governance and business owners, ensuring vendors that access firm or client data are assessed, monitored and held to appropriate security, privacy, contractual and operational standards.
- Guides security review and risk oversight for emerging technologies, cloud services, legal technology, artificial intelligence, automation, analytics and internally developed tools, ensuring innovation is deployed responsibly and in compliance with firm policies, client requirements and applicable legal and ethical obligations.
- Builds, develops and leads a high-performing information security organization with the expertise, credibility, accountability and service orientation required to support a complex, global, partner led professional services environment.
- Defines and manages the Information Security team’s operating model, including functional roles, accountability structures, governance routines, service levels, intake and prioritization processes, escalation protocols, on-call expectations and coordination with Information Technology, Risk, Information Governance, Privacy, Procurement, Human Resources and practice leadership.
- Recruits, develops, coaches and retains a high-caliber Information Security team with the technical depth, risk judgment, executive presence, discretion and client-service mindset required to operate effectively in a global law firm environment.
- Sets clear goals and performance expectations for the Information Security team, regularly assesses performance against strategic objectives and operational metrics, addresses performance gaps, recognizes strong contributions and ensures the team has the training, tools, resources and authority needed to execute effectively.
- Provides strategic, operational and people leadership to the Information Security function, including direct and indirect leadership of security professionals, managers, analysts, advisors, vendors and cross-functional contributors.
- Defines the team’s vision, operating model, service standards, decision rights, escalation paths and priorities to ensure the function delivers consistent, timely, risk-based and business-aligned support across the firm. Builds a culture of accountability, confidentiality trust excellence service orientation continuous improvement inclusion and business partnership.
- Responsible for onboarding, coaching, performance management, succession planning, professional development, retention, resource allocation, budget input, vendor oversight and effective delegation across the security program.
Desired Skills
Deep technical engineering expertise in technology infrastructure, Cloud, zero-trust architecture and cyber defense. Proven ability to leverage frameworks like NIST to build and operate a comprehensive defense in depth capability. Proven ability in change management, building trust with partners and transforming organizations. Experience in a global law firm, professional services firm, financial services institution, technology company or similarly complex environment strongly preferred. Demonstrated success leading cybersecurity strategy, enterprise risk governance, incident response, regulatory and client-facing security matters, third-party risk, audit/certification programs, security awareness and high performing teams. Experience advising senior executives, boards, managing partners or equivalent governance bodies required. Executive-level knowledge of cybersecurity strategy governance risk compliance privacy data protection incident response threat intelligence vulnerability management identity and access management cloud and network security application security endpoint protection email security encryption logging and monitoring disaster recovery business continuity third-party risk DevSecOps modernized secure development practices including AI SDLC and secure technology adoption. Strong understanding of professional responsibility client confidentiality data classification privilege-sensitive work outside counsel guidelines ethical walls cross-border data considerations and the security expectations of sophisticated global clients. Demonstrated ability to translate technical risk into business and legal impact influence senior stakeholders lead through ambiguity make sound risk-based decisions and communicate with clarity credibility discretion and urgency. Familiarity with ISO/IEC 27001 NIST CIS Controls data privacy laws cyber insurance considerations AI governance and emerging legal sector cybersecurity risks strongly preferred. A leader who thrives on learning and is up to date with the fast-evolving technology landscape especially the changing threats with the advancement of AI. Ability to not only understand security tools needs how these are changing but also go back to first principles in solving the underlying problems through innovation. Demonstrate executive presence credibility sound judgment and professional maturity in all interactions particularly when advising firm leadership senior partners governance bodies clients regulators vendors and other high-impact stakeholders on sensitive complex or time-critical information security matters. Communicate with clarity confidence discretion and appropriate urgency translating complex technical legal operational and risk issues into concise business terms that enable informed decisions by senior leaders and non-technical audiences. Influence senior leaders and stakeholders through trusted relationships fact-based analysis persuasive recommendations and a firm-first approach that balances client expectations legal and regulatory obligations operational realities risk appetite and strategic business priorities. Build alignment across a complex matrixed partner-led environment by listening effectively anticipating concerns managing competing perspectives escalating appropriately and helping leaders reach timely defensible and consistently supported decisions. Prepare and deliver executive-level briefings written updates risk narratives Executive Committee materials client-facing responses and incident communications that are accurate audience-appropriate concise and aligned with firm standards and confidentiality obligations. Lead difficult or sensitive conversations with diplomacy composure courage and empathy including situations involving cyber incidents policy exceptions risk acceptance resource tradeoffs control gaps or competing leadership priorities.
Minimum Education
- Bachelor's Degree in Information Security, Cybersecurity, Information Technology, Computer Science, Engineering, Business, Risk Management, Law or a related field; equivalent senior leadership experience may be considered, where appropriate.
Preferred Education
- Master's Degree in MBA, M.S. in Cybersecurity/Information Security, J.D. or other relevant advanced degree preferred.
Certificates
- Relevant professional certifications are strongly preferred, such as CISSP, CISM, CISA, CRISC, CCISO, GIAC ISO/IEC 27001 Lead Implementer or Lead Auditor or comparable credentials. Demonstrated ongoing professional development in cybersecurity privacy risk governance incident response cloud security AI governance and legal/professional services risk is expected.
Minimum Years Of Experience
- 15+ years' progressive information security cybersecurity technology risk privacy compliance or enterprise risk leadership experience including significant executive-level responsibility for a complex highly regulated client-facing organization.
Essential Job Expectations
All DLA Piper employees are expected to demonstrate excellence in how we serve our clients and develop our people, upholding our firm values as part of our culture. Specific expectations include:
- Communicate effectively, both verbally and in writing, with clients lawyers business professionals and external audiences.
- Produce high-quality work and respond to correspondence in an efficient timely and professional manner.
- Meet deadlines manage competing priorities and commit to meeting high standards.
- Comply with firm policies and procedures.
- Maintain confidences as required in a law firm environment.
Physical Demands
Sedentary work: This is primarily sedentary work requiring occasional exertion of up to 10 pounds of force to lift carry push pull or move objects. The role involves sitting for extended periods with occasional walking and standing and occasional travel both domestic and international.
Work Environment
The individual selected for this position may have the opportunity for a hybrid work arrangement combining remote and in-office work. The specific arrangement will be determined at the time of hiring and may be modified at the firm’s discretion.
Disclaimer
The purpose of this job description is to provide a concise statement of the work elements and to organize and present the information in a standardized way. It is not intended to describe all the elements of the work that may be performed by every individual in this classification nor should it serve as the sole criteria for personnel decisions and actions. The job duties requirements and expectations for this position may be modified at the firm’s discretion at any time. This job description does not change the at-will nature of employment.
No immigration sponsorship is available for this position.
This job description provides a concise overview of the role and is not intended to describe all work elements that may be performed. It should not serve as the sole criteria for personnel decisions. Job duties requirements and expectations may be modified at the firm’s discretion at any time. This job description does not alter the at-will nature of employment.
We are committed to excellence in how we serve our clients and develop our people.
The firm’s expected hiring range for this position is $550,000 - $650,000 per year depending on the candidate’s geographic market location.
The compensation offered for employment will also be dependent on other factors including the candidate’s experience skills educational and professional background and overall qualifications. We offer a comprehensive package of benefits including medical/dental/vision insurance and 401(k).
Applicants who are not based in the jurisdiction in which this position is posted and who apply for this role are doing so voluntarily and are not eligible for relocation assistance. Any relocation benefits if any are provided only where a relocation is required at the firm’s direction and in accordance with applicable policy and law.
DLA Piper is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability or status as a protected veteran.
#J-18808-Ljbffr Jobleads-US- ...Description Job Title: Network and security Admin Location: Herndon, Virginia... ...practices. ~ Proficient in Microsoft Office, particularly Word, Excel, VISIO and... ...production environment Additional Information All your information will be kept confidential...SuggestedFull timeContract workWork at office
- ...Information System Security Officer Conducts assessments of threats and vulnerabilities, determines deviations from acceptable configurations or enterprise or local policy, assesses the level of risk, and develops and/or recommends appropriate mitigation countermeasures...SuggestedPermanent employmentInterim roleCasual workLocal area
- ...Information System Security Officer Base-2 Solutions is seeking an Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve...Suggested
$120.8k - $265.8k
...Job Title: Information Systems Security Officer (ISSO) Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: Secret Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Local * * *...SuggestedFull timeContract workWork experience placementWork at officeLocal areaFlexible hours- ...Information System Security Officer (ISSO) The Information System Security Officer (ISSO) is responsible for maintaining the security posture and authorization of the system. You will manage the Risk Management Framework (RMF) lifecycle, maintain ATO documentation and...SuggestedFor contractorsFlexible hours
- ...Information Systems Security Officer (ISSO) Reston, VA About Metron Metron is an employee-owned company dedicated to delivering innovative solutions for the most challenging national security problems. For over 40 years, our principled approach to problem-solving...For contractors
$99k - $225k
...Information System Security Officer The Opportunity: We're looking for an Information System Security Officer (ISSO) who can create solutions for the government that will withstand even the most advanced cyber threats. As a cyber tools assessor at Booz Allen, you...Full timeContract workPart timeFor subcontractorWork at officeLocal areaRemote work- ...mental health centers nationwide.Position SummaryCenturion is seeking an experienced, strategic, and execution-oriented Chief Information Security Officer (CISO)to lead and mature our enterprise security program across a complex, multi-state healthcare environment. This...
- ...Information Systems Security Officer (ISSO) Mantis Security is seeking for immediate placement a highly qualified and technical Information Systems Security Officer (ISSO) to lead the Assessment and Authorization (A&A) for multiple analytic mission systems. The ISSO...Immediate start
- ...Engineer serves as a subject matter expert in ensuring system security compliance and risk management throughout the program life cycle... ...Ability to work full-time onsite in a Sensitive Compartmented Information Facility (SCIF) with flexible hours. Desired Attributes:...Full timeInterim roleFlexible hours
- ...Enterprise IT Infrastructure (EII) to advance DoD Intelligence Information Systems (DoDIIS) Enterprise capabilities and functions. *... ...procedures. Interface with other IA team members, other security disciplines (industrial security, physical security, special programs...Contract workTemporary workWorldwideFlexible hours
- ...Information Systems Security Officer (ISSO) LOCATION Reston, VA 20190 CLEARANCE TS/SCI Full Poly (Please note this position requires full U.S. Citizenship) KEY SUMMARY We are seeking a dedicated and detail-oriented **Information Systems Security...Temporary workFor contractorsImmediate startFlexible hours
$82.3k - $220k
...that inspires the cross-fertilization of ideas necessary for true innovation. For more information about Draper, visit .Job Description Summary:The Information System Security Officer 2 (ISSO) supports the continuous monitoring and authorization efforts of multiple...Full timeLocal area- ...Chief Information Security Officer (CISO) About the Company Global provider of healthcare services to governmental agencies Industry Hospital & Health Care Type Government Agency Founded 2010 Employees 10,001+ Categories Health Care B...
- ...Senior Information Systems Security Officer (ISSO) Location: Annapolis, MD / Reston, VA / Washington, DC Work Model: 100% Onsite (SCIF Environment) Work Type: Full-Time Experience Required: 13+ Years The Senior ISSO will support mission-critical cybersecurity initiatives...Full time
$140k - $190k
...foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests. Title : Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP) Clearance : Active Top Secret with SCI eligibility...Temporary workImmediate startRemote workRelocation packageDay shift- ...Senior Information Systems Security Officer Base-2 Solutions is seeking a Senior Information Systems Security Officer responsible for safeguarding computer networks and systems to ensure data security, integrity, and confidentiality at the highest standards. Essential...
$86.8k - $198k
...adversarial tactics to conduct hands-on security testing ~3+ years of experience performing... ...Bachelor's degree in CS, Information Systems, Engineering, or a relatedfield... ...primarily be performed at a Booz Allen office or customer facility, where employees will...Full timeContract workPart timeWork at officeLocal areaRemote work- ...client. If you're passionate about offensive cybersecurity, identifying vulnerabilities before adversaries do, and protecting national security systems, we'd like to speak with you. As a Penetration Tester, you will perform technical security assessments against customer...
$140k - $160k
...Job Description Job Description Dark Wolf is seeking an I nformation System Security Officer (ISSO) to lead a collaborative team to develop, manage, and maintain information system security Assessment and Authorization (A&A) packages. This could include supporting...Full timeFor contractorsFlexible hours- ...Job Description Job Description Information System Security Officer (ISSO) - SCIF Office Location: Onsite role - Reston, VA Clearance Required: Active TS/SCI with Full Scope Polygraph Number of Positions: 1 Seeking a Information System Security Officer...Work at office
$102k - $178.4k
Amazon Web Services (AWS) Security is seeking an Information System Security Officer (ISSO) to assess, authorize, and continuously defend information systems supporting a high-priority U.S. Government program.In this role, you will develop, maintain, and continuously improve...Flexible hours$160k - $175k
As a MetroStar Sr. Information Systems Security Officer (ISSO) II, your focus will be on Government System Authority to Operate (ATO) support. You will be responsible for guiding government clients through the intricate process of obtaining and maintaining ATO certifications...Full timeLocal area$146k - $234k
...legacy copper infrastructure to modern fiber optic networks and secure cloud connectivity.Work LocationThis position is 100% on-site,... ...'s degree in Telecommunications, Network Engineering, Information Technology, Electrical Engineering, or related field.Certifications...Contract workLocal areaShift work$131.3k - $177.6k
...Services (ProServe) team is seeking a skilled Delivery Consultant - Security to join our team at Amazon Web Services (AWS). In this role,... ...the interview or onboarding process, please visit for more information. If the country/region you’re applying in isn’t listed, please...Flexible hours$168.9k - $244.3k
...lasting positive impact. We serve the Infrastructure; Nuclear, Security & Environmental; Energy; Mining & Metals, and the... ...Manager of Business Engagement, the Cybersecurity Business Information Security Officer - BISO, serves as the primary interface between Bechtel's...16 hoursContract workPart timeFor subcontractorLocal areaRemote workRelocation- ...DLA Piper is seeking a Chief Information Security Officer to lead and mature the firm’s information security program, aligning cyber risk with strategic objectives and client obligations. You will oversee policy, risk assessment, control monitoring and executive reporting...
- ...DLA Piper seeks a Chief Information Security Officer to lead a mature, business-aligned information security program that protects clients, people, data, reputation, and operations globally. Reporting to firm leadership, the CISO will partner with IT, AI governance...
$100k - $150k
...team to design, defend, and continuously evaluate the enterprise security architecture and government accreditation posture for critical... ...~ Experience as a Cyber Analyst, RMF Engineer, ISSO, Information Assurance Engineer, Vulnerability Manager, POA&M Manager ~...Full timeFor contractors$112k - $179k
Responsibilities Job SummaryWe are seeking a highly skilled and technically proficient Information Systems Security Officer (ISSO) with hands-on experience developing, implementing, and validating security controls within DoD RMF environments. This role requires deep...Contract workShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Chief Information Security Officer. Be the first to apply!
- information security officer Reston, VA
- ciso Reston, VA
- chief information security officer ciso Reston, VA
- business information security officer Reston, VA
- information systems security officer Reston, VA
- chief information security officer Reston, VA
- information security Reston, VA
- sr information security engineer Reston, VA
- data center security officer Reston, VA
- information security lead Reston, VA




