Title:
IT Security Manager
Job Type:
Full-time
Target Start Date:
ASAP
Work Location/Structure:
Washington, DC, hybrid schedule (Tuesday through Thursday), with some travel required (likely 1-2 times a quarter to Boston or Texas, and potentially once or twice a year to London).
About the Opportunity:
Our client, a leader in the Legal Services industry, is looking for a skilled IT Security Manager
to join their team for a permanent engagement. This project involves building out a cybersecurity platform, managing the MSSP, handling incident response, rolling out new procedures, and elevating the overall security program. This is a high-impact role that requires a self-motivated professional who can hit the ground running and deliver results quickly.
Key Responsibilities & Deliverables:
This role is focused on the ongoing development, implementation, and oversight of security initiatives that protect the firm’s systems, data, and client confidentiality. Your responsibilities will include:
-
Building out and enhancing the cybersecurity platform.
-
Managing the Managed Security Service Provider (MSSP).
-
Handling incident response and rolling out new security procedures.
-
Elevating the overall security program to reduce incidents.
-
Acting as an individual contributor with hands-on engineering experience.
-
Collaborating closely with firm leadership, attorneys, and technical teams.
We are looking for someone with a proven track record of successful engagements in information security. The ideal candidate will have:
-
6–10+ years of experience in information security, with at least 3 years in a leadership or architect role.
-
Deep understanding of IT infrastructure, cloud platforms (Microsoft 365, Azure), and legal tech environments (MS Shop, NetDocs).
-
Hands-on engineering experience.
-
Demonstrated ability to work autonomously and manage time effectively to meet project goals.
-
Strong communication and leadership skills; able to work effectively across technical and non-technical teams, including attorneys and general counsel.
-
Experience with legal industry security audits, questionnaires, and compliance requirements.
-
Bachelor’s degree in cybersecurity, information systems, or a related field.
-
Relevant certifications (e.g., CISSP, CISM, CISA, CEH) preferred.
-
Prior experience in a law firm, legal services provider, or other highly regulated environment preferred.
-
Experience taking ownership of a project working with an MSSP.