Chief Information Security Officer
DLA Piper is a bold, exceptional, collaborative, and supportive firm where our people are the backbone, heart, and soul. This role offers the opportunity to engage in meaningful work and grow your career in a dynamic, global professional services environment.
About the role
The Chief Information Security Officer (CISO) is a senior executive responsible for protecting DLA Piper’s clients, people, data, reputation, and global business operations. This role leads a mature, business-aligned information security and cyber risk program, setting the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response, third-party security, data protection, and security awareness programs. The CISO serves as a trusted advisor to firm leadership, the Office of General Counsel, Information Technology, Information Governance, Risk Management, practice leadership, and global counterparts, ensuring the confidentiality, integrity, and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience, and exceptional client service.
The CISO operates independently from the Information Technology function to provide objective risk oversight, policy leadership, executive reporting, and continuous improvement of the firm’s security posture.
Location
This position can be based in our Atlanta, Baltimore, Boston, Miami, New York, Northern Virginia, Philadelphia, Raleigh, Short Hills, Washington D.C., or Wilmington office. Candidates must reside within a reasonable commuting distance of their assigned office and be available for periodic travel.
Responsibilities
- Set and execute the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations, and operational resilience objectives.
- Lead the firm’s Information Security Management System and security governance framework, including policy development, risk assessment, control monitoring, executive reporting, audit readiness, certification support, and continuous improvement.
- Serve as the senior incident response leader for information security events, ensuring prompt triage, containment, investigation, evidence preservation, root-cause analysis, remediation, lessons learned, and coordination with the Office of General Counsel, firm leadership, insurers, regulators, law enforcement, vendors, and affected clients when required.
- Partner with executive leadership, Information Technology, AI Innovation, AI Governance, Information Governance, Risk Management, Privacy, Procurement, Finance, Human Resources, practice leaders, and global counterparts to embed security-by-design into firm operations, technology investments, client service delivery, and major transformation initiatives.
- Provide objective cyber risk advice to firm leadership and governance bodies, translating complex technical risk into clear business, legal, reputational, operational, and client-impact terms that enable timely and informed decision-making.
- Oversee enterprise cyber risk identification, assessment, treatment, acceptance, and reporting, including vulnerabilities, threat intelligence, identity and access risk, cloud and infrastructure security, application security, data loss prevention, endpoint protection, email security, ransomware preparedness, and business continuity dependencies.
- Lead security oversight of client and firm confidential information, including data classification, access controls, encryption, retention, secure disposal, cross-border data considerations, ethical walls, client outside counsel guidelines, and matter-specific security obligations.
- Direct third-party and supplier security risk management in partnership with Procurement, Information Technology, Information Governance, and business owners, ensuring vendors that access firm or client data are assessed, monitored, and held to appropriate security, privacy, contractual, and operational standards.
- Guide security review and risk oversight for emerging technologies, cloud services, legal technology, artificial intelligence, automation, analytics, and internally developed tools, ensuring innovation is deployed responsibly and in compliance with firm policies, client requirements, and applicable legal and ethical obligations.
- Build, develop, and lead a high-performing information security organization with the expertise, credibility, accountability, and service orientation required to support a complex, global, partner-led professional services environment.
- Define and manage the Information Security team’s operating model, including functional roles, accountability structures, governance routines, service levels, intake and prioritization processes, escalation protocols, on-call expectations, and coordination with Information Technology, Risk, Information Governance, Privacy, Procurement, Human Resources, and practice leadership.
- Recruit, develop, coach, and retain a high-caliber Information Security team with the technical depth, risk judgment, executive presence, discretion, and client-service mindset required to operate effectively in a global law firm environment.
- Set clear goals and performance expectations for the Information Security team, regularly assess performance against strategic objectives and operational metrics, address performance gaps, recognize strong contributions, and ensure the team has the training, tools, resources, and authority needed to execute effectively.
- Provide strategic, operational, and people leadership to the Information Security function, including direct and indirect leadership of security professionals, managers, analysts, advisors, vendors, and cross-functional contributors.
- Define the team’s vision, operating model, service standards, decision rights, escalation paths, and priorities to ensure the function delivers consistent, timely, risk-based, and business-aligned support across the firm. Build a culture of accountability, confidentiality, trust, excellence, service orientation, continuous improvement, inclusion, and business partnership.
- Responsible for onboarding, coaching, performance management, succession planning, professional development, retention, resource allocation, budget input, vendor oversight, and effective delegation across the security program.
Qualifications
- Bachelor’s Degree in Information Security, Cybersecurity, Information Technology, Computer Science, Engineering, Business, Risk Management, Law, or a related field; equivalent senior leadership experience may be considered where appropriate.
- Master’s Degree in MBA, M.S. in Cybersecurity/Information Security, J.D., or other relevant advanced degree preferred.
- 15+ years’ progressive information security, cybersecurity, technology risk, privacy, compliance, or enterprise risk leadership experience, including significant executive-level responsibility for a complex, highly regulated, client-facing organization.
Skills
- Deep technical engineering expertise in technology infrastructure, Cloud, zero-trust architecture, and cyber defense. Proven ability to leverage frameworks like NIST to build and operate a comprehensive defense-in-depth capability.
- Proven ability in change management, building trust with partners, and transforming organizations.
- Experience in a global law firm, professional services firm, financial services institution, technology company, or similarly complex environment strongly preferred.
- Demonstrated success leading cybersecurity strategy, enterprise risk governance, incident response, regulatory and client-facing security matters, third-party risk, audit/certification programs, security awareness, and high-performing teams.
- Experience advising senior executives, boards, managing partners, or equivalent governance bodies required.
- Executive-level knowledge of cybersecurity strategy, governance, risk, compliance, privacy, data protection, incident response, threat intelligence, vulnerability management, identity and access management, cloud and network security, application security, endpoint protection, email security, encryption, logging and monitoring, disaster recovery, business continuity, third-party risk, DevSecOps, modernized secure development practices including AI SDLC, and secure technology adoption.
- Strong understanding of professional responsibility, client confidentiality, data classification, privilege-sensitive work, outside counsel guidelines, ethical walls, cross-border data considerations, and the security expectations of sophisticated global clients.
- Demonstrated ability to translate technical risk into business and legal impact, influence senior stakeholders, lead through ambiguity, make sound risk-based decisions, and communicate with clarity, credibility, discretion, and urgency.
- Familiarity with ISO/IEC 27001, NIST, CIS Controls, data privacy laws, cyber insurance considerations, AI governance, and emerging legal sector cybersecurity risks strongly preferred.
- A leader who thrives on learning and stays current with the fast-evolving technology landscape, especially the changing threats associated with the advancement of AI.
- Ability to understand security tools and needs, how these are evolving, and to apply first principles in solving underlying problems through innovation.
- Demonstrate executive presence, credibility, sound judgment, and professional maturity in all interactions, particularly when advising firm leadership, senior partners, governance bodies, clients, regulators, vendors, and other high-impact stakeholders on sensitive, complex, or time-critical information security matters.
- Communicate with clarity, confidence, discretion, and appropriate urgency, translating complex technical, legal, operational, and risk issues into concise business terms that enable informed decisions by senior leaders and non-technical audiences.
- Influence senior leaders and stakeholders through trusted relationships, fact-based analysis, persuasive recommendations, and a firm-first approach that balances client expectations, legal and regulatory obligations, operational realities, risk appetite, and strategic business priorities.
- Build alignment across a complex, matrixed, partner-led environment by listening effectively, anticipating concerns, managing competing perspectives, escalating appropriately, and helping leaders reach timely, defensible, and consistently supported decisions.
- Prepare and deliver executive-level briefings, written updates, risk narratives, Executive Committee materials, client-facing responses, and incident communications that are accurate, audience-appropriate, concise, and aligned with firm standards and confidentiality obligations.
- Lead difficult or sensitive conversations with diplomacy, composure, courage, and empathy, including situations involving cyber incidents, policy exceptions, risk acceptance, resource tradeoffs, control gaps, or competing leadership priorities.
Certificates
Relevant professional certifications are strongly preferred, such as CISSP, CISM, CISA, CRISC, CCISO, GIAC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or comparable credentials. Demonstrated ongoing professional development in cybersecurity, privacy, risk governance, incident response, cloud security, AI governance, and legal/professional services risk is expected.