Senior Information Security Engineer
About the role
McDermott Will & Emery is a leading global law firm that brings together more than 1,700 lawyers and 1,400 business professionals. We celebrate excellence, collaboration, and community and have been recognized as a top workplace by USA Today, Fortune, The American Lawyer, Vault, and others. We are also certified by Great Place to Work.
The Senior Information Security Engineer oversees the security of the Firm’s applications, networks, and systems. This position manages the security and integrity of the Firm’s information systems throughout their lifecycle, ensures that systems are secure during operations, and serves as a primary technical point of contact for other Firm departments. This position works under minimal supervision and relies on extensive experience and judgment to plan and accomplish goals.
Responsibilities
- Develop and manage security requirements of Firm assets and systems
- Create and maintain the Firm-wide security architecture
- Manage security requirements throughout the development and acquisition lifecycles for all assets
- Perform certification and accreditation prior to releasing software to production
- Develop and maintain software, application, network, hardware, systems, and mobile device inventories
- Define, implement, assess, and maintain controls necessary to protect software, applications, networks, hardware, systems, and mobile devices in accordance with security requirements
- Manage security configuration and changes for software, applications, networks, hardware, systems, and mobile devices
- Develop and maintain information asset inventories and establish and maintain controls necessary to protect information and critical assets
- Collaborate with individuals and teams outside of Information Security
- Mentor and support other team members in day-to-day activities
Requirements
- At least seven (7) years of related work experience
- Experience with or strong aptitude for AI-assisted development tools, LLMs, and agentic AI
- Knowledge of Microsoft Office Suite (Excel, Outlook, PowerPoint, and Word)
- Knowledge of information systems security risk frameworks and server architecture
- Knowledge of network concepts, host-based security settings/controls, and security technologies
- Knowledge of CI/CD concepts/tools and secure code development
- Strong organizational skills
- Strong mathematical and analytical skills
- Ability to work under tight deadlines and prioritize responsibilities
- Ability to handle and maintain confidential information
- Ability to work independently and under own direction and initiative
Pay
Target hiring range: $121,000 - $203,000. Base pay is based on market location and may vary depending on job-related knowledge, skills, experience, and geographic location. Base pay is only one part of the Total Rewards package, which includes a discretionary bonus and a comprehensive benefits package for full-time positions.
Physical Demands and Work Environment
- While performing the duties of this job, the employee is required to sit, use hands, reach with hands and arms, stoop, talk, and hear.
- Employee must occasionally lift up to twenty (20) pounds.
- Typical indoor office environment.