Our Client, an American multinational law firm, is seeking a Director of Cybersecurity.
Location: New York, NY
Position Type: Full-Time/Perm
Schedule: Hybrid Role, 2-3 days in office
Job Summary:
• The Director of Cybersecurity is responsible for developing security strategies, incident response protocols, and enhancing proactive measures to ensure strong Cybersecurity practices.
• This role involves implementing measures to monitor threats, swiftly respond to incidents, and continuously improve data protections against cyber threats.
Duties and Responsibilities:
Cybersecurity Strategy:
• Establish enterprise security monitoring program to drive continuous improvements aimed at cyber events and incident detection, containment, and remediation.
• Develop standard operating procedures to improve security operations and response capabilities and meet global compliance standards.
• Integrate threat intelligence sources into security operations to enhance threat detection and response capabilities, leveraging both internal and external sources to stay abreast of evolving cyber threats.
Incident Response:
• Lead incident response team to develop and support 24x7x365 incident response capabilities, including defining response procedures.
• Receive escalations/notifications of cybersecurity and business impacting events and appropriately triage, ensure that leadership is kept informed through regular communication as appropriate, and that necessary personnel for managing an incident respond effectively.
Team Management:
• Support and oversee cyber event response activities as the most senior escalation point on the Security Operations team.
• Function as a cybersecurity subject matter expert who can stand on their own to deliver work and represent the team as well as lead their team to success through delegation.
• Lead development and tracking of key performance indicators (KPIs) related to cybersecurity operations, to benchmark and further enhance capabilities.
Qualifications:
• Bachelor's degree required; advanced degree and CISSP certification preferred.
• In-depth knowledge of information security frameworks, best practices, and administrative, physical, and technical safeguards, with experience in common security frameworks such as NIST preferred.
• Minimum of 10+ years of experience developing infrastructure and security programs, implementing and managing security solutions, and leading security teams in incident response.
• Strong technical background and expertise in network and systems security, system and network configuration, and application security.
• Proficiency in incident response management, next-generation firewalls, web application firewalls, multi-factor authentication, data loss prevention, and disaster recovery.
• Hands-on experience with Security Incident and Event Management (SIEM) tools, Endpoint Detection and Response (EDR) tools, vulnerability management suites, and various security solutions.
• Experience working with and implementing NIST, ITIL, and ISO 27001 standards.
• Working knowledge of regulatory data governance obligations, such as EU/UK GDPR, HIPAA/HITECH, ITAR/EAR, and CUI a plus.
• Prior Legal industry experience would be a big plus
Salary: $200-250K base + bonus