Director of IT Security & Risk Management - Philadelphia

Dechert LLP
Philadelphia, PA, United States
about 2 months ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cyber Security Databases Information Security Management Cloud Services Security Support Provider Interface Virtualization Technology Enterprise Data Management Computer Network Technologies

Job description

The Director of Information Security is responsible for leading the firm’s global information security program and advancing a comprehensive, risk-based security strategy aligned with the firm’s business objectives, client obligations, and regulatory requirements. Reporting to the Chief Information and AI Officer, this role provides strategic and operational leadership across cybersecurity governance, risk management, security operations, incident response, security architecture, awareness, compliance, and third-party security. This leader partners closely with firm leadership, business services, technology teams, legal and risk stakeholders, and external partners to safeguard the confidentiality, integrity, and availability of the firm’s information assets, systems, and services. This role ensures security is embedded across the enterprise while enabling the business, protecting client trust, and supporting resilience in a complex global threat and regulatory environment. Security Strategy and Leadership

  • Lead the firm’s global information security program and develop a forward-looking security strategy aligned with business priorities, client expectations, and enterprise risk tolerance.
  • Serve as a trusted advisor to the CIO and firm leadership on cyber risk, security posture, investment priorities, and emerging threats.
  • Establish and maintain an effective security operating model that supports both day-to-day protection and long-term program maturity.
  • Manage the information security budget, resource planning, and program roadmap.

Governance, Risk, and Compliance

  • Design and maintain a cybersecurity governance framework, including appropriate steering committees, reporting structures, and decision-making forums.
  • Develop, implement, and maintain security policies, standards, procedures, and guidelines across the firm.
  • Create and manage a unified, risk-based control framework that supports legal, regulatory, contractual, and client-driven requirements across jurisdictions.
  • Partner with stakeholders across IT, General Counsel, Privacy, Procurement, and Business Continuity to ensure alignment and consistent application of security controls.
  • Support firm-wide risk assessments and advise leaders on risk mitigation strategies within the firm’s risk appetite

Security Operations and Incident Response

  • Oversee the firm’s ability to identify, detect, respond to, manage, and recover from cybersecurity incidents.
  • Lead the development, maintenance, and testing of incident response plans, playbooks, and procedures.
  • Monitor the external threat environment and advise stakeholders on relevant threats, vulnerabilities, and mitigation actions.
  • Help ensure business-critical services are resilient and recoverable in the event of a security incident.
  • Partner with technology teams to ensure security controls are effective across infrastructure, cloud platforms, applications, networks, endpoints, identity, and data.

Security Enablement and Architecture

  • Ensure security is embedded into projects, system implementations, operational processes, and technology change initiatives.
  • Evaluate and implement modern security technologies and practices to strengthen the firm’s capabilities and improve operational maturity.
  • Help establish standards and baseline controls across the firm’s technology environment.
  • Support development and maintenance of asset inventories, including cloud services, third-party hosted systems, and critical information assets.

Client, Vendor, and Commercial Security Support

  • Partner with Procurement and General Counsel to ensure appropriate information security and data protection provisions are included in vendor and third-party contracts.
  • Support responses to client security assessments, outside counsel guidelines, audits, RFPs, and security due diligence requests.
  • Help define and maintain the standards, controls, and assurance practices necessary to meet firm and client expectations.
  • Build and maintain relationships with external peers, partners, vendors, and industry groups to stay informed on trends, incidents, and best practices.

Security Awareness and Team Leadership

  • Lead the firm’s security awareness and training program for employees, contractors, and approved system users.
  • Establish meaningful security metrics and reporting to measure effectiveness, identify trends, and support decision-making.
  • Recruit, develop, and retain a high-performing and diverse team of information security professionals.
  • Foster a strong culture of accountability, collaboration, and continuous improvement across the security function and broader organization.

Requirements

  • Knowledge and experience with enterprise data centers, network technologies, virtualization, unified communication, mobility
  • Experience and knowledge of common security, standards and risk frameworks
  • Knowledge of enterprise architecture and security architecture
  • Understanding of common commercial development and database technologies
  • Experience in developing and managing a security governance program
  • Ability to operate independently and collaborate in teams to achieve desired outcomes
  • Self motivated and highly productive
  • Strong written and verbal communication skills

Required

  • Relevant BS / BA degree
  • 10+ years of experience in Information Security including 5+ years in a Security leadership role

Desired

  • Industry recognized security certifications (CISSP, CISA, CISM)
  • Legal industry knowledge and/or awareness
  • Project management, budget and forecast experience

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:41 min

Transitioning artificial intelligence infrastructure into scalable commodity cloud services

juarezjunior juarezjunior · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all