> Markdown version of [/jobs/ext/1882445-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/1882445-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Morgan & Morgan - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Artificial Intelligence, Data Analysis, Law Practice Management Software, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Zero Trust Network Access, Cloud Platform System, AI Platforms - **Published:** August 2, 2026 - **Apply:** https://www.dice.com/job-detail/4c0821b0-36fb-421a-bfce-49b97719f93d ## About the Role 10+ years in cybersecurity, including senior leadership roles in large, complex environments Proven success leading security programs in high-data-sensitivity, fast-moving organizations Demonstrated ability to communicate cyber risk clearly to executive leadership and Boards Strong working knowledge of: NIST Cybersecurity Framework (CSF) and/or ISO 27001 Zero Trust architecture Incident response and crisis leadership Cloud and SaaS security at scaleExecutive Mindset Business-first approach to security focused on outcomes, not checklists Comfort making tradeo/s and defending decisions at the executive level Calm, credible leadership during high-pressure situations High integrity, sound judgment, and strong ethical foundationPreferred Qualifications CISSP, CISM, or equivalent credentials Experience supporting AI platforms, analytics, or large-scale digital transformation Proven partnership with CIOs, General Counsel, and Compliance leadership Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar) ## Description Security Strategy & Risk Leadership Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment Translate cyber risk into clear business impact for executive leadership and the Board Guide security investment decisions that balance velocity, resilience, and client trustRisk Management & Compliance Lead firm-wide risk assessments, threat modeling, and control maturity evaluations Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning Partner closely with Legal, Privacy, and Compliance leaders to ensure: Protection of sensitive client and case data Defensible security practices suitable for litigation discovery Alignment with regulatory, contractual, and ethical obligations Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology Embed security into: Agile software development and CI/CD pipelines Cloud-native platforms and SaaS ecosystems AI-enabled legal workflows and analytics platforms Implement Zero Trust principles using pragmatic, developer-friendly controls Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys Security Operations Oversee security operations including: Identity & Access Management (IAM) Endpoint, network, and cloud security Security monitoring, detection, and response Continuously improve detection, response time, and operational resilience Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture Build, lead, and mentor a high-caliber, hands-on security organization Establish strong operating models between Security, IT, Engineering, and the business Set clear expectations and a high bar for execution, accountability, and follow-through across the security function Champion a culture where security is designed in early, not bolted on late This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed Act as a visible, trusted executive leader approachable, decisive, and credible ## Related Videos - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [This App Reached 10,000 Users in One Week. Here's How.](https://www.wearedevelopers.com/videos/100329-this-app-reached-10-000-users-in-one-week-here-s-how) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)