Manager, Information Security
Location: Washington DC, Hybrid
This role leads the overall security direction for a professional services organization, with responsibility for protecting sensitive data, client information, and internal systems across the business.
The position operates at both a strategic and operational level, shaping how security is approached across the company while ensuring day-to-day protections, processes, and response capabilities are effective. It partners closely with senior leadership and cross-functional teams to align security priorities with business needs, client expectations, and regulatory considerations.
A core part of the role is leading and developing a dedicated security team. This includes setting direction, delegating execution, mentoring team members, and ensuring consistent delivery across key areas such as risk management, incident response, and compliance. Success in this role requires someone who can drive outcomes through others, not just execute independently.
Key areas of focus include building and maturing the security program, overseeing risk identification and mitigation, guiding incident response efforts, and maintaining alignment with industry frameworks and regulatory expectations. The role also drives internal awareness and education, helping non-technical stakeholders adopt secure practices.
This individual will also evaluate and guide the use of security technologies, manage external vendors where needed, and communicate clearly with leadership around risk, priorities, and program performance.
What success looks like:
- A well-defined and continuously improving security program
- A high-performing, accountable security team with clear ownership and execution
- Clear visibility into risk and actionable mitigation plans
- Effective incident response and organizational readiness
- Strong alignment between security, business operations, and client requirements
Background profile:
- Significant experience leading cybersecurity or risk programs in complex environments
- Direct people management experience (including mentoring, performance management, and team development)
- Strong familiarity with industry frameworks and compliance standards (e.g., NIST, ISO, SOC2)
- Experience influencing senior stakeholders and cross-functional teams
- Ability to balance business needs with security priorities
- Experience within a law firm or legal services environment strongly preferred