Chief Information Security Officer

Orlando, FL, US • Posted 1 day ago • Updated 4 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Customer Support
  • Marketing
  • Information Security
  • Software Development
  • Continuous Improvement
  • Information Security Governance
  • Decision-making
  • Apache Velocity
  • Risk Assessment
  • Threat Modeling
  • Litigation
  • Risk Management
  • Security Architecture
  • Agile
  • Continuous Integration
  • Continuous Delivery
  • Workflow
  • Security Controls
  • Identity Management
  • Network
  • Cloud Security
  • Security Operations
  • Mentorship
  • CaliberRM
  • Cyber Security
  • ISO/IEC 27001:2005
  • Incident Management
  • Cloud Computing
  • CISSP
  • CISM
  • Analytics
  • Partnership
  • Collaboration
  • Regulatory Compliance
  • SaaS
  • Innovation
  • FOCUS
  • Embedded Systems
  • Artificial Intelligence
  • Legal
  • Management
  • Onboarding
  • Leadership
  • Accountability
  • Expect
  • Law
  • Insurance
  • Genetics
  • Security Management
  • Privacy

Summary

At Morgan & Morgan, the work we do matters. For millions of Americans, we're their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People.

About the Role

Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability.

We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms.

This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent-ensuring our teams can fight for clients without distraction, delay, or doubt.

This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust.

Key Responsibilities

Security Strategy & Risk Leadership
Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale
Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment
Translate cyber risk into clear business impact for executive leadership and the Board
Guide security investment decisions that balance velocity, resilience, and client trustRisk

Management & Compliance
Lead firm-wide risk assessments, threat modeling, and control maturity evaluations
Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning
Partner closely with Legal, Privacy, and Compliance leaders to ensure:
Protection of sensitive client and case data
Defensible security practices suitable for litigation discovery
Alignment with regulatory, contractual, and ethical obligations
Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement
Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology
Embed security into:
Agile software development and CI/CD pipelines
Cloud-native platforms and SaaS ecosystems
AI-enabled legal workflows and analytics platforms
Implement Zero Trust principles using pragmatic, developer-friendly controls
Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys

Security Operations
Oversee security operations including:
Identity & Access Management (IAM)
Endpoint, network, and cloud security
Security monitoring, detection, and response
Continuously improve detection, response time, and operational resilience
Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations
Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture
Build, lead, and mentor a high-caliber, hands-on security organization
Establish strong operating models between Security, IT, Engineering, and the business
Set clear expectations and a high bar for execution, accountability, and follow-through across the security function
Champion a culture where security is designed in early, not bolted on late
This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed
Act as a visible, trusted executive leader approachable, decisive, and credible

Required Experience
10+ years in cybersecurity, including senior leadership roles in large, complex environments
Proven success leading security programs in high-data-sensitivity, fast-moving organizations
Demonstrated ability to communicate cyber risk clearly to executive leadership and

Boards
Strong working knowledge of:
NIST Cybersecurity Framework (CSF) and/or ISO 27001
Zero Trust architecture
Incident response and crisis leadership
Cloud and SaaS security at scaleExecutive Mindset
Business-first approach to security focused on outcomes, not checklists
Comfort making tradeo/s and defending decisions at the executive level
Calm, credible leadership during high-pressure situations
High integrity, sound judgment, and strong ethical foundationPreferred Qualifications
CISSP, CISM, or equivalent credentials
Experience supporting AI platforms, analytics, or large-scale digital transformation
Proven partnership with CIOs, General Counsel, and Compliance leadership
Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar)

Why Morgan & Morgan
Unmatched scale: Secure operations across 140+ offices nationwide
Real impact: Protect systems supporting more than $30 billion recovered for clients
Innovation focus: Security embedded in rapid software delivery and AI-driven legal tech
Executive influence: Direct involvement in firm-wide risk and investment decisions
Leadership commitment: Security treated as a strategic business capability

What We Offer

Morgan & Morgan offers a people-first environment grounded in high performance. We provide comprehensive medical, dental, vision, and mental health benefits; generous paid time off; strong onboarding and leadership support; and a culture that values accountability, growth, and results. You'll work alongside driven professionals who expect excellence and support one another in achieving it.

Benefits

Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays.

Equal Opportunity Statement

Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

E-Verify

This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form.

Privacy Policy

Here is a link to Morgan & Morgan's privacy policy.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: RTX1cdadb
  • Position Id: 753c5e37ad9ddcc07dd3d1aa1854df2
  • Posted 1 day ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Full-time

USD 235,000.00 - 270,000.00 per year

Remote

Today

Full-time

USD 300,000.00 - 400,000.00 per year

Remote

6d ago

Easy Apply

Contract

70 - 80

Remote or Utah

Today

Full-time

Search all similar jobs