Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Chief Information Security Officer role.
Rezi rewrites your resume against DLA Piper's job description. Free.

Tailor your resume to this Chief Information Security Officer role.
Rezi rewrites your resume against DLA Piper's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Chief Information Security Officer posting at DLA Piper — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Chief Information Security Officer posting at DLA Piper — free, in seconds.
About the Role
The Chief Information Security Officer (CISO) is a senior executive responsible for protecting DLA Piper’s clients, people, data, reputation, and global business operations by leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response, third-party security, data protection, and security awareness programs. The CISO operates as a trusted advisor to firm leadership, ensuring the confidentiality, integrity, and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience, and exceptional client service.
Responsibilities
- Sets and executes the enterprise information security strategy for DLA Piper, aligning cyber risk management with firm strategy, client obligations, professional responsibility requirements, regulatory expectations, and operational resilience objectives.
- Leads the firm’s Information Security Management System and security governance framework, including policy development, risk assessment, control monitoring, executive reporting, audit readiness, certification support, and continuous improvement.
- Serves as the senior incident response leader for information security events, ensuring prompt triage, containment, investigation, evidence preservation, root-cause analysis, remediation, lessons learned, and appropriate coordination with relevant parties.
- Partners with executive leadership and various departments to embed security-by-design into firm operations, technology investments, client service delivery, and major transformation initiatives.
- Provides objective cyber risk advice to firm leadership and governance bodies, translating complex technical risk into clear business, legal, reputational, operational, and client-impact terms.
- Oversees enterprise cyber risk identification, assessment, treatment, acceptance, and reporting.
- Leads security oversight of client and firm confidential information, including data classification, access controls, encryption, retention, secure disposal, cross-border data considerations, ethical walls, client outside counsel guidelines, and matter-specific security obligations.
- Directs third-party and supplier security risk management, ensuring vendors are assessed, monitored, and held to appropriate security, privacy, contractual, and operational standards.
- Guides security review and risk oversight for emerging technologies, cloud services, legal technology, artificial intelligence, automation, analytics, and internally developed tools.
- Builds, develops, and leads a high-performing information security organization.
- Defines and manages the Information Security team’s operating model, including functional roles, accountability structures, governance routines, service levels, intake and prioritization processes, escalation protocols, on-call expectations, and coordination with relevant departments.
- Recruits, develops, coaches, and retains a high-caliber Information Security team.
- Sets clear goals and performance expectations for the Information Security team, regularly assesses performance, addresses performance gaps, recognizes strong contributions, and ensures the team has the necessary training, tools, resources, and authority.
- Provides strategic, operational, and people leadership to the Information Security function.
- Defines the team’s vision, operating model, service standards, decision rights, escalation paths, and priorities.
- Responsible for onboarding, coaching, performance management, succession planning, professional development, retention, resource allocation, budget input, vendor oversight, and effective delegation across the security program.
Requirements
- Candidates must reside within a reasonable commuting distance of their assigned office and be available for periodic travel.
- Demonstrated ability to translate technical risk into business and legal impact, influence senior stakeholders, lead through ambiguity, make sound risk-based decisions, and communicate with clarity, credibility, discretion, and urgency.
- Build alignment across a complex, matrixed, partner-led environment by listening effectively, anticipating concerns, managing competing perspectives, escalating appropriately, and helping leaders reach timely, defensible, and consistently supported decisions.
- Prepare and deliver executive-level briefings, written updates, risk narratives, Executive Committee materials, client-facing responses, and incident communications that are accurate, audience-appropriate, concise, and aligned with firm standards and confidentiality obligations.
- Lead difficult or sensitive conversations with diplomacy, composure, courage, and empathy.
- All DLA Piper employees are expected to demonstrate excellence in how we serve our clients and develop our people, upholding our firm values as part of our culture.
- Communicate effectively, both verbally and in writing, with clients, lawyers, business professionals, and external audiences.
- Produce high-quality work and respond to correspondence in an efficient, timely, and professional manner.
- Meet deadlines, manage competing priorities, and commit to meeting high standards.
- Comply with firm policies and procedures.
- Maintain confidences as required in a law firm environment.
- Sedentary work: This is primarily sedentary work, requiring occasional exertion of up to 10 pounds of force to lift, carry, push, pull, or move objects. The role involves sitting for extended periods, with occasional walking and standing, and occasional travel, both domestic and international.
Skills
- Deep technical engineering expertise in technology infrastructure, Cloud, zero-trust architecture and cyber defense.
- Proven ability to leverage frameworks like NIST to build and operate a comprehensive defense in depth capability.
- Proven ability in change management, building trust with partners and transforming organizations.
- Demonstrated success leading cybersecurity strategy, enterprise risk governance, incident response, regulatory and client-facing security matters, third-party risk, audit/certification programs, security awareness, and high performing teams.
- Experience advising senior executives, boards, managing partners, or equivalent governance bodies required.
- Executive-level knowledge of cybersecurity strategy, governance, risk, compliance, privacy, data protection, incident response, threat intelligence, vulnerability management, identity and access management, cloud and network security, application security, endpoint protection, email security, encryption, logging and monitoring, disaster recovery, business continuity, third-party risk, DevSecOps, modernized secure development practices including AI SDLC, and secure technology adoption.
- Strong understanding of professional responsibility, client confidentiality, data classification, privilege-sensitive work, outside counsel guidelines, ethical walls, cross-border data considerations, and the security expectations of sophisticated global clients.
- Familiarity with ISO/IEC 27001, NIST, CIS Controls, data privacy laws, cyber insurance considerations, AI governance, and emerging legal sector cybersecurity risks strongly preferred.
- A leader who thrives on learning and is up to date with the fast-evolving technology landscape, especially the changing threats with the advancement of AI.
- Ability to not only understand security tools/needs, how these are changing but also go back to first principles in solving the underlying problems through innovation.
- Demonstrate executive presence, credibility, sound judgment, and professional maturity in all interactions.
- Communicate with clarity, confidence, discretion, and appropriate urgency, translating complex technical, legal, operational, and risk issues into concise business terms that enable informed decisions by senior leaders and non-technical audiences.
- Influence senior leaders and stakeholders through trusted relationships, fact-based analysis, persuasive recommendations, and a firm-first approach that balances client expectations, legal and regulatory obligations, operational realities, risk appetite, and strategic business priorities.
Location
- Atlanta
- Baltimore
- Boston
- Miami
- New York
- Northern Virginia
- Philadelphia
- Raleigh
- Short Hills
- Washington D.C.
- Wilmington
Work Type
- Hybrid
Experience Level
- 15+ years’ progressive information security, cybersecurity, technology risk, privacy, compliance, or enterprise risk leadership experience, including significant executive-level responsibility for a complex, highly regulated, client-facing organization.
Education Level
- Bachelor’s Degree in Information Security, Cybersecurity, Information Technology, Computer Science, Engineering, Business, Risk Management, Law, or a related field; equivalent senior leadership experience may be considered, where appropriate.
- Master’s Degree in MBA, M.S. in Cybersecurity/Information Security, J.D., or other relevant advanced degree preferred.
- Relevant professional certifications are strongly preferred, such as CISSP, CISM, CISA, CRISC, CCISO, GIAC, ISO/IEC 27001 Lead Implementer or Lead Auditor, or comparable credentials.
- Demonstrated ongoing professional development in cybersecurity, privacy, risk governance, incident response, cloud security, AI governance, and legal/professional services risk is expected.
Salary/Compensations
- $550,000 - $650,000 per year depending on the candidate’s geographic market location.
Benefits
- medical/dental/vision insurance
- 401(k)
About the Company
- DLA Piper is, at its core, bold, exceptional, collaborative and supportive. Our people are the backbone, heart and soul of our firm. Wherever you are in your professional journey, DLA Piper is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.
Equal Opportunity
- DLA Piper is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.