Chief Information Security Officer

Morganmorganjobsapplynow

Orlando (FL)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical and dental insurance
401(k) plan
Paid time off
Paid holidays

Job summary

Morgan & Morgan seeks a Chief Information Security Officer to lead a modern, business-aligned security program protecting sensitive data while enabling rapid software development, AI-driven workflows, and innovation across legal-technology platforms. This on-site role partners with engineering, product, legal, and operations to embed security into fast-moving delivery cycles and build scalable guardrails.

The CISO will drive risk-informed decisions, manage incident response, and align security

Qualifications

  • 10+ years in cybersecurity with senior leadership experience
  • Demonstrated ability to communicate cyber risk to executives
  • Proven track record delivering risk-informed security programs
  • Experience embedding security into rapid software development and AI-enabled workflows
  • Strong knowledge of CSF/ISO27001, Zero Trust, and incident leadership
  • Preferred: CISSP, CISM, or equivalent credentials

Responsibilities

  • Define and execute a business-aligned cybersecurity strategy
  • Establish risk-informed security governance for fast decision-making
  • Translate cyber risk into business impact for leadership and Board
  • Guide security investments balancing velocity, resilience and trust
  • Lead firm-wide risk assessments, threat modeling, and control maturity
  • Own incident response strategy, breach readiness, tabletop exercises
  • Partner with Legal, Privacy, Compliance to protect sensitive data and ensure regulatory alignment
  • Oversee third-party and vendor security risk management at national scale
  • Design scalable security architecture for platforms, AI-enabled workflows, and cloud-native environments
  • Embed security into Agile development, CI/CD pipelines, and SaaS ecosystems
  • Implement Zero Trust with developer-friendly controls
  • Oversee IAM, endpoint, network and cloud security, monitoring and response
  • Foster leadership culture with clear accountability and fast execution

Skills

Cybersecurity leadership
Executive communication
Risk management
Security strategy
Zero Trust
Cloud security
Incident response
Security architecture

Job description

At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People.

About the Role

Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Ourscale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases.We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability.

We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms.

This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles throughpragmatic guardrails, clear risk ownership, and modern security architecture.Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt.

This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust.

Key Responsibilities
Security Strategy & Risk Leadership
  • Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale
  • Establish risk-informed security governance that enables fast, confident decision-makingin a high-volume, litigation-driven environment
  • Translate cyber risk into clear business impact for executive leadership and the Board
  • Guide security investment decisions that balance velocity, resilience, and client trust
Management & Compliance
  • Lead firm-wide risk assessments, threat modeling, and control maturity evaluations
  • Own end-to-end incident response strategy, breach readiness, tabletop exercises, andpost-incident learning
  • Partner closely with Legal, Privacy, and Compliance leaders to ensure:
    • Protection of sensitive client and case data
    • Defensible security practices suitable for litigation discovery
    • Alignment with regulatory, contractual, and ethical obligations
    • Oversee third-party and vendor security risk management at national scale
Security Architecture & Engineering Enablement
  • Design and evolve a scalable security architecture that supports internally builtplatforms, modern development practices, and AI-enabled legal technology
  • Embed security into Agile software development and CI/CD pipelines
  • Embed security into Cloud-native platforms and SaaS ecosystems
  • Embed security into AI-enabled legal workflows and analytics platforms
  • Implement Zero Trust principles using pragmatic, developer-friendly controls
  • Ensure security controls function as guardrails, not bottlenecks, for engineers andattorneys
Security Operations
  • Oversee security operations including:
    • Identity & Access Management (IAM)
    • Endpoint, network, and cloud security
    • Security monitoring, detection, and response
  • Continuously improve detection, response time, and operational resilience
  • Ensure security operations remain resilient and e/ective during high-volume, time-sensitive legal operations
  • Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyers
Leadership & Culture
  • Build, lead, and mentor a high-caliber, hands-on security organization
  • Establish strong operating models between Security, IT, Engineering, and the business
  • Set clear expectations and a high bar for execution, accountability, and follow-throughacross the security function
  • Champion a culture where security is designed in early, not bolted on late
  • This role requires a leader who is comfortable operating close to the technology engagingdirectly with teams, systems, and incidents when needed
  • Act as a visible, trusted executive leader approachable, decisive, and credible
Required Experience
  • 10+ years in cybersecurity, including senior leadership roles in large, complexenvironments
  • Proven success leading security programs in high-data-sensitivity, fast-movingorganizations
  • Demonstrated ability to communicate cyber risk clearly to executive leadership and
Boards
  • Strong working knowledge of:
    • NIST Cybersecurity Framework (CSF) and/or ISO 27001
    • Zero Trust architecture
    • Incident response and crisis leadership
  • Cloud and SaaS security at scale
Executive Mindset
  • Business-first approach to security focused on outcomes, not checklists
  • Comfort making tradeo/s and defending decisions at the executive level
  • Calm, credible leadership during high-pressure situations
  • High integrity, sound judgment, and strong ethical foundation
Preferred Qualifications
  • CISSP, CISM, or equivalent credentials
  • Experience supporting AI platforms, analytics, or large-scale digital transformation
  • Proven partnership with CIOs, General Counsel, and Compliance leadership
  • Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, orsimilar)
Why Morgan & Morgan
  • Unmatched scale: Secure operations across 140+ offices nationwide
  • Real impact: Protect systems supporting more than $30 billion recovered for clients
  • Innovation focus: Security embedded in rapid software delivery and AI-driven legal tech
  • Executive influence: Direct involvement in firm-wide risk and investment decisions
  • Leadership commitment: Security treated as a strategic business capability
What We Offer

Morgan & Morgan offers a people‑first environment grounded in high performance. We provide comprehensive medical, dental, vision, and mental health benefits; generous paid time off; strong onboarding and leadership support; and a culture that values accountability, growth, and results. You’ll work alongside driven professionals who expect excellence and support one another in achieving it.

Benefits

Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff. For full‑time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan, paid time off and paid holidays.

Equal Opportunity Statement

Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

E-Verify

This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form.

Privacy Policy

Here is a link to Morgan & Morgan's privacy policy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Security Engineer
Cloud Security Engineer

Morgan & Morgan, P.A. • Tampa (FL)

On-site
USD 120,000 - 160,000
Medical and dental insurance
401(k) plan
Paid time off
+1
Cloud Security Engineer
Cloud Security Engineer

Morganmorganjobsapplynow • Orlando (FL)

On-site
USD 120,000 - 160,000
Cloud Security Engineer
Cloud Security Engineer

Morgan & Morgan, P.A. • Orlando (FL)

On-site
USD 120,000 - 180,000
Medical insurance
Dental insurance
401(k) plan
+2
Senior Security Engineer
Senior Security Engineer

Morganmorganjobsapplynow • Orlando (FL)

On-site
USD 100,000 - 120,000
Medical and dental insurance
401(k) plan
Paid time off and holidays
IT Physical Security Administrator
IT Physical Security Administrator

Morganmorganjobsapplynow • Orlando (FL)

On-site
USD 65,000 - 85,000
Medical and dental insurance
401(k) plan
Paid time off
+1
Senior Manager, Strategy & Operations
Senior Manager, Strategy & Operations

Morganmorganjobsapplynow • Chicago (IL)

On-site
USD 150,000 - 210,000
Medical and dental insurance
401(k) plan
Paid time off
+1
Senior GRC Analyst
Senior GRC Analyst

Morganmorganjobsapplynow • Orlando (FL)

On-site
USD 80,000 - 100,000
Medical and dental insurance
401(k) plan
Paid time off
+1
Strategy and Operations Associate
Strategy and Operations Associate

Morganmorganjobsapplynow • New York (NY)

On-site
USD 100,000 - 150,000
Medical insurance
Dental insurance
401(k) plan
+2
Senior Manager, Strategy & Operations
Senior Manager, Strategy & Operations

Morganmorganjobsapplynow • New York (NY)

On-site
USD 140,000 - 180,000
Medical & dental insurance
401(k) plan
Paid time off
+1
Senior Manager, Strategy & Operations
Senior Manager, Strategy & Operations

Socket.dev • New York (NY)

On-site
USD 140,000 - 180,000
Medical and dental insurance
401(k) plan
Paid time off
+1