Stand out for this role — generate a tailored resume and cover letter in about a minute.
DLA Piper is seeking a Chief Information Security Officer to lead a mature, business-aligned cyber risk program across a global platform. You will set the strategic direction for the Information Security Management System, governance, risk management, incident response, data protection and security awareness programs.
As a trusted advisor to firm leadership and global counterparts, you will enable innovation, responsible AI adoption, and operational resilience while preserving client service
DLA Piper is, at its core, bold, exceptional, collaborative and supportive. Our people are the backbone, heart and soul of our firm. Wherever you are in your professional journey, DLA Piper is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.
The Chief Information Security Officer (CISO), working in collaboration with and in support of the firm’s strategic initiatives, is a senior executive responsible for protecting DLA Piper's clients, people, data, reputation and global business operations by leading a mature, business-aligned information security and cyber risk program. This role sets the strategic direction for the firm’s Information Security Management System, security governance, risk management, incident response, third-party security, data protection and security awareness programs. Operating as a trusted advisor to firm leadership, the Office of General Counsel, Information Technology, Information Governance, Risk Management, practice leadership, and global counterparts, the CISO ensures the confidentiality, integrity and availability of client and firm information while enabling innovation, responsible AI adoption, operational resilience and exceptional client service. The CISO works closely with, but independently from, the Information Technology function to provide objective risk oversight, policy leadership, executive reporting and continuous improvement of the firm’s security posture.
This position can sit in our Atlanta, Baltimore, Boston, Miami, New York, Northern Virginia, Philadelphia, Raleigh, Short Hills, Washington D.C. or Wilmington office. Candidates must reside within a reasonable commuting distance of their assigned office and be available for periodic travel.
Deep technical engineering expertise in technology infrastructure, Cloud, zero-trust architecture and cyber defense. Proven ability to leverage frameworks like NIST to build and operate a comprehensive defense in depth capability. Proven ability in change management, building trust with partners and transforming organizations. Experience in a global law firm, professional services firm, financial services institution, technology company or similarly complex environment strongly preferred. Demonstrated success leading cybersecurity strategy, enterprise risk governance, incident response, regulatory and client-facing security matters, third-party risk, audit/certification programs, security awareness and high performing teams. Experience advising senior executives, boards, managing partners or equivalent governance bodies required. Executive-level knowledge of cybersecurity strategy governance risk compliance privacy data protection incident response threat intelligence vulnerability management identity and access management cloud and network security application security endpoint protection email security encryption logging and monitoring disaster recovery business continuity third-party risk DevSecOps modernized secure development practices including AI SDLC and secure technology adoption. Strong understanding of professional responsibility client confidentiality data classification privilege-sensitive work outside counsel guidelines ethical walls cross-border data considerations and the security expectations of sophisticated global clients. Demonstrated ability to translate technical risk into business and legal impact influence senior stakeholders lead through ambiguity make sound risk-based decisions and communicate with clarity credibility discretion and urgency. Familiarity with ISO/IEC 27001 NIST CIS Controls data privacy laws cyber insurance considerations AI governance and emerging legal sector cybersecurity risks strongly preferred. A leader who thrives on learning and is up to date with the fast-evolving technology landscape especially the changing threats with the advancement of AI. Ability to not only understand security tools needs how these are changing but also go back to first principles in solving the underlying problems through innovation. Demonstrate executive presence credibility sound judgment and professional maturity in all interactions particularly when advising firm leadership senior partners governance bodies clients regulators vendors and other high-impact stakeholders on sensitive complex or time-critical information security matters. Communicate with clarity confidence discretion and appropriate urgency translating complex technical legal operational and risk issues into concise business terms that enable informed decisions by senior leaders and non-technical audiences. Influence senior leaders and stakeholders through trusted relationships fact-based analysis persuasive recommendations and a firm-first approach that balances client expectations legal and regulatory obligations operational realities risk appetite and strategic business priorities. Build alignment across a complex matrixed partner-led environment by listening effectively anticipating concerns managing competing perspectives escalating appropriately and helping leaders reach timely defensible and consistently supported decisions. Prepare and deliver executive-level briefings written updates risk narratives Executive Committee materials client-facing responses and incident communications that are accurate audience-appropriate concise and aligned with firm standards and confidentiality obligations. Lead difficult or sensitive conversations with diplomacy composure courage and empathy including situations involving cyber incidents policy exceptions risk acceptance resource tradeoffs control gaps or competing leadership priorities.
All DLA Piper employees are expected to demonstrate excellence in how we serve our clients and develop our people, upholding our firm values as part of our culture. Specific expectations include:
Sedentary work: This is primarily sedentary work requiring occasional exertion of up to 10 pounds of force to lift carry push pull or move objects. The role involves sitting for extended periods with occasional walking and standing and occasional travel both domestic and international.
The individual selected for this position may have the opportunity for a hybrid work arrangement combining remote and in-office work. The specific arrangement will be determined at the time of hiring and may be modified at the firm’s discretion.
The purpose of this job description is to provide a concise statement of the work elements and to organize and present the information in a standardized way. It is not intended to describe all the elements of the work that may be performed by every individual in this classification nor should it serve as the sole criteria for personnel decisions and actions. The job duties requirements and expectations for this position may be modified at the firm’s discretion at any time. This job description does not change the at-will nature of employment.
No immigration sponsorship is available for this position.
This job description provides a concise overview of the role and is not intended to describe all work elements that may be performed. It should not serve as the sole criteria for personnel decisions. Job duties requirements and expectations may be modified at the firm’s discretion at any time. This job description does not alter the at-will nature of employment.
We are committed to excellence in how we serve our clients and develop our people.
The firm’s expected hiring range for this position is $550,000 - $650,000 per year depending on the candidate’s geographic market location.
The compensation offered for employment will also be dependent on other factors including the candidate’s experience skills educational and professional background and overall qualifications. We offer a comprehensive package of benefits including medical/dental/vision insurance and 401(k).
Applicants who are not based in the jurisdiction in which this position is posted and who apply for this role are doing so voluntarily and are not eligible for relocation assistance. Any relocation benefits if any are provided only where a relocation is required at the firm’s direction and in accordance with applicable policy and law.
DLA Piper is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability or status as a protected veteran.