Director, AI Security

Gibson Dunn

New York (NY)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Gibson, Dunn & Crutcher LLP in New York seeks a Director of AI Security to partner with the CISO and craft a first‑of‑its‑kind AI security program. You will define strategy, lead the function, and align governance with legal and regulatory obligations, while translating business needs into secure delivery options.

The role requires partnering with senior leadership, designing risk controls for AI platforms, and managing complex security reviews from conception to production in a fast-paced

Qualifications

  • Strong strategic and analytical thinking demonstrated by building security capability from ground up.
  • Excellent written and verbal communication, including with clients and regulators.
  • Ability to influence senior stakeholders and move quickly in a cross-functional environment.

Responsibilities

  • Define the firm's AI security strategy, target architecture, and multi-year roadmap with executive endorsement.
  • Design, budget, recruit, and lead the AI security function, including team structure and tooling decisions.
  • Establish the security control framework for AI systems and oversee AI use-case reviews from proposal to production.
  • Build relationships with practice group leaders and business leaders to translate AI security needs into secure delivery options.
  • Own agentic identity governance and lifecycle management for AI systems and non-human identities.
  • Develop and own the roadmap for applying AI within the security function and measure its impact.

Skills

Strategic thinking
Executive communication
Stakeholder influence
Security leadership

Education

Bachelor's degree in Computer Science, Cybersecurity, Information

Job description

Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high‑stakes. The firm's work is distinguished by a unique combination of precision and vision.

Based in New York, the Director of AI Security will work directly with the CISO to define the firm's AI security strategy and determine and build the function required to deliver it - its shape, its size, its sequencing and its budget. This is the firm's first dedicated AI security role, with no inherited team or playbook; defining the team required to deliver the strategy is a key part of the role. The position requires the ability to engage credibly with senior executives and practice group leadership on strategy, while also reasoning about technical details such as token scopes and prompt injection.

This role reports to the Chief Information Security Officer.

Responsibilities include:
AI Security Strategy & Program Development
  • Define the firm's AI security strategy, target architecture, and multi-year roadmap in partnership with the CISO, and secure executive endorsement.
  • Design, budget, recruit, and lead the AI security function, including team structure, tooling, and build‑versus‑buy decisions.
  • Establish the security control framework for AI systems.
  • Own the security review stage of the AI use‑case intake and approval process, ensuring a clear and timely path from proposal to production.
  • Partner with the Office of General Counsel and the Cyber & Data Governance Committee on obligations relating to confidentiality, privilege, and competent use of technology.
Stakeholder Engagement & Secure AI Enablement
  • Build relationships with partners, practice group leaders, and business leaders to understand the drivers of AI adoption and translate business needs into secure delivery options.
  • Present AI risk and strategy to executive stakeholders and, where required, to clients.
  • Conduct security architecture and design reviews for AI platforms, RAG pipelines, agent frameworks, and in-house builds.
  • Define controls against AI-specific threats, including prompt injection, tool abuse, data leakage, supply chain compromise, and cross‑matter contamination.
  • Address unsanctioned AI use through discovery, sanctioned alternatives, and clear guidance, in partnership with IT and the practice groups.
Identity & Access Management for AI Systems
  • Own the firm's agentic identity model, governing how agents, service accounts, and tool integrations are issued identity, authenticated, scoped, and revoked.
  • Establish lifecycle governance for non‑human identities, including registration, ownership, entitlement review, credential rotation, and decommissioning.
  • Define authorization patterns for delegated access, ensuring agents never exceed user entitlements and that ethical walls and matter‑level restrictions hold.
  • Set governance standards for tools and connectors, including MCP servers and equivalent integration layers.
  • Ensure every consequential agent action is auditable and attributable to an identity, delegating principal, and matter context.
AI-Enabled Security Operations
  • Develop and own the roadmap for applying AI within the security function.
  • Identify and deliver high‑value use cases such as alert triage, detection engineering, investigation support, and third‑party risk review.
  • Set operating standards for the security function's own AI systems, including autonomy limits, human review points, and ongoing evaluation.
  • Maintain a current view of AI‑enabled threats to the firm and ensure defenses and awareness training keep pace.
  • Measure and report operational impact of AI investments.
Assurance, Risk & Compliance
  • Establish AI red teaming and adversarial testing programs, with findings tracked to remediation.
  • Define pre‑deployment and change‑driven security evaluation criteria for AI systems, including guardrail regression testing.
  • Own AI‑specific incident response playbooks and support the IR team on AI‑related events.
  • Lead security assessments of AI vendors and legal‑tech platforms.
  • Translate emerging regulation and guidance (e.g., EU AI Act, bar association guidance) into control requirements.
  • Deputize for the CISO on AI matters at management and committee level.
Qualifications:
  • Strong strategic and analytical thinking, with a track record of building a security capability from the ground up rather than inheriting one.
  • Ability to operate at executive level - setting strategy, making the business case for investment, and holding your position with senior stakeholders under pressure to move quickly.
  • Ability to influence without formal authority and earn trust in a partnership environment, including from fee earners.
  • Excellent written and verbal communication, including with clients and regulators.
Experience:
  • Bachelor's degree in Computer Science, Cybersecurity, Information
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, AI Security
Director, AI Security

Gibson, Dunn & Crutcher • New York (NY), Northern (KY)

Hybrid
USD 300,000 - 380,000
Health care
Retirement benefits
Paid time off and vacation
+4
Director, AI Security & Strategy
Director, AI Security & Strategy

Gibson Dunn • New York (NY)

On-site
USD 180,000 - 240,000
Director, AI Security: Build Strategy & Lead Secure AI
Director, AI Security: Build Strategy & Lead Secure AI

Gibson, Dunn & Crutcher • New York (NY), Northern (KY)

Hybrid
USD 300,000 - 380,000
Health care
Retirement benefits
Paid time off and vacation
+4
AI Security Specialist
AI Security Specialist

Milbank LLP • New York (NY)

On-site
USD 140,000 - 180,000
Director of Legal Innovation and AI
Director of Legal Innovation and AI

Gibson Dunn • Buffalo (NY)

On-site
USD 300,000 - 380,000
Health care
Retirement benefits
Paid time off
+4
Consulting Director, AI Security
Consulting Director, AI Security

Veriipro • Chicago (IL)

On-site
USD 180,000 - 240,000
Senior Director AI Security
Senior Director AI Security

Ryder System, Inc. • Washington

On-site
USD 180,000 - 240,000
AI Defense Engineer
AI Defense Engineer

Gravity IT Resources • Cincinnati (OH)

On-site
USD 140,000 - 210,000
Director of Cybersecurity Consulting Delivery and Operations
Director of Cybersecurity Consulting Delivery and Operations

TekStream Solutions • Atlanta (GA)

On-site
USD 180,000 - 280,000
Senior Manager/Director — Strategy & AI Advisory
Senior Manager/Director — Strategy & AI Advisory

People Stretch Solutions • McLean (VA)

On-site
USD 140,000 - 200,000