Director, AI Security

Gibson, Dunn & Crutcher

New York, Northern (NY, KY)

Hybrid

USD 300,000 - 380,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health care
Retirement benefits
Paid time off and vacation
Parental leave
Life insurance
Flexible Spending Accounts
Discretionary bonuses

Job summary

Gibson Dunn, a leading global law firm based in New York, seeks a Director of AI Security to define and lead the firm’s AI security program. You will work directly with the CISO to design the team, budget, and roadmap, shaping how AI is securely adopted across the organization.

You will own the security review of AI use cases, establish controls against AI threats, and partner with legal and governance bodies to ensure compliant, confidential operations.

Qualifications

  • Bachelor’s degree in CS/Cybersecurity/IT or equivalent experience.
  • 10+ years information security experience.
  • Deep experience securing production AI and LLM systems, including AI-specific threats.
  • Security architecture across cloud (Azure/AWS) and SaaS-heavy environments.
  • Certs such as CISSP/CCSP/CISM a plus.

Responsibilities

  • Define the firm’s AI security strategy and multi-year roadmap with the CISO.
  • Design, budget, recruit, and lead the AI security function; determine team structure and tooling.
  • Establish the security control framework for AI systems.
  • Own the security review stage of the AI use-case intake and approval process.
  • Partner with the GC and Cyber & Data Governance Committee on confidentiality and privilege obligations.

Skills

Strategic thinking
Executive stakeholder engagement
Security architecture
Communication with clients/regulators

Education

Bachelor’s degree in CS/Cybersecurity/IT

Tools

OAuth 2.0
OIDC
SAML

Job description

Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision.

Based in New York, the Director of AI Security will work directly with the CISO to define the firm’s AI security strategy and determine and build the function required to deliver it — its shape, its size, its sequencing and its budget. This is the firm’s first dedicated AI security role, with no inherited team or playbook; defining the team required to deliver the strategy is a key part of the role. The position requires the ability to engage credibly with senior executives and practice group leadership on strategy, while also reasoning about technical details such as token scopes and prompt injection.

This role reports to the Chief Information Security Officer.

Responsibilities include:

AI Security Strategy & Program Development

  • Define the firm’s AI security strategy, target architecture, and multi-year roadmap in partnership with the CISO, and secure executive endorsement.
  • Design, budget, recruit, and lead the AI security function, including team structure, tooling, and build-versus-buy decisions.
  • Establish the security control framework for AI systems.
  • Own the security review stage of the AI use‑case intake and approval process, ensuring a clear and timely path from proposal to production.
  • Partner with the Office of General Counsel and the Cyber & Data Governance Committee on obligations relating to confidentiality, privilege, and competent use of technology.

Stakeholder Engagement & Secure AI Enablement

  • Build relationships with partners, practice group leaders, and business leaders to understand the drivers of AI adoption and translate business needs into secure delivery options.
  • Present AI risk and strategy to executive stakeholders and, where required, to clients.
  • Conduct security architecture and design reviews for AI platforms, RAG pipelines, agent frameworks, and in‑house builds.
  • Define controls against AI‑specific threats, including prompt injection, tool abuse, data leakage, supply chain compromise, and cross‑matter contamination.
  • Address unsanctioned AI use through discovery, sanctioned alternatives, and clear guidance, in partnership with IT and the practice groups.

Identity & Access Management for AI Systems

  • Own the firm’s agentic identity model, governing how agents, service accounts, and tool integrations are issued identity, authenticated, scoped, and revoked.
  • Establish lifecycle governance for non‑human identities, including registration, ownership, entitlement review, credential rotation, and decommissioning.
  • Define authorization patterns for delegated access, ensuring agents never exceed user entitlements and that ethical walls and matter‑level restrictions hold.
  • Set governance standards for tools and connectors, including MCP servers and equivalent integration layers.
  • Ensure every consequential agent action is auditable and attributable to an identity, delegating principal, and matter context.

AI-Enabled Security Operations

  • Develop and own the roadmap for applying AI within the security function.
  • Identify and deliver high‑value use cases such as alert triage, detection engineering, investigation support, and third‑party risk review.
  • Set operating standards for the security function’s own AI systems, including autonomy limits, human review points, and ongoing evaluation.
  • Maintain a current view of AI‑enabled threats to the firm and ensure defenses and awareness training keep pace.
  • Measure and report operational impact of AI investments.
  • Establish AI red teaming and adversarial testing programs, with findings tracked to remediation.
  • Define pre‑deployment and change‑driven security evaluation criteria for AI systems, including guardrail regression testing.
  • Own AI‑specific incident response playbooks and support the IR team on AI‑related events.
  • Lead security assessments of AI vendors and legal‑tech platforms.
  • Translate emerging regulation and guidance (e.g., EU AI Act, bar association guidance) into control requirements.
  • Deputize for the CISO on AI matters at management and committee level.

Qualifications:

  • Strong strategic and analytical thinking, with a track record of building a security capability from the ground up rather than inheriting one.
  • Ability to operate at executive level — setting strategy, making the business case for investment, and holding your position with senior stakeholders under pressure to move quickly.
  • Ability to influence without formal authority and earn trust in a partnership environment, including from fee earners.
  • Excellent written and verbal communication, including with clients and regulators.

Experience:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
  • 10+ years of information security experience, including end‑to‑end ownership of a significant security domain.
  • Deep, practical experience securing production AI and LLM systems, including AI‑specific threats such as prompt injection and data leakage.
  • Strong identity and access management foundations (OAuth 2.0, OIDC, SAML, delegation patterns, machine identity at scale).
  • Security architecture experience across cloud (Azure and/or AWS) and SaaS‑heavy environments.
  • Experience applying AI or automation to measurably improve security operations.
  • Relevant certifications (CISSP, CCSP, CISM, or equivalents) a plus.

Gibson Dunn will consider for employment qualified Applicants with Criminal Histories in a manner consistent with the requirements of local law.

The annual compensation range for this position is $300,000 – $380,000. The salary offered within this range will depend upon qualifications and other operational considerations.

Benefits offered for this position include health care; retirement benefits; paid days off, including sick time, and vacation time; parental leave; basic life insurance; Flexible Spending Accounts; as well as discretionary, performance‑based bonuses.

Gibson Dunn is committed to ensuring equal employment opportunities for all qualified applicants, including individuals with disabilities. We strive to ensure an inclusive and accessible hiring experience. The Firm will provide reasonable accommodations to qualified individuals with disabilities to enable participation in the application and recruitment process, unless doing so would impose an undue hardship, in accordance with applicable laws and regulations. If you require a reasonable accommodation to complete an application, participate in an interview, or otherwise take part in the recruitment process, please contact us at recruiting‑accommodations@gibsondunn.com. Please note, this is a dedicated email inbox established exclusively to assist applicants with accommodation request related to the recruitment process. Inquiries about the status of an application or other non‑accommodation matter will not receive a response.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Legal Innovation and AI
Director of Legal Innovation and AI

Gibson, Dunn & Crutcher • New York (NY), Northern (KY)

Hybrid
USD 300,000 - 380,000
Health care
Retirement benefits
Paid time off
+4
Senior Director, Security Operations
Senior Director, Security Operations

Gibson, Dunn & Crutcher • New York (NY)

On-site
USD 305,000 - 395,000
Health benefits
Paid time off
Parental leave
Deputy Chief Information Security Officer
Deputy Chief Information Security Officer

Gibson, Dunn & Crutcher • New York (NY), Northern (KY)

Hybrid
USD 330,000 - 450,000
Health care
Retirement benefits
Paid time off
+4
Manager, AI & Advisory Solutions
Manager, AI & Advisory Solutions

Gibson Dunn • New York (NY)

On-site
USD 240,000 - 260,000
Health insurance
Retirement Benefits
Paid time off
+3
Director, AI Security: Build Strategy & Lead Secure AI
Director, AI Security: Build Strategy & Lead Secure AI

Gibson, Dunn & Crutcher • New York (NY), Northern (KY)

Hybrid
USD 300,000 - 380,000
Health care
Retirement benefits
Paid time off and vacation
+4
Director of Data Services
Director of Data Services

Gibson Dunn • Town of Tonawanda (NY)

On-site
USD 325,000 - 380,000
Health care
Retirement benefits
Paid time off
+2
Deputy Chief Information Security Officer
Deputy Chief Information Security Officer

The Security Executive Council • New York (NY), Northern (KY)

Hybrid
USD 330,000 - 450,000
Enterprise Architect
Enterprise Architect

Gibson Dunn • New York (NY)

On-site
USD 175,000 - 220,000
Health care
Retirement benefits
Paid time off (vacation & sick)
+2
Senior Data Engineer
Senior Data Engineer

Gibson Dunn • New York (NY)

On-site
USD 150,000 - 200,000
Health care
Retirement benefits
Paid time off
+3
Engineering Manager, Platform Engineering
Engineering Manager, Platform Engineering

Gibson Dunn • New York (NY)

On-site
USD 230,000 - 300,000
Health care
Retirement benefits
Paid time off
+4