Loading jobs…
Loading jobs…
GTI — New York City, New York
Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision.
Based in New York, the Deputy Chief Information Security Officer (Deputy CISO) serves as the second-in-command of the information security organization, partnering with the CISO to define and execute the enterprise security strategy.
Responsibilities
when needed. This role reports to the Chief Information Security Officer.
include: Strategic Leadership Partner with the CISO to develop and maintain the enterprise information security strategy, roadmap, and governance framework. Represent the security organization to executive leadership, the board, and other internal and external stakeholders in collaboration with the CISO. Drive alignment between security initiatives and business objectives across the Firm.
Lead strategic planning for emerging risks, regulatory changes, and technology shifts. Operational Oversight Support the CISO with the day-to-day management of the security function, including security operations, security engineering architecture, governance, risk compliance and physical security. Manage security metrics, reporting, and executive dashboards to provide visibility into risk posture.
Maintain a list of inflight security initiatives and report status to the CISO and other stakeholders. Coordinate cross-functional security initiatives with IT, information governance and other areas of the business as required. Team Leadership Development Lead, mentor, and develop a team of security managers and senior technical staff.
Build a high-performing, inclusive security culture focused on continuous improvement. Own workforce planning, hiring, and succession planning for the security organization. Foster professional development and career growth across the team.
Incident Crisis Management Serve as key member of the incident response team. Lead post-incident reviews and drive lessons-learned improvements. Support proactive crisis tabletop exercises.
Qualifications
: Proven ability to communicate security risk to executive audiences in business terms. Confident communicator who builds trust with technical/non-technical stakeholders. Ability to balance long-term vision with pragmatic, risk-based prioritization.
Works effectively across organizational boundaries; influences without authority and provides calm, decisive leadership during incidents and crises. Experience: Bachelor's degree in computer science, information security, or related field (or equivalent experience); master’s degree preferred. 10+ years of progressive experience in information security, with at least 5 years in senior leadership roles.
Industry certifications such as CISSP, CISM, CISA, or CRISC. Background in both enterprise and cloud-native security environments. Demonstrated experience building and leading security teams with a track record of leading security during M A, digital transformation, or rapid growth.
Deep expertise across multiple security domains: governance/risk/compliance, security architecture, operations, identity access management, application security, or cloud security. Strong understanding of regulatory and compliance frameworks relevant to the industry. Experience managing security budgets and vendor relationships.
and other operational considerations
Requirements
of local law.
Compensation
range for this position is $330-450k.
Benefits
: The annual