BostonRecruiter Since 2001
the smart solution for Boston jobs

Director, Information Security

Company: WilmerHale
Location: Boston
Posted on: February 26, 2021

Job Description:

Tracking Code 1397-437 Job Description JOB SUMMARYThe Director, Information Security is responsible for directing IS strategy and activities related to information security. The Director provides leadership and direction to a team responsible for designing and implementing an overall enterprise security strategy, program, and architecture that minimizes information related to loss and meets client and regulatory requirements. Develops, monitors and implements firm-wide information security policies to ensure that appropriate access to, and the confidentiality of firm, client and private information is maintained. Conducts information risk assessments as an integral part of business planning involving General Counsel, internal specialists and business owners as the need arises. Serves as a liaison to firm clients in all matters of information security including completion of client audits and review of RFPs and outside counsel guidelines. Leads and coordinates the firm's tactical and operational response to information security incidents. Identifies and reports on information security incidents to firm management. Manages organizational risk by ensuring the protection of the enterprise infrastructure with a layered system of technical defenses including firewalls, intrusion detection and prevention, antivirus, and content monitoring. Provides risk review and approval of changes to systems, applications and facilities. Leads the evaluation and recommendation of security products, services and/or procedures to enhance productivity and effectiveness. Leads risk assessments of firm vendors and solution providers. Lead all aspects of and conducts security awareness programs and provides education on security policies and practices.Ensures that staff members are providing quality service to internal members/departments of the Firm as well as external clients and vendors by displaying professionalism via electronic and print correspondence, over the telephone and in-person and by encouraging an atmosphere that rewards a "can do" attitude.PRINCIPAL DUTIES AND RESPONSIBILITIES*

  • Manages Information Security staff, including scheduling, performance evaluation, salary recommendation and related personnel actions.
  • Identifies areas of risk to firm, client and private information and leads risk assessments to determine appropriate remediation, serving as a liaison to General Counsel in this regard.
  • Works directly with firm clients to address information security concerns and complete written and in-house security audits, negotiating and implementing requested security training and technical measures.
  • Works with the business to review Outside Counsel Guidelines and Requests for Proposal, confirming the firm's ability to meet requirements and requesting changes as warranted.
  • Directs firm activities and resources to achieve and maintain compliance with information security standards such as state and federal privacy laws, ISO 27002/1, and GDPR.
  • Leads and coordinates the firm's operational response to information security incidents that threaten firm, client and private information, directing forensics and organizing communications. Identifies and reports on information security incidents to firm management.
  • Approves changes to firm systems, applications and policies that may affect the security of firm, client and private information. Serves as the internal auditor for information security processes.
  • Works closely with senior leaders, line-of-business managers, the IT organization, and others to establish an effective security governance framework, support the delegation of authority, handle budgets, ensure effective enterprise risk management and support the establishment of measurable controls.
  • Serves as an internal information security consultant to the Department and Firm. Advises the department with current information about information security technologies and related regulatory issues.
  • Develops a strategic vision for the security program; prioritizes resources for effective security policies, practices and processes; and develops an annual security plan. Identifies enterprise systems, processes, and information resources that require security protections.
  • Identifies areas where existing security architecture requires change or development. Ensures local security standards align with international and national standards. Stays up to date with Security (legal requirements, policy and technology) developments in the commercial world and especially in the area of the law so that the firm remains at the forefront of any security related developments affecting the firm and the firm's clients.
  • Monitors multiple logs across diverse platforms to uncover specific activities as they occur from platform to platform. Analyzes security analysis reports for security vulnerabilities and recommends feasible and appropriate options. Reports on significant trends and vulnerabilities.
  • Develops, maintains, publishes, and communicates enterprise-wide security standards, procedures and guidelines. Ensures that alignment to those standards is monitored and carried out.
  • Lead all aspects of the security infrastructure; for example identity and access management, firewalls, antivirus and intrusion detection system/intrusion prevention system. Monitors internal control systems to ensure that appropriate information access levels and security clearances are maintained. Monitors the security infrastructure for policy violations or security events, conducts security engineering, assists with resolution of escalated incidents and participates in problem management activities.
  • Improves security awareness and instills a risk-aware culture in the organization, ensuring that personnel fully understand the risk implications of their IT assets.
  • Measures and reports on the effectiveness and efficiency of security activities and capabilities. Manages, monitors, and matures security processes (for example, identity and access management; and threat and vulnerability management).
  • Oversees IT security within the system development lifecycle, change management, production systems support and technology-enabled projects (user administration, security logging, secure process flow, security standard methodologies).
  • Develops and leads information security projects, adhering to budgets, project plans, and business objectives.
  • Negotiates security-related software licensing and support agreements.
  • Assumes additional responsibilities as assigned. Required Skills
    • Critical thinking and planning abilities required.
    • Analytical thinking
      • Able to breakdown raw information and undefined problems into specific, workable components that in-turn clearly identify the issues at hand.
      • Makes logical conclusions, anticipates obstacles and considers different approaches that are relevant to the decision making process.
      • Team player with ability to effectively meet challenges, influence and drive consensus within the team.
      • Enterprise business knowledge
        • Solicits information on enterprise direction, goals and industry competitive environment to determine how own function can add value to the organization and to customers.
        • Makes decisions and recommendations clearly linked to the organization's strategy and financial goals, reflecting an awareness of external dynamics.
        • Risk management:
          • Identifies risks and obstacles to plans. Defines scarcity and conflicts of resource needs, and potential constraints.
          • Investigates risks within various project elements, assesses impact, and develops contingency plans to address major risks.
          • Knowledge of security issues, techniques, and implications across all existing computer platforms required.
          • Knowledge in networking, databases and systems operations is required.
          • Leadership skills are required.
          • Collaboration and influence skills are required.
          • Proven interpersonal and communication skills.
          • Demonstrated ability to prioritize tasks and effectively handle multiple responsibilities in a multifaceted environment.
          • Demonstrated problem solving abilities, analytical skills, and proven ability to meet challenging deadlines required.
          • Strong work ethic; excellent use of discretion and judgment. Excellent written communication skills.
          • Ability to work under stress and multi-task on various assignments; Detail orientation is a must.Education
            • Bachelor's Degree in Computer Science, Management or related work experience.
            • CISSP or other major security certification preferred. Required Experience
              • 5-7 years' work experience leading information security in a large and sophisticated environment; or other equivalent combination of education and experience that provides the required knowledge and skills.
              • Prior experience managing an Information Security, compliance or internal controls team preferred.
              • Knowledge of WilmerHale IT systems preferred.WilmerHale is an Equal Opportunity Employer. All qualified applicants will receive consideration without regard to race, color, religion, gender, sexual orientation, gender identity, national origin or ancestry, age, disability or veteran status, or other protected status. Job Location Boston, Massachusetts, United States Position Type Full-Time/Regular

Keywords: WilmerHale, Boston , Director, Information Security, Executive , Boston, Massachusetts

Click here to apply!

Didn't find what you're looking for? Search again!

I'm looking for
in category

Other Executive Jobs

Manufacturing Operations - Project Manager
Description: Manufacturing Operations - Project Manager Bachelor's degree in a related field Business or Technical --or equivalent experience is required plus a minimum of 2 years of relevant experience or Master's (more...)
Company: General Dynamics Mission Systems, Inc.
Location: Taunton
Posted on: 02/27/2021

Research and Development Manager
Description: Group: Magna Mechatronics, Mirrors Lighting Division: Autosystems America, Inc. Job Type: Permanent/Regular Location: Plymouth, MI, US, 48170 Belleville, ON, CA Ostrava, CZ Rivoli Turin, IT Sao Paolo, (more...)
Company: Magna International Inc.
Location: Plymouth
Posted on: 02/27/2021

Program Manager [Common Hardware Systems
Description: Careers - General Dynamics Mission Systems ul li Land li Sea li Air li Space li Cyber li About li News Events li Careers
Company: Regional Recreation Corporation of Wood Buffalo
Location: Taunton
Posted on: 02/27/2021

Business Director
Company: The Waterford at Plymouth
Location: Plymouth
Posted on: 02/27/2021

General Manager
Description: -The General Manager GM is responsible for management of the entire store operation. The GM will lead the management team to ensure execution of organizational objectives, initiatives, and achievement (more...)
Company: Global Partners LP
Location: Plymouth
Posted on: 02/27/2021

Senior Project Manager (Transportation - Design
Description: Career Opportunities with McMahon Associates A great place to work. Share with friends or Subscribe Current job opportunities are posted here as they become available. Subscribe to our RSS feeds to (more...)
Company: McMahon Associates
Location: Taunton
Posted on: 02/27/2021

Purchasing Manager, Construction
Description: Rivian--is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract.-- As a company, (more...)
Company: Via Transportation Inc
Location: Plymouth
Posted on: 02/27/2021

Operations Technology Manager
Description: JOB DESCRIPTIONOperations technology manager is responsible for leading key strategic activities related to IOT, Networking, Servers and systems with plant operations scope. This person functions as (more...)
Company: Adient plc
Location: Plymouth
Posted on: 02/27/2021

Addiction Medicine - Medical Director & Attending - Taunton, MA
Description: Taunton, Massachusetts Full Time Opportunity Details br Morton Hospital is seeking two full-time physicians to manage the future Level 4 detox facility at Morton, MORCAP. Physicians will manage the (more...)
Company: Health eCareers
Location: Taunton
Posted on: 02/27/2021

Director of Health, Safety & Risk Management
Description: Director of Health, Safety Risk Management Summary: The Rhode Island Interlocal Risk Management Trust The Trust is searching for a Director of Health, Safety Risk Management . br br Posted: (more...)
Company: Association-Governmental Risk
Location: East Providence
Posted on: 02/27/2021

Log In or Create An Account

Get the latest Massachusetts jobs by following @recnetMA on Twitter!

Boston RSS job feeds