Manager/Senior Manager, Information Security
25 days ago
New York
Job Description Incisive. Inclusive. Invested. We’re Axinn. Experienced, tenacious, and always trial-ready, we are committed to understanding complex legal challenges that impact the future of our clients' businesses, globally. Focusing on antitrust, intellectual property, and high-stakes litigation, our extensive teams in the U.S. possess deep knowledge and client-side experience across a range of sectors, including technology, healthcare, life sciences, and consumer products. At Axinn, inclusivity is central to who we are. We have a purpose that goes beyond profit, which includes fostering a fair, welcoming workplace and supporting the communities where we live and work. We actively recognize talent and promote opportunities for all team members. By embracing the unique experiences and perspectives of our people, we fuel creativity and deliver results for our clients. The Firm’s Manager of Information Security is responsible for establishing and leading a comprehensive, enterprise-wide information security program that safeguards the firm’s data, systems, and client information. This role provides strategic direction to ensure the confidentiality, integrity, and availability of information assets across the firm’s technology and business operations. The position partners closely with executive leadership, IT, legal stakeholders, and business leaders to align security initiatives with organizational objectives, risk tolerance, and regulatory obligations. The Manager of Information Security drives the development of policies, frameworks, and governance structures that support compliance with client requirements, industry standards, and evolving regulatory expectations. Serving as a trusted advisor to firm leadership, this role oversees security strategy, risk management, and program maturity, while fostering a culture of security awareness across the firm. The position also leads and develops security personnel, ensuring effective execution through strong delegation, oversight, and continuous improvement, enabling the firm to proactively respond to an increasingly complex threat landscape.Duties and Responsibilities: • Establish and lead the firm’s enterprise information security program, ensuring alignment with business strategy, regulatory requirements, and client confidentiality obligations, • Define and maintain a comprehensive governance framework, including security policies, standards, and procedures that support firm-wide risk management objectives, • Develop and report on key risk and performance metrics, providing regular updates and strategic insights to executive leadership and stakeholders, • Direct the identification, assessment, and mitigation of cybersecurity risks, ensuring a proactive and risk-based approach to protecting firm assets, • Oversee incident response strategy and execution, ensuring timely investigation, containment, remediation, and executive-level reporting, • Champion organizational readiness through the development of incident response playbooks and leadership of regular tabletop exercises, • Ensure ongoing compliance with applicable frameworks and obligations (e.g., NIST, ISO, HIPAA), as well as evolving client security requirements, • Lead firm-wide security awareness and training initiatives to foster a strong culture of security across attorneys and business staff, • Provide strategic oversight of security technologies and platforms, ensuring effective capabilities, integration, and return on investment, • Partner with IT, Legal, Compliance, and business leaders to embed security into operations, third-party risk management, and cloud strategy, • Oversee enterprise risk assessments and remediation programs, communicating priorities, progress, and outcomes to senior leadership, • Build, lead, and develop a high-performing information security team, including mentoring, performance management, and capability growth, • Perform other leadership duties as required to support the firm’s security and risk management objectives Education • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; Master’s degree in Information Security, Business Administration, or a related discipline strongly preferred., • Advanced security certifications highly desirable (CISSP, CISM, CISA, CRISC, CCSP)., • Ongoing professional development in cybersecurity, risk management, or leadership is highly valued. Experience: • Minimum of 10 years of progressive experience in information security, IT risk management, or cybersecurity leadership roles., • Proven track record leading enterprise-wide security programs, aligning cybersecurity strategy with organizational goals., • Extensive experience overseeing incident response, vulnerability management, and compliance initiatives at scale., • Demonstrated ability to manage and mentor multi-level security teams, including managers and senior analysts., • History of influencing executive leadership and participating in strategic planning for enterprise risk management., • Experience with budget planning, vendor management, and cross-functional security initiatives. Skills and Competencies: • Deep knowledge of enterprise security frameworks and standards (ISO/IEC 27001, NIST CSF, CIS Controls, SOC 2) and regulatory compliance requirements., • Strategic oversight of security architecture, risk assessment, incident response, and threat intelligence programs., • Exceptional leadership, organizational, and project management skills with the ability to drive complex, multi-team initiatives., • Excellent communication skills, capable of translating complex security concepts and risk assessments for executive leadership and boards., • Strong business acumen, with the ability to balance security priorities against operational and financial considerations., • Demonstrated ability to foster a security-conscious culture across all levels of the organization., • Experience evaluating emerging threats, technologies, and vendor solutions to inform enterprise security strategy and investments. Benefits At Axinn, we offer market competitive wages and generous benefit options to our valued employees. This includes, but is not limited to, the following: • Competitive starting pay and annual discretionary bonus and raise eligibility, • Generous paid time off benefits (vacation, personal days, holidays, and sick leave), • Firm paid short and long-term disability, plus life and accident insurance, • 401(k) Profit Sharing Plan and Cash Balance Retirement Plan with generous employer contributions (please ask for further details re: eligibility requirements), • Comprehensive medical, dental, and vision insurance options, • Flexible spending and health savings accounts (medical plan dependent), • Firm paid comprehensive Employee Assistance Program (EAP), • Student loan refinancing discounts, • Lifestyle reimbursement program This is a full-time, benefits eligible, exempt level position. Final rate of pay and title will be commensurate with the incumbent’s experience, with a targeted hiring range of $160,000 - $225,000 (the upper range reserved for highly qualified applicants). This position is currently available in either our NY, CT, or DC office locations. Axinn is an equal employment opportunity employer and is committed to creating an environment that draws upon the strength of the diversity of its workforce to achieve excellence in the Firm's field and beyond