Deep technical engineering expertise in technology infrastructure, Cloud, zero-trust architecture and cyber defense. Proven ability to leverage frameworks like NIST to build and operate a comprehensive defense in depth capability. Proven ability in change management, building trust with partners and transforming organizations. Experience in a global law firm, professional services firm, financial services institution, technology company, or similarly complex environment strongly preferred. Demonstrated success leading cybersecurity strategy, enterprise risk governance, incident response, regulatory and client-facing security matters, third-party risk, audit/certification programs, security awareness, and high performing teams. Experience advising senior executives, boards, managing partners, or equivalent governance bodies required.
Executive-level knowledge of cybersecurity strategy, governance, risk, compliance, privacy, data protection, incident response, threat intelligence, vulnerability management, identity and access management, cloud and network security, application security, endpoint protection, email security, encryption, logging and monitoring, disaster recovery, business continuity, third-party risk, DevSecOps, modernized secure development practices including AI SDLC, and secure technology adoption. Strong understanding of professional responsibility, client confidentiality, data classification, privilege-sensitive work, outside counsel guidelines, ethical walls, cross-border data considerations, and the security expectations of sophisticated global clients.
Demonstrated ability to translate technical risk into business and legal impact, influence senior stakeholders, lead through ambiguity, make sound risk-based decisions, and communicate with clarity, credibility, discretion, and urgency. Familiarity with ISO/IEC 27001, NIST, CIS Controls, data privacy laws, cyber insurance considerations, AI governance, and emerging legal sector cybersecurity risks strongly preferred. A leader who thrives on learning and is up to date with the fast-evolving technology landscape, especially the changing threats with the advancement of AI. Ability to not only understand security tools/needs, how these are changing but also go back to first principles in solving the underlying problems through innovation.
Demonstrate executive presence, credibility, sound judgment, and professional maturity in all interactions, particularly when advising firm leadership, senior partners, governance bodies, clients, regulators, vendors, and other high-impact stakeholders on sensitive, complex, or time-critical information security matters. Communicate with clarity, confidence, discretion, and appropriate urgency, translating complex technical, legal, operational, and risk issues into concise business terms that enable informed decisions by senior leaders and non-technical audiences. Influence senior leaders and stakeholders through trusted relationships, fact-based analysis, persuasive recommendations, and a firm-first approach that balances client expectations, legal and regulatory obligations, operational realities, risk appetite, and strategic business priorities.
Build alignment across a complex, matrixed, partner-led environment by listening effectively, anticipating concerns, managing competing perspectives, escalating appropriately, and helping leaders reach timely, defensible, and consistently supported decisions. Prepare and deliver executive-level briefings, written updates, risk narratives, Executive Committee materials, client-facing responses, and incident communications that are accurate, audience-appropriate, concise, and aligned with firm standards and confidentiality obligations. Lead difficult or sensitive conversations with diplomacy, composure, courage, and empathy, including situations involving cyber incidents, policy exceptions, risk acceptance, resource tradeoffs, control gaps, or competing leadership priorities.