Information Security Manager- Financial or Law Firm exp (Perm only/No Consultants) Job at Stone Search, LLC, New York, NY

d3J6Wm9VbENLbXFLa2pUbUpRUVRUMVlkZEE9PQ==
  • Stone Search, LLC
  • New York, NY

Job Description

Information Security Manager

NY, DC, or CT

*US Citizens or GC Holders

*on-site at first, once acclimated, hybrid 3 days on-site

Position Summary

The Information Security Manager is responsible for developing, implementing, and managing the firm’s information security program to protect sensitive client and firm data. This role ensures that the firm maintains strong cybersecurity practices, complies with legal industry security standards, and meets client security requirements. The Information Security Manager works closely with IT leadership, attorneys, and administrative departments to identify risks, implement safeguards, and respond to security incidents.

Key Responsibilities:

Information Security Program Management

  • Develop, implement, and maintain the firm’s information security strategy, policies, and procedures.
  • Establish and enforce security governance frameworks and best practices.
  • Conduct regular risk assessments and security audits to identify vulnerabilities and recommend mitigation strategies.
  • Maintain and update the firm’s security policies, standards, and guidelines.

Security Operations

  • Oversee monitoring of security systems including SIEM, endpoint protection, firewalls, and intrusion detection/prevention systems.
  • Coordinate incident detection, response, and investigation for cybersecurity events.
  • Manage vulnerability management and patch management programs.
  • Ensure security controls are implemented across network, systems, applications, and cloud environments.

Compliance & Risk Management

  • Ensure compliance with client security requirements, legal industry standards, and regulatory obligations.
  • Support security questionnaires, client audits, and third-party security assessments.
  • Maintain security documentation and evidence for compliance reviews.
  • Lead the firm’s cybersecurity risk management initiatives.

Third-Party Security & Vendor Management

  • Assess security risks associated with vendors and third-party service providers.
  • Conduct vendor security reviews and maintain a vendor risk management process.
  • Ensure contracts include appropriate security and confidentiality provisions.

Security Awareness & Training

  • Develop and deliver security awareness training programs for attorneys and staff.
  • Promote cybersecurity best practices and reduce risks related to phishing and social engineering.
  • Conduct regular security awareness campaigns and simulated phishing exercises.

Incident Response & Business Continuity

  • Develop and maintain the firm’s incident response plan.
  • Coordinate response activities during cybersecurity incidents.
  • Support business continuity and disaster recovery planning from a security perspective.

Collaboration with IT and Leadership

  • Work closely with IT operations teams to ensure secure system architecture and deployments.
  • Advise firm leadership on emerging cybersecurity risks and security investments.
  • Provide regular reports on security posture, incidents, and risk mitigation efforts.

Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, or a related field.
  • 5–8+ years of experience in cybersecurity or information security roles.
  • Experience managing or implementing enterprise security programs.
  • Experience in a law firm or professional services environment preferred.
  • Familiarity with protecting confidential and regulated data.

Technical Knowledge:

  • Security frameworks (NIST, ISO 27001, CIS)
  • Security monitoring tools (SIEM, EDR/XDR)
  • Identity and access management
  • Network and cloud security
  • Vulnerability management
  • Incident response and threat detection

Preferred Certifications:

  • CISSP
  • CISM
  • CISA
  • Security+
  • GIAC certifications

Job Tags

Permanent employment

Similar Jobs

Horizon Construction Group

Site Development - Multifamily Construction Projects Job at Horizon Construction Group

 ...plans, utility profiles, grading plans, and construction details. ~ Proven ability to drive schedules, coordinate multiple moving parts, and keep crews aligned to milestones. ~ Confidence working with subcontractors, inspectors, survey teams, and project managers in... 

Delta Gear, LLC

Program Manager Job at Delta Gear, LLC

The Delta Family of Companies offer competitive compensation packages, excellent Health Insurance, Prescription Drug Coverage, Dental, 401(k), and Vacation. No Relocation Assistance provided at this time, seeking local candidates only. PROGRAM MANAGER Delta...

GIE Media, Inc.

Assistant Editor Job at GIE Media, Inc.

 ...Assistant Editor GIE Media Inc., a B2B media company serving a wide range of industries, is seeking an Assistant Editor to join our...  ...for the print magazine and website Editing copy for print and digital products Developing and pitching story and multimedia content... 

EC Consulting NY LLC

Arborist Consultant Job at EC Consulting NY LLC

 ...Description Environmental Conservation Consulting NY, LLC is a leading arborist consulting firm serving New York City. We specialize in tree inspections, inventories, permitting, and on-site arborist oversight for major infrastructure and construction projects. We are... 

The New York Public Library

Library Information Assistant - Roosevelt Island Library Job at The New York Public Library

 ...Overview The New York Public Library (NYPL) has been an essential provider of free books, information, ideas, and education for all...  ...and materials. The Library is seeking a Library Information Assistant to provide service to patrons of all ages. Information...