Jobs and Careers
WO

Director of Information Security

Womble Bond Dickinson (US) LLP
United Statesfull_timeVerifiedPosted 13 Mar 2025

About the role

Womble Bond Dickinson (US) LLP is seeking a Director of Information Security (DIS) to join their team in Winston-Salem, North Carolina. The ideal candidate will be highly strategic, detail-oriented, and possess a strong background in information security management. They should have excellent leadership and communication skills, with a proven track record of implementing effective cybersecurity measures and leading high-performing teams.  The DIS reports to the CIO and works closely with Administrative Department Heads, Office of General Counsel, key attorneys and business professionals. 

 

RESPONSIBILITIES

  • Develop and implement a comprehensive cybersecurity strategy that aligns with the Firm’s business objectives.
  • Oversee the creation of a security policy and enforcement of procedures to protect information assets.
  • Conduct information security risk assessments to identify vulnerabilities and develop mitigation plans.
  • Lead incident response efforts to quickly address and recover from any security incident.
  • Ensure compliance with industry-relevant regulations and standards.
  • Build and maintain a firmwide business continuity and disaster recovery planning with annual BC/DR testing.
  • Responsible for security architecture review and secure development practices.
  • Facilitate employee security awareness training & testing program.
  • Work with the General Council and Risk Management Committee to approve and execute annual penetration testing.
  • Collaborate with other executives to integrate cybersecurity measures with overall business strategies.
  • Manage the security budget and optimize resource allocation for maximum protection.
  • Establish metrics and reporting mechanisms to monitor the effectiveness of security initiatives. 
  • Evaluate and implement new security technologies and tools to enhance the FIRM’s defenses.
  • Maintain relationships with external partners, security professionals, and vendors to ensure robust security measures.
  • Mentor and develop the security team, promoting continuous learning and professional growth.
  • Provide regular updates to the CIO and Risk Management Committee on the state of the firm’s security posture.
  • Maintain a firmwide oversight of third-party information security assessment and vendor management.
  • Stay abreast of emerging threats and industry trends to continuously evolve the security strategy.
  • Engage in continuing education and attend conferences to stay current with modern security tactics and techniques.

 

REQUIREMENTS:

  • BSc/BA in Computer Science, Information Technology, or a related field.  
  • A master's degree in cybersecurity or a relevant management degree is preferred.  
  • 5+ years of experience in executive leadership roles, ideally as a security manager or in a similar position.  
  • Relevant certifications such as CISSP, CISM, or CISA.
  • Proven experience in leadership roles, ideally as a Security Manager or in a similar position.
  • The ability to build and lead high-performing security teams.
  • Excellent strategic planning and risk management capabilities.
  • An understanding of cybersecurity frameworks, compliance regulations, and industry standards.
  • Exceptional communication skills, both written and verbal, with the ability to convey complex security concepts to non-technical stakeholders.
  • Strong decision-making and problem-solving skills, with the ability to quickly respond to security incidents and anticipate potential threats.
  • Experience in budget management and optimizing resource allocation for security initiatives.
  • Hands on experience with cloud security, data analysis and security performance metrics.
  • Demonstrable competency in managing relationships with external partners, vendors, and regulatory bodies.
  • Experience in managing geographically dispersed security teams.
  • Working knowledge of IT infrastructure, network security, legal holds, eDiscovery and information governance.
  • Experience in incident response planning and disaster recovery.
  • A willingness to keep up with emerging threats and technologies and adapt security strategies accordingly.

 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Womble Bond Dickinson (US) LLP

View company profile →