Senior Manager Information Security

Honigman LLP
MI, United States
Full-time

Honigman is a premier business law firm with an international practice. Consistently recognized in Metropolitan Detroit as one of the Best and Brightest Places to Work , we earned this recognition by recruiting attorneys and staff members with outstanding credentials.

We are looking for an experienced Senior Manager, Information Technology for our Detroit, Chicago or Washington D.C. Office.

In addition to Detroit, we have offices in Chicago, IL, Washington D.C., Bloomfield Hills, Ann Arbor, Kalamazoo, Grand Rapids, and Lansing.

With more than 300 attorneys working in 60 different areas of concentration, Honigman provides timely and cost-effective counsel to clients in numerous industries.

The Senior Manager, Information Security reports to the Chief Information Officer and leads a highly collaborative and results-oriented team tasked with developing and implementing a comprehensive information security strategy to safeguard the firm's sensitive data, intellectual property, and client information.

This strategic leader will collaborate with internal stakeholders, legal professionals, and IT teams to ensure the confidentiality, integrity, and availability of our information assets.

The Senior Manager, Information Security will also play a critical role in overseeing and managing relationships with third-party vendors to ensure that the firm's cybersecurity standards are upheld throughout the supply chain.

RESPONSIBILITIES

1.) Security Strategy and Planning :

  • Develop and implement a robust information security strategy aligned with the firm's business goals and regulatory requirements.
  • Evaluate and assess the firm's current security posture, identifying vulnerabilities and recommending appropriate measures for improvement.
  • Conduct security best practice analysis of : servers; group policy; desktops / laptops; applications; mobile devices, routers / switches;

firewalls; and printers.

  • Develop least privilege access policy relative to requirements for Windows environment and audit file share access permissions.
  • Assist with completion of Project Security & Privacy template.

2.) Risk Management :

  • Conduct risk assessments and regularly update risk profiles to proactively address potential threats and vulnerabilities.
  • Collaborate with legal teams to ensure compliance with industry regulations and client-specific security requirements.

3.) Incident Response and Management :

  • Establish and maintain an incident response plan to effectively respond to and mitigate security incidents.
  • Lead investigations into security breaches and incidents, providing timely and accurate reports to executive leadership.
  • Collaborate with vendors to develop and test incident response plans, ensuring a coordinated and efficient response in the event of a security incident.
  • Clearly define the roles and responsibilities of both the vendor and the law firm in the event of a data breach or other security events.
  • 4.) Security Awareness and Training :
  • Develop and deliver ongoing cybersecurity training programs for employees to enhance awareness and promote a culture of security.
  • Foster a proactive security mindset across the organization.

5.) Technology Evaluation and Integration :

  • Stay abreast of emerging security technologies and trends, evaluating their relevance and potential impact on the firm.
  • Collaborate with IT teams to integrate security measures into technology infrastructure and applications.

6.) Vendor Management : By actively managing vendor relationships in this comprehensive manner, the Senior Manager, Information Security ensures that the entire ecosystem surrounding the law firm operates with a unified commitment to information security, safeguarding not only the firm's data but also the data entrusted to it by clients and other stakeholders.

A.) Risk Assessment and Due Diligence :

  • Conduct thorough risk assessments of potential vendors before engagement, evaluating their cybersecurity practices and assessing their ability to safeguard sensitive information.
  • Implement a due diligence process that includes evaluating the vendor's security policies, incident response capabilities, and overall cybersecurity posture.

B.) Contractual Agreements :

  • Work closely with the legal team to incorporate robust cybersecurity clauses into contracts with vendors. These clauses should outline specific security requirements, standards, and expectations.
  • Ensure that vendor contracts include provisions for regular security audits and assessments to monitor compliance.

C.) Security Audits and Assessments :

  • Periodically audit and assess vendor security controls and practices to ensure ongoing adherence to contractual agreements and industry standards.
  • Collaborate with internal audit teams or external experts to conduct comprehensive assessments of critical vendors.

D.) Continuous Monitoring :

  • Establish mechanisms for continuous monitoring of vendor activities related to information security.
  • Implement tools and processes to track and evaluate changes in the vendor's security posture over time, promptly addressing any identified risks or vulnerabilities.

E.) Regular Reporting and Communication :

  • Provide regular updates to executive leadership on the status of vendor security, highlighting any emerging risks or areas of improvement.
  • Establish open lines of communication with vendors to address concerns, share best practices, and foster a collaborative approach to cybersecurity.

F.) Contract Renewals and Review :

  • During contract renewals, revisit and update cybersecurity clauses based on changes in the regulatory environment, industry standards, or the firm's own security policies.
  • Evaluate the vendor's performance against cybersecurity metrics and consider this information when deciding on contract renewals.

G.) Training and Awareness :

  • Provide guidance and training to vendors on the firm's security policies and expectations.
  • Foster a shared responsibility for security, encouraging vendors to adopt a proactive approach to cybersecurity.

QUALIFICATIONS

Proven experience as an Information Security Manager or in a senior leadership role within information security.

Strong understanding of cybersecurity frameworks, principles, technologies, and best practices.

Strong understanding of ISO security and privacy standards. (ISO 27001 / 27701)

Familiarity with relevant legal and regulatory requirements.

Excellent communication and interpersonal skills.

Strong team-orientation and ability to collaborate across business segments and with personnel at all levels of the organization.

High-level presentation skills.

Very strong leadership, analytical , project management, negotiation and problem solving skills.

Proven management skills and demonstrated ability to foster an inclusive team where everyone has opportunities to develop and succeed.

Experience with successfully leading, developing, and managing change management initiatives that served to advance organizational information security performance.

Maintain expert understanding of key market trends in functional area.

Demonstrated critical thinking skills.

Preferred certifications include :

Certified Information Systems Security Professional (CISSP)

Certified Authorization Professional (CAP)

Certified Information Security Manager (CISM)

GIAC Security Leadership (GSLC)

Bachelor’s and / or Master’s degree in Information Security, Computer Science, or a related field.

Honigman is an Equal Opportunity Employer and does not discriminate on the basis of race, color, religion, sex, age, national origin, veteran status, marital status, sexual orientation, disability or any other category prohibited by applicable local, state or federal law.

This policy applies to all aspects of employment, including recruitment, placement, promotion, transfer, demotion, compensation, benefits, and termination.

2 days ago
Related jobs
Promoted
Honigman LLP
MI, United States

The Senior Manager, Information Security reports to the Chief Information Officer and leads a highly collaborative and results-oriented team tasked with developing and implementing a comprehensive information security strategy to safeguard the firm's sensitive data, intellectual property, and client...

Promoted
Venteon
MI, United States

Proven experience in Information Security Management or a senior leadership role. Create ongoing cybersecurity training to promote awareness and foster a security-focused culture. Experience leading change management in information security. Bachelor’s or Master’s degree in Information Security, Com...

Promoted
Confluent
Lansing, Michigan

What You Will Do:Lead and develop the Detection and Response team, and advance the maturity of our capabilities to ensure effective security operationsHelp solve detection engineering problems in a multi-cloud, multi-region, and multi-account environment leveraged by many engineering teamsIdentify w...

Chelsea Search Group
Detroit, Michigan

The Senior Manager, Information Security reports to the Chief Information Officer and leads a highly collaborative and results-oriented team tasked with developing and implementing a comprehensive information security strategy to safeguard the firm's sensitive data, intellectual property, and client...

Total Security Solutions
Fowlerville, Michigan

Project Manager Job Description As a Project Manager you are responsible for managing $800K - $2. As one of our Project Managers, you will provide excellent customer service by properly forecasting our projects and will be a problem preventer as well as a problem solver. You will work hand-in-hand w...

McLaren Health Care Corp
Grand Blanc, Michigan

Responsible for the management of IT Security systems in a large enterprise, and designing, implementing, and maintaining security measures to protect our organization's computer systems, networks, and data from cyber threats. Information Technology with 5 years in a security focused role. Bachelor’...

University of Michigan
Ann Arbor, Michigan

The University of Michigan Office of the Vice President for Research (OVPR) seeks a Research Information Security Manager to assist the Assistant Director, Research Information Security in supporting the Research Information Security Oversight (RISO) program. In coordination with university units (I...

DCS Corp
Sterling Heights, Michigan

The Information System Security Manager is the principal information assurance professional responsible for maintaining the security posture of an accredited DoD system. BS degree in Information Technology, Cybersecurity, Data Science, Information Systems or Computer Science with 12 years of experie...

American Axle & Manufacturing, Inc
Detroit, Michigan

Manager Information Security - ICS/OT Cybersecurity. Manager Information Security - ICS/OT Cybersecurity. This position will report to the Chief Information Security Officer (CISO) and support the people, process and technology enhancements required for successful cybersecurity risk management withi...

Rise Technical
Michigan

This position entails compliance with all company policies and procedures, as well as the installation and administration of network security solutions, ensuring software is up-to-date with the latest security patches, delivering security training for the IT team, and documenting and enforcing infor...