Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
AFS

Director of Information Security

AFS

. Lead development, operation, and continuous improvement of the firm’s information security, cybersecurity, privacy, compliance, and technology risk programs .

Posted 10/2/2026full-timeUnited StatesLead💰 $231,000 - $371,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in leading and managing comprehensive cybersecurity, information security, and technology risk programs, with a strong focus on compliance and governance across various platforms and technologies. Proven ability to develop security strategies, oversee incident response, and integrate security into enterprise initiatives while managing budgets and stakeholder communications.

Highest-signal resume keywords
Cybersecurity LeadershipInformation Security StrategyCompliance ManagementCloud Security GovernanceRisk Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
CybersecurityInformation SecurityTechnology Risk ManagementSecurity ArchitectureIncident ResponseVulnerability ManagementData ProtectionIdentity And Access ManagementSecurity AuditsAI Risk Management
Soft Skills
Stakeholder CommunicationTeam LeadershipTraining And Awareness PromotionPolicy EnforcementStrategic Planning
Tools & Technologies
Microsoft 365AzureMicrosoft DefenderMicrosoft SentinelReliaQuestProofpointAbnormal SecurityNetskopeMicrosoft PurviewMicrosoft Intune
Certifications & Qualifications
CISSPCISMCISA
Industry Keywords
Legal ServicesFinancial ServicesHealthcareISO/IEC 27001NIST Cybersecurity FrameworkZero Trust PrinciplesCIS ControlsRegulatory ComplianceCloud ApplicationsThird-Party Services

Tech Stack

Tools & technologies
AzureCloudCyber Security

About the role

Key responsibilities & impact
  • Lead development, operation, and continuous improvement of the firm’s information security, cybersecurity, privacy, compliance, and technology risk programs
  • Define security strategy, governance, architecture, controls, and operational capabilities across cloud services, identity, applications, endpoints, networks, email, data, AI, and third-party services
  • Develop and execute the firm’s information security strategy, governance framework, policies, standards, and annual security roadmap
  • Lead enterprise cybersecurity, privacy, risk management, and compliance programs aligned with laws, regulations, client requirements, and industry frameworks
  • Establish security requirements and governance for cloud services, AI, generative AI, machine learning, autonomous agents, and emerging technologies
  • Direct enterprise risk assessments, security architecture reviews, and control evaluations
  • Oversee threat monitoring and detection, vulnerability management, incident response, forensic investigations, and security engineering
  • Govern identity and access management, data protection, network security, endpoint security, application security, cloud security, and third-party technology integrations
  • Support business continuity, disaster recovery, and physical security programs
  • Advise leadership, business stakeholders, clients, auditors, and vendors on cybersecurity, privacy, regulatory, and technology risk matters
  • Lead client security audits, security questionnaires, Outside Counsel Guidelines reviews, Requests for Proposal, and client-driven security assessments
  • Direct vendor security reviews and due diligence
  • Partner with Technology Services, Innovation, administrative departments, and business leaders to integrate security into enterprise projects and technology initiatives
  • Promote security awareness through training, communication, policy enforcement, and ongoing education
  • Define and report cybersecurity metrics, program maturity, emerging risks, and strategic initiatives to executive leadership
  • Manage security budgets, contracts, projects, and strategic investments

Requirements

What you’ll need
  • Bachelor’s degree in a related field, specialized training, or equivalent professional experience
  • Relevant industry certification such as CISSP, CISM, CISA, or comparable credential
  • Eight or more years of progressively responsible experience in cybersecurity, information security, technology risk, privacy, compliance, security architecture, or related discipline
  • At least three years in a leadership role
  • Demonstrated success leading a multidisciplinary security program in a legal, professional services, financial services, healthcare, or similarly sensitive and regulated environment
  • Law firm or professional services experience strongly preferred
  • Experience developing and operating enterprise security capabilities across Microsoft 365, Azure, Entra ID, cloud applications, email, endpoints, networks, data, APIs, and third-party services
  • Experience with platforms such as ReliaQuest, Proofpoint, Abnormal Security, Netskope, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Microsoft Intune
  • Experience evaluating the security, privacy, compliance, and operational impact of AI and AI-enabled applications
  • Experience governing OAuth applications, Microsoft Graph permissions, enterprise application registrations, privileged and workload identities, certificates, service accounts, secrets, and role-based access controls
  • Experience leading incident response, vendor assessments, remediation efforts, client and ISO audits, security awareness initiatives, and executive risk reporting
  • Experience applying ISO/IEC 27001, ISO/IEC 27002, NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, and Zero Trust principles
  • Experience managing security teams and providers, budgets, contracts, implementation projects, and service levels

Benefits

Comp & perks
  • Performance-based bonus, payable monthly or annually for eligible positions
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Profit-sharing
  • Generous paid time off
  • Flexible benefit options
  • Flexible reimbursement account supporting personal well-being expenses