Chief Information Security Officer

Morgan & Morgan, P.A.Orlando, FL
Onsite

About The Position

Morgan & Morgan is the largest plaintiff-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability. We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms. This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt. This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust.

Requirements

  • 10+ years in cybersecurity, including senior leadership roles in large, complex environments
  • Proven success leading security programs in high-data-sensitivity, fast-moving organizations
  • Demonstrated ability to communicate cyber risk clearly to executive leadership and Boards
  • Strong working knowledge of NIST Cybersecurity Framework (CSF) and/or ISO 27001
  • Strong working knowledge of Zero Trust architecture
  • Strong working knowledge of Incident response and crisis leadership
  • Strong working knowledge of Cloud and SaaS security at scale
  • Business-first approach to security focused on outcomes, not checklists
  • Comfort making trade-offs and defending decisions at the executive level
  • Calm, credible leadership during high-pressure situations
  • High integrity, sound judgment, and strong ethical foundation

Nice To Haves

  • CISSP, CISM, or equivalent credentials
  • Experience supporting AI platforms, analytics, or large-scale digital transformation
  • Proven partnership with CIOs, General Counsel, and Compliance leadership
  • Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar)

Responsibilities

  • Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale
  • Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment
  • Translate cyber risk into clear business impact for executive leadership and the Board
  • Guide security investment decisions that balance velocity, resilience, and client trust
  • Lead firm-wide risk assessments, threat modeling, and control maturity evaluations
  • Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning
  • Partner closely with Legal, Privacy, and Compliance leaders to ensure protection of sensitive client and case data, defensible security practices suitable for litigation discovery, and alignment with regulatory, contractual, and ethical obligations
  • Oversee third-party and vendor security risk management at national scale
  • Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology
  • Embed security into Agile software development and CI/CD pipelines, Cloud-native platforms and SaaS ecosystems, and AI-enabled legal workflows and analytics platforms
  • Implement Zero Trust principles using pragmatic, developer-friendly controls
  • Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys
  • Oversee security operations including Identity & Access Management (IAM), Endpoint, network, and cloud security, and Security monitoring, detection, and response
  • Continuously improve detection, response time, and operational resilience
  • Ensure security operations remain resilient and effective during high-volume, time-sensitive legal operations
  • Ensure security capabilities scale effectively across 140+ offices and 1,000+ lawyers
  • Build, lead, and mentor a high-caliber, hands-on security organization
  • Establish strong operating models between Security, IT, Engineering, and the business
  • Set clear expectations and a high bar for execution, accountability, and follow-through across the security function
  • Champion a culture where security is designed in early, not bolted on late
  • Operate close to the technology engaging directly with teams, systems, and incidents when needed
  • Act as a visible, trusted executive leader approachable, decisive, and credible

Benefits

  • Comprehensive medical, dental, vision, and mental health benefits
  • Generous paid time off
  • Strong onboarding and leadership support
  • 401(k) plan
  • Paid holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service