Director, AI Security

Gibson DunnNew York, NY
$300,000 - $380,000Onsite

About The Position

Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision. Based in New York, the Director of AI Security will work directly with the CISO to define the firm’s AI security strategy and determine and build the function required to deliver it — its shape, its size, its sequencing and its budget. This is the firm's first dedicated AI security role, with no inherited team or playbook; defining the team required to deliver the strategy is a key part of the role. The position requires the ability to engage credibly with senior executives and practice group leadership on strategy, while also reasoning about technical details such as token scopes and prompt injection. This role reports to the Chief Information Security Officer.

Requirements

  • Strong strategic and analytical thinking, with a track record of building a security capability from the ground up rather than inheriting one.
  • Ability to operate at executive level — setting strategy, making the business case for investment, and holding your position with senior stakeholders under pressure to move quickly.
  • Ability to influence without formal authority and earn trust in a partnership environment, including from fee earners.
  • Excellent written and verbal communication, including with clients and regulators.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
  • 10+ years of information security experience, including end-to-end ownership of a significant security domain.
  • Deep, practical experience securing production AI and LLM systems, including AI-specific threats such as prompt injection and data leakage.
  • Strong identity and access management foundations (OAuth 2.0, OIDC, SAML, delegation patterns, machine identity at scale).
  • Security architecture experience across cloud (Azure and/or AWS) and SaaS-heavy environments.
  • Experience applying AI or automation to measurably improve security operations.

Nice To Haves

  • Relevant certifications (CISSP, CCSP, CISM, or equivalents) a plus.

Responsibilities

  • Define the firm's AI security strategy, target architecture, and multi-year roadmap in partnership with the CISO, and secure executive endorsement.
  • Design, budget, recruit, and lead the AI security function, including team structure, tooling, and build-versus-buy decisions.
  • Establish the security control framework for AI systems.
  • Own the security review stage of the AI use-case intake and approval process, ensuring a clear and timely path from proposal to production.
  • Partner with the Office of General Counsel and the Cyber & Data Governance Committee on obligations relating to confidentiality, privilege, and competent use of technology.
  • Build relationships with partners, practice group leaders, and business leaders to understand the drivers of AI adoption and translate business needs into secure delivery options.
  • Present AI risk and strategy to executive stakeholders and, where required, to clients.
  • Conduct security architecture and design reviews for AI platforms, RAG pipelines, agent frameworks, and in-house builds.
  • Define controls against AI-specific threats, including prompt injection, tool abuse, data leakage, supply chain compromise, and cross-matter contamination.
  • Address unsanctioned AI use through discovery, sanctioned alternatives, and clear guidance, in partnership with IT and the practice groups.
  • Own the firm's agentic identity model, governing how agents, service accounts, and tool integrations are issued identity, authenticated, scoped, and revoked.
  • Establish lifecycle governance for non-human identities, including registration, ownership, entitlement review, credential rotation, and decommissioning.
  • Define authorization patterns for delegated access, ensuring agents never exceed user entitlements and that ethical walls and matter-level restrictions hold.
  • Set governance standards for tools and connectors, including MCP servers and equivalent integration layers.
  • Ensure every consequential agent action is auditable and attributable to an identity, delegating principal, and matter context.
  • Develop and own the roadmap for applying AI within the security function.
  • Identify and deliver high-value use cases such as alert triage, detection engineering, investigation support, and third-party risk review.
  • Set operating standards for the security function's own AI systems, including autonomy limits, human review points, and ongoing evaluation.
  • Maintain a current view of AI-enabled threats to the firm and ensure defenses and awareness training keep pace.
  • Measure and report operational impact of AI investments.
  • Establish AI red teaming and adversarial testing programs, with findings tracked to remediation.
  • Define pre-deployment and change-driven security evaluation criteria for AI systems, including guardrail regression testing.
  • Own AI-specific incident response playbooks and support the IR team on AI-related events.
  • Lead security assessments of AI vendors and legal-tech platforms.
  • Translate emerging regulation and guidance (e.g., EU AI Act, bar association guidance) into control requirements.
  • Deputize for the CISO on AI matters at management and committee level.

Benefits

  • health care
  • retirement benefits
  • paid days off, including sick time, and vacation time
  • parental leave
  • basic life insurance
  • Flexible Spending Accounts
  • discretionary, performance-based bonuses
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service