Deputy Chief Information Security Officer
Gibson Dunn
Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision.
Based in London, the Deputy Chief Information Security Officer (Deputy CISO) serves as the second-in-command of the information security organization, partnering with the CISO to define and execute the enterprise security strategy. This role combines strategic leadership with operational oversight, ensuring security programs run effectively while preparing to assume full CISO responsibilities when needed.
This role reports to the Chief Information Security Officer.
Responsibilities include:
Strategic Leadership
- Partner with the CISO to develop and maintain the enterprise information security strategy, roadmap, and governance framework.
- Represent the security organization to executive leadership, the board, and other internal and external stakeholders in collaboration with the CISO.
- Drive alignment between security initiatives and business objectives across the Firm.
- Lead strategic planning for emerging risks, regulatory changes, and technology shifts.
Operational Oversight
- Support the CISO with the day-to-day management of the security function, including security operations, security engineering & architecture, governance, risk & compliance and physical security.
- Manage security metrics, reporting, and executive dashboards to provide visibility into risk posture.
- Maintain a list of inflight security initiatives and report status to the CISO and other stakeholders.
- Coordinate cross-functional security initiatives with IT, information governance and other areas of the business as required.
Team Leadership & Development
- Lead, mentor, and develop a team of security managers and senior technical staff.
- Build a high-performing, inclusive security culture focused on continuous improvement.
- Own workforce planning, hiring, and succession planning for the security organization.
- Foster professional development and career growth across the team.
Incident & Crisis Management
- Serve as key member of the incident response team.
- Lead post-incident reviews and drive lessons-learned improvements.
- Support proactive crisis tabletop exercises.
Qualifications:
- Proven ability to communicate security risk to executive audiences in business terms.
- Confident communicator who builds trust with technical/non-technical stakeholders.
- Ability to balance long-term vision with pragmatic, risk-based prioritization.
- Works effectively across organizational boundaries; influences without authority and provides calm, decisive leadership during incidents and crises.
Experience:
- Bachelor's degree in computer science, information security, or related field (or equivalent experience); master’s degree preferred.
- 10+ years of progressive experience in information security, with at least 5 years in senior leadership roles.
- Industry certifications such as CISSP, CISM, CISA, or CRISC.
- Background in both enterprise and cloud-native security environments.
- Demonstrated experience building and leading security teams with a track record of leading security during M&A, digital transformation, or rapid growth.
- Deep expertise across multiple security domains: governance/risk/compliance, security architecture, operations, identity & access management, application security, or cloud security.
- Strong understanding of regulatory and compliance frameworks relevant to the industry.
- Experience managing security budgets and vendor relationships.
Gibson Dunn will consider for employment qualified Applicants with Criminal Histories in a manner consistent with the requirements of local law.
For technical difficulties with our online application, please contact us at [email protected]. Our recruiting support team will respond as soon as possible.
Gibson Dunn is committed to ensuring equal employment opportunities for all qualified applicants, including individuals with disabilities. We strive to ensure an inclusive and accessible hiring experience. The Firm will provide reasonable accommodations to qualified individuals with disabilities to enable participation in the application and recruitment process, unless doing so would impose an undue hardship, in accordance with applicable laws and regulations.
If you require a reasonable accommodation to complete an application, participate in an interview, or otherwise take part in the recruitment process, please contact us at [email protected]. Please note, this is a dedicated email inbox established exclusively to assist applicants with accommodation request related to the recruitment process. Inquiries about the status of an application or other non-accommodation matter will not receive a response.
Similar jobs
More Security jobs →Relief Security Officer
Securitas
Company Description We’re Hiring: Relief Security Officer! Location: London, WC1B 5EH Pay: £13.85 per hour Hours: Guaranteed 24 hours per week, with the potential to work additional hours across days,…
Field Officer - Electronic Monitoring West London
Serco
Location: Stevenage any CB or IP28 postcode Due to the nature of the role and operational requirements you must live within the SG postcode area Caring. Compassionate. Resilient. Sound like you? You…
Information Security Manager (12 month fixed-term maternity cover)
Legatics
Role Purpose Legatics handles some of the world’s most complex and confidential legal transactions, so information security is core to the product and to client trust. The Information Security Manager…