Back to jobs
New

Director, AI Security

New York City

Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision.

Based in New York, the Director of AI Security will work directly with the CISO to define the firm’s AI security strategy and determine and build the function required to deliver it — its shape, its size, its sequencing and its budget. This is the firm's first dedicated AI security role, with no inherited team or playbook; defining the team required to deliver the strategy is a key part of the role. The position requires the ability to engage credibly with senior executives and practice group leadership on strategy, while also reasoning about technical details such as token scopes and prompt injection.

This role reports to the Chief Information Security Officer.

Responsibilities include:

AI Security Strategy & Program Development

  • Define the firm's AI security strategy, target architecture, and multi-year roadmap in partnership with the CISO, and secure executive endorsement.
  • Design, budget, recruit, and lead the AI security function, including team structure, tooling, and build-versus-buy decisions.
  • Establish the security control framework for AI systems.
  • Own the security review stage of the AI use-case intake and approval process, ensuring a clear and timely path from proposal to production.
  • Partner with the Office of General Counsel and the Cyber & Data Governance Committee on obligations relating to confidentiality, privilege, and competent use of technology.

 Stakeholder Engagement & Secure AI Enablement

  • Build relationships with partners, practice group leaders, and business leaders to understand the drivers of AI adoption and translate business needs into secure delivery options.
  • Present AI risk and strategy to executive stakeholders and, where required, to clients.
  • Conduct security architecture and design reviews for AI platforms, RAG pipelines, agent frameworks, and in-house builds.
  • Define controls against AI-specific threats, including prompt injection, tool abuse, data leakage, supply chain compromise, and cross-matter contamination.
  • Address unsanctioned AI use through discovery, sanctioned alternatives, and clear guidance, in partnership with IT and the practice groups.

 Identity & Access Management for AI Systems

  • Own the firm's agentic identity model, governing how agents, service accounts, and tool integrations are issued identity, authenticated, scoped, and revoked.
  • Establish lifecycle governance for non-human identities, including registration, ownership, entitlement review, credential rotation, and decommissioning.
  • Define authorization patterns for delegated access, ensuring agents never exceed user entitlements and that ethical walls and matter-level restrictions hold.
  • Set governance standards for tools and connectors, including MCP servers and equivalent integration layers.
  • Ensure every consequential agent action is auditable and attributable to an identity, delegating principal, and matter context.

 AI-Enabled Security Operations

  • Develop and own the roadmap for applying AI within the security function.
  • Identify and deliver high-value use cases such as alert triage, detection engineering, investigation support, and third-party risk review.
  • Set operating standards for the security function's own AI systems, including autonomy limits, human review points, and ongoing evaluation.
  • Maintain a current view of AI-enabled threats to the firm and ensure defenses and awareness training keep pace.
  • Measure and report operational impact of AI investments.

 Assurance, Risk & Compliance

  • Establish AI red teaming and adversarial testing programs, with findings tracked to remediation.
  • Define pre-deployment and change-driven security evaluation criteria for AI systems, including guardrail regression testing.
  • Own AI-specific incident response playbooks and support the IR team on AI-related events.
  • Lead security assessments of AI vendors and legal-tech platforms.
  • Translate emerging regulation and guidance (e.g., EU AI Act, bar association guidance) into control requirements.
  • Deputize for the CISO on AI matters at management and committee level.

 Qualifications:

  • Strong strategic and analytical thinking, with a track record of building a security capability from the ground up rather than inheriting one.
  • Ability to operate at executive level — setting strategy, making the business case for investment, and holding your position with senior stakeholders under pressure to move quickly.
  • Ability to influence without formal authority and earn trust in a partnership environment, including from fee earners.
  • Excellent written and verbal communication, including with clients and regulators.

Experience:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
  • 10+ years of information security experience, including end-to-end ownership of a significant security domain.
  • Deep, practical experience securing production AI and LLM systems, including AI-specific threats such as prompt injection and data leakage.
  • Strong identity and access management foundations (OAuth 2.0, OIDC, SAML, delegation patterns, machine identity at scale).
  • Security architecture experience across cloud (Azure and/or AWS) and SaaS-heavy environments.
  • Experience applying AI or automation to measurably improve security operations.
  • Relevant certifications (CISSP, CCSP, CISM, or equivalents) a plus.

Gibson Dunn will consider for employment qualified Applicants with Criminal Histories in a manner consistent with the requirements of local law.

Compensation & Benefits:

The annual compensation range for this position is $300,000 – $380,000. The salary offered within this range will depend upon qualifications and other operational considerations.

Benefits offered for this position include health care; retirement benefits; paid days off, including sick time, and vacation time; parental leave; basic life insurance; Flexible Spending Accounts; as well as discretionary, performance-based bonuses.

______

For technical difficulties with our online application, please contact us at staffrecruiting@gibsondunn.com. Our recruiting support team will respond as soon as possible.

______

Gibson Dunn is committed to ensuring equal employment opportunities for all qualified applicants, including individuals with disabilities.  We strive to ensure an inclusive and accessible hiring experience.  The Firm will provide reasonable accommodations to qualified individuals with disabilities to enable participation in the application and recruitment process, unless doing so would impose an undue hardship, in accordance with applicable laws and regulations.
 
If you require a reasonable accommodation to complete an application, participate in an interview, or otherwise take part in the recruitment process, please contact us at recruiting-accommodations@gibsondunn.com.
Please note, this is a dedicated email inbox established exclusively to assist applicants with accommodation request related to the recruitment process.  Inquiries about the status of an application or other non-accommodation matter will not receive a response.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Prior to submitting this application, please review and acknowledge Gibson, Dunn & Crutcher LLP’s compliance notices below.  

Terms of Use and Legal NoticesCookie Notice 

Select...

By submitting your application, you confirm you have reviewed the below statements, and acknowledge, certify, and/or consent to the below statements, based on the location of the position to which you're applying.

1. I certify that the facts set forth above are true and complete. I understand that if I am employed, any falsification of this application or other information supplied, including, without limitation, information on my resume if I have submitted one (including omitting information or supplying misleading information), may result in my immediate discharge, regardless of the time elapsed before discovery.

2. I understand that all offers of employment are conditioned on the provision of satisfactory proof of an applicant's identity and legal authority to work in the country in which the position is based, as well as subject to completion of any background/reference check being conducted, as allowable under local law.

3. I agree to have any of the statements checked by Gibson, Dunn & Crutcher LLP unless I have indicated to the contrary. I authorize my references, as well as all other individuals whom the Firm contacts, to provide the Firm any and all information, with the exception of information related to salary history, concerning my previous employment and any other pertinent information that they may have.

4. In consideration of my employment, if I am hired, I agree that my employment and compensation can be terminated at will, with or without cause, and with or without notice, at any time, either at my option or at the option of the Firm.

I understand that no employee or representative of the Firm, other than the Managing Partner, has the authority to enter into any agreement for employment for any specified period of time, or to make any agreement contrary to the above. Such agreement must be in writing and must specifically state that this at will employment agreement is being modified.

I agree that this constitutes an integrated agreement with respect to the at-will nature of any employment of me by the Firm, that it is final and fully binding, and that there are no oral, written, or implied agreements regarding this issue.

TO ALL APPLICANTS (EXCEPT NY APPLICANTS)
1. I understand that, in order to be hired, I may be required to sign an authorization permitting Gibson, Dunn & Crutcher LLP to obtain consumer reports, consumer credit reports, and/or investigative consumer reports.

If so, I will be provided with the authorization form(s). I understand that submitting this employment application does not obligate me to sign such form(s), although I understand that Gibson, Dunn & Crutcher LLP may not further consider me for employment if I choose not to sign such form(s), if requested.

Select...

Gibson, Dunn & Crutcher LLP respects your privacy and  is committed to handling your personal data in compliance with applicable law. I acknowledge and agree that any personal information I provide in this application or otherwise during the application process may be collected, used, processed, utilized, maintained, or shared by Gibson, Dunn & Crutcher LLP in accordance with the Privacy Statement appearing at the following Internet address: https://www.gibsondunn.com/privacy-statement/.