Back to jobs
New

Chief Information Security Officer

Orlando, Florida, United States

At Morgan & Morgan, the work we do matters. For millions of Americans, we’re their last line of defense against insurance companies, large corporations or defective goods. From attorneys in all 50 states, to client support staff, creative marketing to operations teams, every member of our firm has a key role to play in the winning fight for consumer rights. Our over 6,000 employees are all united by one mission: For the People.

About the Role

Morgan & Morgan is the largest plainti/-side law firm in the United States, with 140+ offices nationwide, more than 1,000 lawyers, and over $30 billion recovered for clients. Our scale is matched by a strong culture of speed, innovation, and in-house technology development, where software, data, and AI-enabled platforms are core to how we serve clients and win cases. We operate in a high-stakes, litigation-driven environment where technology decisions directly affect outcomes, reputation, and client trust. As a result, cybersecurity is not a support function it is a core business capability.

We are seeking a Chief Information Security Officer (CISO) to lead a modern, business-aligned security program that protects highly sensitive data while enabling rapid software development, AI-driven workflows, and continuous innovation across legal-technology platforms.

This role is designed for a security executive who believes strong security should accelerate innovation, not constrain it. The CISO will partner deeply with engineering, product, legal, and operations leaders to embed security into fast-moving delivery cycles through pragmatic guardrails, clear risk ownership, and modern security architecture. Security at Morgan & Morgan plays a direct role in protecting the trust of the people we represent—ensuring our teams can fight for clients without distraction, delay, or doubt.

This is an on-site executive leadership role, requiring consistent presence in our Orlando headquarters and active engagement across firm offices. We believe strong security should enable innovation, not slow it down. Our approach is grounded in risk-informed decision-making, pragmatic controls, and shared ownership across technology and the business. We build security as scalable guardrails designed to support rapid software development, AI-driven workflows, and continuous improvement without sacrificing client trust.

Key Responsibilities

Security Strategy & Risk Leadership

• Define and execute a business-aligned cybersecurity strategy that supports firm growth, rapid delivery, and national scale

• Establish risk-informed security governance that enables fast, confident decision-making in a high-volume, litigation-driven environment

• Translate cyber risk into clear business impact for executive leadership and the Board

• Guide security investment decisions that balance velocity, resilience, and client trustRisk

Management & Compliance

• Lead firm-wide risk assessments, threat modeling, and control maturity evaluations

• Own end-to-end incident response strategy, breach readiness, tabletop exercises, and post-incident learning

• Partner closely with Legal, Privacy, and Compliance leaders to ensure:

• Protection of sensitive client and case data

• Defensible security practices suitable for litigation discovery

• Alignment with regulatory, contractual, and ethical obligations

• Oversee third-party and vendor security risk management at national scale Security Architecture & Engineering Enablement

• Design and evolve a scalable security architecture that supports internally built platforms, modern development practices, and AI-enabled legal technology

• Embed security into:

• Agile software development and CI/CD pipelines

• Cloud-native platforms and SaaS ecosystems

• AI-enabled legal workflows and analytics platforms

• Implement Zero Trust principles using pragmatic, developer-friendly controls

• Ensure security controls function as guardrails, not bottlenecks, for engineers and attorneys

Security Operations

• Oversee security operations including:

• Identity & Access Management (IAM)

• Endpoint, network, and cloud security

• Security monitoring, detection, and response

• Continuously improve detection, response time, and operational resilience

• Ensure security operations remain resilient and e/ective during high-volume, time- sensitive legal operations

• Ensure security capabilities scale e/ectively across 140+ o/ices and 1,000+ lawyersLeadership & Culture

• Build, lead, and mentor a high-caliber, hands-on security organization

• Establish strong operating models between Security, IT, Engineering, and the business

• Set clear expectations and a high bar for execution, accountability, and follow-through across the security function

• Champion a culture where security is designed in early, not bolted on late

• This role requires a leader who is comfortable operating close to the technology engaging directly with teams, systems, and incidents when needed

• Act as a visible, trusted executive leader approachable, decisive, and credible

Required Experience

• 10+ years in cybersecurity, including senior leadership roles in large, complex environments

• Proven success leading security programs in high-data-sensitivity, fast-moving organizations

• Demonstrated ability to communicate cyber risk clearly to executive leadership and

Boards

• Strong working knowledge of:

• NIST Cybersecurity Framework (CSF) and/or ISO 27001

• Zero Trust architecture

• Incident response and crisis leadership

• Cloud and SaaS security at scaleExecutive Mindset

• Business-first approach to security focused on outcomes, not checklists

• Comfort making tradeo/s and defending decisions at the executive level

• Calm, credible leadership during high-pressure situations

• High integrity, sound judgment, and strong ethical foundationPreferred Qualifications

• CISSP, CISM, or equivalent credentials

• Experience supporting AI platforms, analytics, or large-scale digital transformation

• Proven partnership with CIOs, General Counsel, and Compliance leadership

• Background in product-led, technology-driven organizations (legal tech, fintech, SaaS, or similar)

Why Morgan & Morgan

• Unmatched scale: Secure operations across 140+ offices nationwide

• Real impact: Protect systems supporting more than $30 billion recovered for clients

• Innovation focus: Security embedded in rapid software delivery and AI-driven legal tech

• Executive influence: Direct involvement in firm-wide risk and investment decisions

• Leadership commitment: Security treated as a strategic business capability

What We Offer

Morgan & Morgan offers a people-first environment grounded in high performance. We provide comprehensive medical, dental, vision, and mental health benefits; generous paid time off; strong onboarding and leadership support; and a culture that values accountability, growth, and results. You’ll work alongside driven professionals who expect excellence and support one another in achieving it.

Benefits

Morgan & Morgan is a leading personal injury law firm dedicated to protecting the people, not the powerful. This success starts with our staff.  For full-time employees, we offer an excellent benefits package including medical and dental insurance, 401(k) plan,  paid time off and paid holidays.

Equal Opportunity Statement

Morgan & Morgan provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

E-Verify

This employer participates in E-Verify and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. If E-Verify cannot confirm that you are authorized to work, this employer is required to give you written instructions and an opportunity to contact Department of Homeland Security (DHS) or Social Security Administration (SSA) so you can begin to resolve the issue before the employer can take any action against you, including terminating your employment. Employers can only use E-Verify once you have accepted a job offer and completed the I-9 Form.   

Privacy Policy

Here is a link to Morgan & Morgan's privacy policy.

Create a Job Alert

Interested in building your career at Morgan & Morgan, P.A.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...

Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Morgan & Morgan, P.A.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.