Company Overview Harrison LLP is a fast‑growing Premier, nationwide law firm with 10 offices across the United States and additional locations on the roadmap. We specialize in estate planning, tax, select litigation, and related practices—handling highly sensitive client data subject to strict regulatory, ethical, and privacy obligations. Technology drives our success: we are an O365 shop leveraging Microsoft Defender, Sentinel, and a cloud‑first architecture to deliver secure, efficient legal services from coast to coast. Role Overview – Information Security Officer (ISO) Harrison LLP seeks an experienced Information Security Officer to own and advance the firm’s cybersecurity, privacy, and AI‑governance programs. Reporting to the Director of IT, you will design and execute security strategy, manage our Microsoft‑centric security stack (Defender, Sentinel, Purview), and ensure our expanding AI usage complies with ABA, GDPR, HIPAA, and state privacy laws. This is a hands‑on role with firm‑wide impact and visibility across 10 offices and a distributed workforce. Key Responsibilities • Strategy & Policy – Craft and maintain a firm‑wide information‑security and AI‑compliance program aligned to NIST CSF and ISO 27001 for a multi‑office environment. • Risk & Compliance – Lead recurring risk assessments, vulnerability testing, and remediation; manage GDPR, HIPAA, PCI‑DSS, and state‑law compliance. • Microsoft Security Operations – Administer/tune Microsoft Defender (O365, Endpoint, Cloud Apps) and Microsoft Sentinel SIEM; integrate logs from cloud services. • Incident Response – Own the IR plan, coordinate investigations firm‑wide, and brief stakeholders; refine playbooks for geographically dispersed teams. • Secure SDLC & Vendor Oversight – Embed security reviews into software/vendor lifecycle ; guide responsible use of generative‑AI tools. • Training & Culture – Deliver security‑awareness and AI‑ethics training tailored for attorneys and staff in multiple time zones; foster a security‑first culture. • Physical Security – Maintain Verkada badge access, Security cameras support and process Required Qualifications • 5+ years in information security; at least 2 years leading Microsoft 365/Azure security solutions in a distributed enterprise. • Direct experience managing SIEM platforms (preferably Microsoft Sentinel) with multi‑site log ingestion. • Demonstrated success building policies and controls aligned to NIST, ISO 27001. • Hands‑on expertise with Defender suite, Azure AD Conditional Access, Purview DLP, Intune. • Strong grasp of AI governance/regulations. • One or more of: CISSP, CISM, CCSP, Microsoft SC‑100/200/300/400, ISO 27001 Lead Implementer. Preferred Qualifications • Legal or similarly regulated sector experience. • Knowledge of e‑discovery, NetDocuments, legal‑practice platforms. • Automation skills (PowerShell, Python) and experience with penetration testing/forensics. Technical Skills Snapshot Domain Core Technologies Microsoft Cloud Security Defender (O365, Endpoint, Identity), Sentinel, Purview DLP, Azure AD, Intune SIEM & Analytics Fabric, Critical Start Endpoint / Network EDR, NGFWs, VPN, Zero‑Trust NAC Governance & Compliance NIST CSF, ISO 27001, GDPR, HIPAA, ABA AI ethics Automation PowerShell, Python, Soft Skills & Cultural Fit • Concise communicator able to translate risk for partners and executives. • Proactive, detail‑oriented, comfortable working across multiple offices/time zones. • Collaborative : Builds strong relationships with IT and practice groups. Compensation & Benefits Base Salary: $140,000 – $160,000 plus annual performance bonus • 401(k) • Dental insurance • Employee assistance program • Flexible schedule • Flexible spending account • Free parking • Health insurance • Health savings account • Life insurance • Opportunities for advancement • Paid time off • Profit sharing • Referral program • Vision insurance Location & Work Style This role is a Hybrid role in the St. Louis or Chicago office, travel may be required <10% to any of our 10 offices for strategic meetings, incident response exercises, or onboarding events is required. Ready to secure the future of a nationwide, growth‑oriented law firm? Apply today and help Harrison LLP practice law—securely and responsibly in the age of AI.
Job Type
Fulltime role
Skills required
Azure, Fabric, Python
Location
Chicago, Illinois
Salary
No salary information was found.
Date Posted
June 8, 2025
Harrison LLP is seeking an experienced Information Security Officer to lead the firm's cybersecurity, privacy, and AI-governance programs. This hands-on role involves managing Microsoft security solutions and ensuring compliance with various regulations across multiple offices.