Director, AI Security
Gibson Dunn is a leading global law firm, advising clients on significant transactions and disputes. Our exceptional teams craft and deploy creative legal strategies that are meticulously tailored to every matter, however complex or high-stakes. The firm’s work is distinguished by a unique combination of precision and vision.
Based in New York, the Director of AI Security will work directly with the CISO to define the firm’s AI security strategy and determine and build the function required to deliver it — its shape, its size, its sequencing and its budget. This is the firm's first dedicated AI security role, with no inherited team or playbook; defining the team required to deliver the strategy is a key part of the role. The position requires the ability to engage credibly with senior executives and practice group leadership on strategy, while also reasoning about technical details such as token scopes and prompt injection.
This role reports to the Chief Information Security Officer.
Responsibilities include:
AI Security Strategy & Program Development
- Define the firm's AI security strategy, target architecture, and multi-year roadmap in partnership with the CISO, and secure executive endorsement.
- Design, budget, recruit, and lead the AI security function, including team structure, tooling, and build-versus-buy decisions.
- Establish the security control framework for AI systems.
- Own the security review stage of the AI use-case intake and approval process, ensuring a clear and timely path from proposal to production.
- Partner with the Office of General Counsel and the Cyber & Data Governance Committee on obligations relating to confidentiality, privilege, and competent use of technology.
Stakeholder Engagement & Secure AI Enablement
- Build relationships with partners, practice group leaders, and business leaders to understand the drivers of AI adoption and translate business needs into secure delivery options.
- Present AI risk and strategy to executive stakeholders and, where required, to clients.
- Conduct security architecture and design reviews for AI platforms, RAG pipelines, agent frameworks, and in-house builds.
- Define controls against AI-specific threats, including prompt injection, tool abuse, data leakage, supply chain compromise, and cross-matter contamination.
- Address unsanctioned AI use through discovery, sanctioned alternatives, and clear guidance, in partnership with IT and the practice groups.
Identity & Access Management for AI Systems
- Own the firm's agentic identity model, governing how agents, service accounts, and tool integrations are issued identity, authenticated, scoped, and revoked.
- Establish lifecycle governance for non-human identities, including registration, ownership, entitlement review, credential rotation, and decommissioning.
- Define authorization patterns for delegated access, ensuring agents never exceed user entitlements and that ethical walls and matter-level restrictions hold.
- Set governance standards for tools and connectors, including MCP servers and equivalent integration layers.
- Ensure every consequential agent action is auditable and attributable to an identity, delegating principal, and matter context.
AI-Enabled Security Operations
- Develop and own the roadmap for applying AI within the security function.
- Identify and deliver high-value use cases such as alert triage, detection engineering, investigation support, and third-party risk review.
- Set operating standards for the security function's own AI systems, including autonomy limits, human review points, and ongoing evaluation.
- Maintain a current view of AI-enabled threats to the firm and ensure defenses and awareness training keep pace.
- Measure and report operational impact of AI investments.
Assurance, Risk & Compliance
- Establish AI red teaming and adversarial testing programs, with findings tracked to remediation.
- Define pre-deployment and change-driven security evaluation criteria for AI systems, including guardrail regression testing.
- Own AI-specific incident response playbooks and support the IR team on AI-related events.
- Lead security assessments of AI vendors and legal-tech platforms.
- Translate emerging regulation and guidance (e.g., EU AI Act, bar association guidance) into control requirements.
- Deputize for the CISO on AI matters at management and committee level.
Qualifications:
- Strong strategic and analytical thinking, with a track record of building a security capability from the ground up rather than inheriting one.
- Ability to operate at executive level — setting strategy, making the business case for investment, and holding your position with senior stakeholders under pressure to move quickly.
- Ability to influence without formal authority and earn trust in a partnership environment, including from fee earners.
- Excellent written and verbal communication, including with clients and regulators.
Experience:
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent experience).
- 10+ years of information security experience, including end-to-end ownership of a significant security domain.
- Deep, practical experience securing production AI and LLM systems, including AI-specific threats such as prompt injection and data leakage.
- Strong identity and access management foundations (OAuth 2.0, OIDC, SAML, delegation patterns, machine identity at scale).
- Security architecture experience across cloud (Azure and/or AWS) and SaaS-heavy environments.
- Experience applying AI or automation to measurably improve security operations.
- Relevant certifications (CISSP, CCSP, CISM, or equivalents) a plus.
Gibson Dunn will consider for employment qualified Applicants with Criminal Histories in a manner consistent with the requirements of local law.
Compensation & Benefits:
The annual compensation range for this position is $300,000 – $380,000. The salary offered within this range will depend upon qualifications and other operational considerations.
Benefits offered for this position include health care; retirement benefits; paid days off, including sick time, and vacation time; parental leave; basic life insurance; Flexible Spending Accounts; as well as discretionary, performance-based bonuses.
______
For technical difficulties with our online application, please contact us at staffrecruiting@gibsondunn.com. Our recruiting support team will respond as soon as possible.
______
Gibson Dunn is committed to ensuring equal employment opportunities for all qualified applicants, including individuals with disabilities. We strive to ensure an inclusive and accessible hiring experience. The Firm will provide reasonable accommodations to qualified individuals with disabilities to enable participation in the application and recruitment process, unless doing so would impose an undue hardship, in accordance with applicable laws and regulations.
If you require a reasonable accommodation to complete an application, participate in an interview, or otherwise take part in the recruitment process, please contact us at recruiting-accommodations@gibsondunn.com. Please note, this is a dedicated email inbox established exclusively to assist applicants with accommodation request related to the recruitment process. Inquiries about the status of an application or other non-accommodation matter will not receive a response.
Skills
As published by greenhouse · 23 questions · 2 written answers
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
Short answers (8)
- Preferred First Name optional
- List any aliases or other name(s) you have used or currently use or indicate N/A.
- Please provide your full home address.
- If so, when were you employed or when did you apply? optional
- If other or referral, please share details. optional
- When are you available for employment (i.e. what is your notice period, if currently employed)?
- What are your salary expectations?
- If yes, please explain: optional
Pick from a list (13)
- Are you over the age of 18?
- Have you previously applied to or worked for Gibson Dunn (including through an employment agency)? optional
- Are you authorized to work lawfully in the country in which this position is based for Gibson Dunn?
- Do you now, or will you in the future, require sponsorship for employment visa status to work legally for Gibson Dunn in the country in which this position is based?
- How did you hear about this position?
- Which type of employment are you seeking?
- In which of our offices are you open to working?
- Are you available for overtime?
- We value transparency and aim to ensure alignment early in the process. Can you confirm you have reviewed the compensation range, office location and work hours (if applicable) for the position and are comfortable moving forward?
- Have you ever been separated from a previous employer under circumstances such as disciplinary action or involuntary resignation?
- Acknowledgment of Legal Notices:
- Certification and Consent:
- Privacy Notice:
Written answers (2)
- List all close personal and professional connections employed by Gibson Dunn and their relationship to you, or indicate N/A.
- Please tell us what you liked and disliked about your last role. What interests you most about this opportunity?