McGuireWoods LLP

Sr. Information Security Engineer

Job Location US-VA-Richmond
Category
Information Technology
Pos. Type
Regular Full-Time
Salary - Minimum
USD $120,800.00
Salary - Maximum
USD $181,200.00

Overview

McGuireWoods is hiring a Senior Information Security Engineer. This is a hands-on technical lead position responsible for designing, implementing, and maintaining security technologies that protect the confidentiality, integrity, and availability of firm, client, and personal data. This role provides technical leadership across security platforms, architecture, automation, and SaaS integrations. The person in this position must be a self-starter who can drive projects independently, collaborate across teams, and effectively communicate technical decisions to all levels of firm personnel.

McGuireWoods, one of the world’s leading law firms, has provided legal solutions to corporate, individual and nonprofit clients since 1834. Along with excellent benefits, McGuireWoods offers most employees a hybrid remote option allowing flexibility and work-life balance. Our Applicant Disclosures describe your rights. Our Privacy Statement describes how we will process and safeguard your personal data.

Responsibilities

  • Serve as technical lead for security platform implementations across endpoint, network, cloud, SaaS, and identity platforms.
  • Administer day-to-day operations and optimization of security controls, including EDR/AV, firewalls, DLP, email security, web filtering, and identity/access systems.
  • Lead platform integration efforts, including refining SaaS configurations, IAM, and SIEM log onboarding, parsing, and correlation rule development.
  • Manage vulnerability assessment tooling, build attack-surface visibility, and conduct risk/threat modeling aligned with the MITRE ATT&CK framework.
  • Provide engineering support during security incidents, including host isolation, forensic collection, and log retrieval.
  • Develop automated playbooks, API integrations, and detection logic to accelerate triage and reduce false positives.
  • Perform root-cause analysis post-incident and partner with infrastructure teams on air-gapped/immutable backup and recovery architecture.
  • Translate security policies and regulatory requirements into technical baselines and secure configuration standards.
  • Support internal and external audits by producing technical evidence, architecture documentation, and remediation solutions.
  • Evaluate and recommend new security products, SaaS tools, and AI integrations to improve firm security and address business needs.

Qualifications

  • Minimum of 5 years of progressive, hands-on information security engineering experience.
  • Bachelor’s Degree in IT, Cybersecurity, or equivalent hands-on experience preferred.
  • CISSP, GIAC, or CCSP certification strongly preferred.
  • Prior experience in a law firm or heavily regulated professional services environment preferred.
  • Demonstrated proficiency with EDR, SIEM, firewalls, identity management (MFA/PAM), scripting (APIs/Microsoft Graph), and vulnerability tools.
  • Ability to work independently, manage project priorities, and balance security requirements with firm risk tolerance.
  • Experience leveraging AI-enabled productivity or security tools is a plus. 

Have more questions? Connect with a recruiter directly. #LI-KB1

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share