Sr. Information Security Engineer
Job Description
McGuireWoods LLP is hiring a Sr. Information Security Engineer to serve as a hands-on technical lead for designing, implementing, and maintaining security technologies. The role focuses on technical leadership across security platforms, architecture, automation, and SaaS integrations.
Location
Richmond, VA 23219 (hybrid)
Compensation
USD 120,800 - 181,200 per yearly
Key Responsibilities
- Act as technical lead for security platform implementations across endpoint, network, cloud, SaaS, and identity platforms.
- Oversee day-to-day operations and optimization of security controls, including EDR/AV, firewalls, DLP, email security, web filtering, and identity/access systems.
- Lead platform integrations, including refining SaaS configurations, supporting IAM, and onboarding SIEM logs through parsing and correlation rule development.
- Manage vulnerability assessment tooling, build attack-surface visibility, and perform risk and threat modeling aligned with the MITRE ATT&CK framework.
- Support security incidents through engineering assistance, including host isolation, forensic collection, and log retrieval.
- Develop automated playbooks, API integrations, and detection logic to speed triage and reduce false positives.
- Conduct post-incident root-cause analysis and partner with infrastructure teams on air-gapped/immutable backup and recovery architecture.
- Convert security policies and regulatory requirements into technical baselines and secure configuration standards.
- Assist internal and external audits by producing technical evidence, architecture documentation, and remediation solutions.
- Evaluate and recommend new security products, SaaS tools, and AI integrations to improve firm security and meet business needs.
Required Experience and Qualifications
- Minimum 5 years of progressive, hands-on information security engineering experience.
- Bachelor’s Degree in IT, Cybersecurity, or equivalent hands-on experience preferred.
- CISSP, GIAC, or CCSP strongly preferred.
- Prior experience in a law firm or heavily regulated professional services environment preferred.
- Demonstrated proficiency with EDR, SIEM, firewalls, identity management (MFA/PAM), scripting (APIs/Microsoft Graph), and vulnerability tools.
- Ability to work independently, manage priorities, and balance security needs with the firm’s risk tolerance.
- Experience leveraging AI-enabled productivity or security tools is a plus.
Security Technologies
- EDR/AV, firewalls, DLP, email security, web filtering
- Identity/access systems, SaaS, IAM
- SIEM, MITRE ATT&CK, MFA, PAM
- Microsoft Graph, API integrations
- Air-gapped/immutable backup and recovery architecture
Benefits
- Hybrid remote option to support flexibility and work-life balance.
- Excellent benefits.