CybersecurityJobs.io
← Back to all jobs

Job Description

McGuireWoods LLP is hiring a Senior Information Security Engineer to help strengthen security across the firm’s endpoints, networks, cloud, SaaS, and identity environments. This hybrid role in Richmond, VA 23219 combines hands-on engineering with technical leadership, with an emphasis on building reliable security platforms, improving integrations, and supporting incident response with automation and smarter detection.

The compensation range is USD 120,800 - 181,200 per year. You will bring practical experience and take ownership of security technology design, implementation, and day-to-day optimization to help the firm meet technical baselines and regulatory expectations.

Responsibilities

  • Act as the technical lead for security platform implementations across endpoint, network, cloud, SaaS, and identity platforms.
  • Administer and optimize security controls, including EDR/AV, firewalls, DLP, email security, web filtering, and identity/access systems.
  • Lead platform integration work such as refining SaaS configurations, IAM, and SIEM log onboarding, including parsing and correlation rule development.
  • Manage vulnerability assessment tooling to build attack-surface visibility and conduct risk and threat modeling aligned with the MITRE ATT&CK framework.
  • Provide engineering support during security incidents, including host isolation, forensic collection, and log retrieval.
  • Develop automated playbooks, API integrations, and detection logic to accelerate triage and reduce false positives.
  • Perform post-incident root-cause analysis and partner with infrastructure teams on air-gapped/immutable backup and recovery architecture.
  • Translate security policies and regulatory requirements into technical baselines and secure configuration standards.
  • Support internal and external audits by producing technical evidence, architecture documentation, and remediation solutions.
  • Evaluate and recommend new security products, SaaS tools, and AI integrations to improve the firm’s security posture and address business needs.

Requirements

  • Minimum 5 years of progressive, hands-on information security engineering experience.
  • Bachelor’s Degree in IT, Cybersecurity, or equivalent hands-on experience (preferred).
  • CISSP, GIAC, or CCSP certification strongly preferred.
  • Prior experience in a law firm or heavily regulated professional services environment (preferred).
  • Demonstrated proficiency with EDR, SIEM, firewalls, identity management (MFA/PAM), scripting (including APIs and Microsoft Graph), and vulnerability tools.
  • Ability to work independently, manage project priorities, and balance security requirements with firm risk tolerance.
  • Experience leveraging AI-enabled productivity or security tools (plus).

Technologies

  • EDR/AV, firewalls, DLP, email security, web filtering
  • Identity/access systems, SaaS, IAM, SIEM
  • MITRE ATT&CK, MFA, PAM
  • Microsoft Graph, API integrations
  • Air-gapped/immutable backup and recovery architecture

Benefits

  • Hybrid remote option to support flexibility and work-life balance.
  • Excellent benefits (details not provided in the listing).

Similar Jobs