- Location
- Remote - United States, United States of America
- Workplace
- Hybrid, Remote
- Type
- Full-time
- Department
- Security
- Seniority
- Manager
- Experience
- 5+ years
- Education
- Master
- Source
- Workday
Description
Aderant is a global industry leading software company providing comprehensive business management solutions for law firms and other professional services organizations with a mission to help them run a better business. We are motivated by a collective desire to drive the legal industry to the forefront of innovation. With over 2,500 clients around the world, including 95 of the top AmLaw 100 firms, we are changing the outside perception of the legal sphere; where there was once resistance to modernization, we are creating a culture that embraces new ideas and technology.
At Aderant, the “A” is more than just a letter. It is a representation of how we fulfill our foundational purpose, serving our clients. It embodies our core values and reminds us that to achieve success, every day must start with the “A”. We bring the “A” to life by fostering a culture of innovation, collaboration, and personal growth. We encourage our diverse teams to bring their whole selves to work – ideas, experience, and passion – to drive our mission forward.
Our people are our strength.
Position Summary
Aderant is the leading global provider of business management software for law firms, and the Information Security team protects the systems, data, and client trust that underpin that mission. The Manager, Information Security leads Aderant's security operations and incident response function, directing a team of analysts and engineers responsible for detecting, investigating, and responding to threats across the company's global environment.
Reporting to the Director, Head of Information Security, this role translates security strategy into day-to-day operational execution — owning the security operations function, incident response program, and threat detection capabilities, while building and developing a high-performing team.
Key Responsibilities
Security Operations & Incident Response
- Lead day-to-day security operations, including monitoring, threat detection, and alert triage across the SIEM, EDR, cloud-native security services, and related security tooling.
- Own the incident response program: lead investigation and response for security incidents, coordinate cross-functional response (IT, Legal, Privacy, Communications), and drive post-incident root-cause analysis and remediation.
- Maintain and continuously improve incident response plans, playbooks, and tabletop exercises, cloud- and identity-specific response scenarios.
- Establish and track key operational metrics (mean time to detect/respond, alert volumes, false-positive rates) and report on security operations performance to the Director.
- Oversee vulnerability management operations across cloud infrastructure, endpoints, containers, and applications, including risk-based prioritization and coordination of remediation with Engineering and IT.
- Serve as an escalation point and on-call leader during active security incidents, including after hours as required.
Cloud Security (AWS & Azure)
- Own day-to-day cloud security operations across Aderant's production AWS and Azure environments, including detection, triage, and response to cloud control-plane and workload threats.
- Manage cloud security posture management (CSPM) operations: monitor for misconfiguration and drift, prioritize findings by real-world risk, and drive remediation with Cloud Engineering and IT.
- Establish and maintain cloud security guardrails and baselines — logging and telemetry coverage, network segmentation, encryption, secrets handling, and secure-by-default configuration standards.
- Lead identity and access security operations in the cloud and across the enterprise: privileged access, role and permission hygiene, conditional access, MFA enforcement, and detection of identity-based attack techniques such as token theft, session hijacking, and consent abuse.
- Ensure comprehensive security telemetry from both cloud platforms is ingested, normalized, and covered by detections in the SIEM.
- Partner with Cloud Engineering on the security of container and orchestration platforms, infrastructure-as-code pipelines, and the edge/WAF layer protecting customer-facing services.
- Support cloud security architecture reviews for new services, regions, and platform changes, and translate the outcomes into operational monitoring requirements.
Application & Product Security
- Partner with Engineering and Product to embed security detection, logging, and response requirements into application and infrastructure changes.
Detection Engineering, Automation & AI Enablement
- Build and tune detection content mapped to MITRE ATT&CK (including cloud and identity techniques), measuring and closing coverage gaps rather than only responding to vendor-supplied alerts.
- Drive automation of repeatable detection, enrichment, and response tasks to improve team efficiency and reduce mean time to respond.
- Apply AI tools — including Claude and Aderant-approved AI assistants — to accelerate investigation, detection development, documentation, and reporting, and establish sound team practices for their use.
- Contribute to the secure and responsible use of AI across Aderant, including deployment and management of our AIDR solution and monitoring for AI-related risks such as data leakage and shadow AI usage.
- Evaluate and recommend security operations tooling (SIEM, SOAR, EDR, CSPM, threat intelligence) to improve detection and response capability.
- Stay current on the threat landscape relevant to legal technology, SaaS, and cloud environments, and translate intelligence into detection use cases.
Team Leadership
- Manage, mentor, and develop a team of security analysts and engineers, including hiring, performance management, and career development.
- Establish on-call rotations, staffing coverage, and workload distribution to ensure 24/7 operational readiness.
- Build a culture of accountability, continuous learning, and operational rigor within the team.
Cross-Functional Collaboration
- Partner with IT, Engineering, and Product teams to embed security detection and response requirements into infrastructure and application changes.
- Support the Director, Head of Information Security in preparing security posture updates for executive leadership and, where applicable, customer and audit inquiries.
- Coordinate with Legal and Compliance on regulatory or contractual incident notification obligations.
Required Qualifications
- 5+ years of experience in information security, with at least 3 years in security operations, incident response, or threat detection.
- 2+ years of experience directly managing or leading a security team, including hiring and performance management.
- Hands-on experience securing and monitoring public cloud environments — substantive depth in both AWS and Azure (or deep expertise in one with demonstrated working knowledge of the other), including cloud logging and telemetry, IAM, and cloud-native security services.
- Practical experience with cloud security posture management and remediating misconfiguration at scale in a production environment.
- Hands-on experience with SIEM platforms EDR, and CSPM tools (CrowdStrike preferred)
- Experience managing the incident response processes in a production environment.
- Working knowledge of common attack techniques, threat actor behavior, and the MITRE ATT&CK framework, including cloud and identity techniques..
- Experience developing or maturing incident response plans, playbooks, and post-incident reviews.
- Demonstrated use of AI tools (such as Claude or comparable assistants) to improve security operations quality and efficiency, with sound judgment about where they are and are not appropriate.
- Strong written and verbal communication skills, including experience communicating incident status to non-technical stakeholders and leadership.
- Proficiency securing Cloud environments (AWS and Azure).
- Bachelor's degree in Computer Science, Information Security, or related field, or equivalent professional experience.
Preferred Qualifications
- Experience in a SaaS, legal technology, or software company handling sensitive or regulated client data.
- Relevant certifications such as CISSP, GCIH, GCIA, CISM, or equivalent.
- Cloud security certifications such as AWS Certified Security – Specialty, Microsoft Certified: Azure Security Engineer Associate (AZ-500), GCSA, or GCLD.
- Experience with a unified endpoint and cloud security platform such as CrowdStrike Falcon (Aderant's preferred platform), or comparable EDR/CNAPP tooling.
- Experience with edge security and web application firewall platforms such as Cloudflare.
- Familiarity with cloud-native security services (AWS GuardDuty, Security Hub, CloudTrail; Microsoft Defender for Cloud, Entra ID Protection, Azure Monitor/Sentinel).
- Experience securing containers and orchestration platforms (Docker, Kubernetes, EKS/AKS) and infrastructure-as-code (Terraform) pipelines.
- Experience with SOAR platforms and security automation/orchestration.
- Experience managing a co-managed SOC or MSSP relationship.
- Familiarity with SOC 2, ISO 27001, or similar compliance frameworks and how operational security supports audit readiness.
- Experience operating in a global, multi-region environment.