Demo

Information Security & Compliance Manager

Chisholm Chisholm & Kilpatrick LTD
Providence, RI Full Time
POSTED ON 4/15/2026
AVAILABLE BEFORE 5/14/2026
Description

Information Security & Compliance Manager

Location: Providence, RI (Hybrid work environment available)

Chisholm Chisholm & Kilpatrick (CCK) is a nationally recognized law firm committed to providing exceptional client service in the areas of Veterans Law, Litigation, and Bequest Management. CCK is seeking an Information Security & Compliance Manager (ISCM) to lead its information governance, security and compliance program.

This individual will serve as the firm’s primary authority on cybersecurity strategy, data governance, and regulatory compliance, ensuring that client data, attorney-client privileged communications, and firm intellectual assets are protected at the highest standard. This position requires both strategic thinking and hands-on execution, with strong cross-functional collaboration across IT, legal, operations, and client-facing teams.

Given the sensitive nature of legal practice and the firm’s obligations under applicable bar rules, data protection regulations, and client contractual requirements, this role demands a leader who can create and adapt policy, implement controls, cultivate a security-aware culture, and maintain compliance with evolving legal and regulatory frameworks.

Key Responsibilities:

  • Develop, implement, and maintain the firm's data governance framework, information security strategy, multi-year roadmap, and security architecture.
  • Establish and operationalize cybersecurity and data governance policies, standards, and procedures firmwide, including applicable state statutory requirements, HIPAA data security requirements, and SOC 2 Trust Services Criteria.
  • Oversee vulnerability management, penetration testing programs, and security monitoring operations.
  • Manage security technologies including SIEM, endpoint detection and response (EDR), identity and access management (IAM), email security, and data loss prevention (DLP) tools.
  • Evaluate third-party vendors for compliance with internal policies and procedures, state statutory requirements, HIPAA data security requirements, SOC 2 standards and best practices.
  • Lead incident response planning, tabletop exercises, and post-incident review processes
  • Foster a culture of security and compliance across the firm, including collaborating with the firm’s internal stakeholders from across departments regarding information security initiatives.
  • Partner with practice group leaders and attorneys to embed data handling standards into legal workflows
  • Maintain current knowledge of emerging security alerts, issues, threats and trends to enhance the firm’s Information Security posture.

Requirements

  • Minimum 5 years of experience in information security, cybersecurity, and/or compliance roles, with demonstrated career growth.
  • Demonstrated experience building an information security program from the ground up, including policy development, control implementation, and program governance.
  • Hands-on experience conducting or overseeing security risk assessments, audits, and compliance evaluations.
  • Experience managing vendor/third-party risk and reviewing technology contracts with security implications.
  • Demonstrated understanding of state data security laws and regulations, HIPAA data security requirements, and SOC 2 Type II audit criteria.
  • Experience using and administering security tools (SIEM, endpoint protection, DLP, MFA, etc.).
  • Experience with the incident response life cycle.
  • Familiarity with NIST, ISO 27001, or COBIT frameworks.
  • Excellent written and communication skills and ability to work with legal, technical staff and non-technical staff.
  • Ability to translate complex technical risk and mitigation into clear business terms for non-technical audiences, including firm partners and executive leadership
  • Strong project management skills and ability to manage multiple concurrent initiatives with competing priorities
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a closely related field; equivalent combination of education and experience considered

Preferred Certifications:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified HIPAA Security Professional (CHSP) or equivalent
  • Certified Information Privacy Professional (CIPP/US or CIPM)
  • Certified in Risk and Information Systems Control (CRISC)
  • CompTIA Security or equivalent foundational certification

Compensation & Benefits:

  • Competitive salary based on experience
  • CCK offers options for medical, dental, and vision insurance (including employer-paid medical insurance for the employee!) and other wellness benefits
  • Gym membership reimbursement
  • 15 days of PTO which increase to 20 days of PTO after 1 year plus 14 paid company holidays in 2026
  • 35 Work from Home Days per year that can be used for any reason
  • 401k matching
  • Paid Parental Leave

Salary.com Estimation for Information Security & Compliance Manager in Providence, RI
$148,800 to $178,066
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security & Compliance Manager?

Sign up to receive alerts about other jobs on the Information Security & Compliance Manager career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Chisholm Chisholm & Kilpatrick LTD

  • Chisholm Chisholm & Kilpatrick LTD Providence, RI
  • Description Chisholm Chisholm & Kilpatrick (CCK) is a private, public-interest law firm with a strong commitment to serving disabled military veterans and ... more
  • 14 Days Ago

  • Chisholm Chisholm & Kilpatrick LTD Providence, RI
  • Description Chisholm Chisholm & Kilpatrick (CCK) is a private, public-interest law firm with a strong commitment to serving disabled military veterans and ... more
  • 15 Days Ago

  • Chisholm Chisholm & Kilpatrick LTD Providence, RI
  • Description At Chisholm Chisholm & Kilpatrick LTD, our Bequest Management practice group represents some of the nation’s most significant charities. We man... more
  • 4 Days Ago

  • Chisholm Chisholm & Kilpatrick LTD Providence, RI
  • Description This position is located in our Providence, RI headquarters. Position Overview: The Editor will play a key role on a dynamic content marketing ... more
  • 5 Days Ago


Not the job you're looking for? Here are some other Information Security & Compliance Manager jobs in the Providence, RI area that may be a better fit.

  • Rhode Island Housing Providence, RI
  • RIHousing – Information & Data Security Manager Salary - $107,884.00 - $156,432.00 Please note: This pay range represents the base annual full‑time salary ... more
  • 10 Days Ago

  • Information Resource Group, Inc. Providence, RI
  • Role: Release Manager Location: Providence, RI- 100% Onsite Duration: 1 year 35 hours a week. Required Skills and qualifications: Project & release managem... more
  • 5 Days Ago

AI Assistant is available now!

Feel free to start your new journey!