Morgan & Morgan is America's largest personal injury law firm, with more than 6,000 employees and over 1,000 attorneys licensed across all 50 states. Founded in 1988, the firm operates from 140+ offices nationwide, handling over 50 practice areas - from auto accidents and medical malpractice to class actions and workers' compensation - on a contingency fee basis.
A firm of this scale operates with the attack surface of a mid-size enterprise: 6,000 endpoints, sensitive client data spanning every state's jurisdiction, and a compliance footprint that touches attorney-client privilege, HIPAA-adjacent medical records, and class-action discovery troves. The threat model is straightforward - PII at scale, regulatory exposure, and the operational risk of a 24/7 firm that can't afford downtime.
Cybersecurity roles here sit at the intersection of legal tech infrastructure and data protection at volume. The work involves securing systems that handle case management, client intake, and litigation workflows across a distributed national footprint. For security engineers thinking about real-world data sensitivity under regulatory scrutiny, this is a firm where the stakes aren't theoretical.






