Director of Information Security
RemoteUnited States
Job Summary
Develop and execute the firm's information security program, roadmap, and annual priorities aligned with business objectives, client obligations, and regulatory expectations. Define security configuration standards for Microsoft 365, Entra ID, AV, and EDR; establish data protection controls, email filtering, and network patch compliance. Lead risk assessments, control reviews, and the GLBA/FTC Safeguards program, while supporting client security reviews and audit needs. Maintain the incident response plan, coordinate tabletop exercises, and manage vulnerability scans and penetration tests. Evaluate managed-security vendors and conduct security due diligence for acquisitions. This role requires 7+ years of progressive IT security experience with hands-on M365 and endpoint management. Full-time employment offers comprehensive medical, dental, vision, and 401(k) benefits.
Required Qualifications
- 7+ years of progressive IT and security experience
- 3 or more years hands on in information security
- Proven ability to plan security controls and implement them yourself
- Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune
- Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response
- A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable
- Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks
- Experience maintaining security policies and a risk register and turning them into implemented controls
- Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done
Desired Qualifications
- Experience in professional services, accounting, or another regulated, financial-data environment
- Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization
- Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them
- Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.