Director, Cybersecurity

🕒 Julho 29

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

👻 Score fantasma 18%

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of Ascend

Ascend

1001 - 5000 funcionários

Fundada em 2023

🤝 B2B

💼 Consultoria

💰 $2.018.785 Seed Round - Ascend em 2025-02

B2B • Consulting

A Ascend é uma plataforma moderna que faz parceria com firmas de contabilidade empreendedoras, oferecendo os recursos e vantagens de uma grande firma de contabilidade enquanto preserva a independência de cada firma. Apoiada pela empresa de private equity focada em pessoas, Alpine Investors, e fundada em janeiro de 2023, a Ascend fornece capital para crescimento, aquisição e desenvolvimento de talentos, tecnologia transformadora, um sistema de liderança catalisador, serviços compartilhados de back-office e incentivos de patrimônio modernizados para ajudar as firmas de contabilidade regionais a se expandirem. A empresa já é reconhecida como uma das 25 principais firmas pela Accounting Today.

Descrição

• Own the enterprise cybersecurity strategy and multi-year roadmap, sequencing initiatives against partner-firm seasonality (tax deadlines) and the broader TST (Technology Stack Transition) integration timeline; present strategy and progress to the Vice President, Technology Infrastructure & Cybersecurity. • Define, track, and report a concise set of security metrics and program-maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to executive leadership on a fixed cadence. • Develop and manage the cybersecurity budget for tooling, MSSP/vendor contracts, and headcount, keeping security cost transparent and competitive across partner firms. • Manage relationships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), securing preferred pricing and early access to product roadmaps and preview programs. • Own endpoint detection and response (CrowdStrike Falcon), security monitoring and log management, vulnerability management, and email security across Ascend and all partner firms. • Serve as incident commander for cybersecurity incidents; maintain and test the incident response plan through regular tabletop exercises, and lead post-incident reviews and remediation to closure. • Establish detection coverage, alert triage, and escalation standards, and determine the right outsourced-vs.-in-house MSSP model for 24x7 monitoring. • Define vulnerability and patch SLAs by asset criticality and partner with infrastructure and service-desk teams to ensure remediation lands; engage a qualified external firm to conduct periodic penetration testing. • Own the governance, risk, and compliance program, including enterprise risk assessments and security policies and standards aligned to NIST CSF 2.0. • Own the full SOC 2 Type II audit lifecycle — control design, evidence collection, and auditor management — sustaining a clean attestation through each annual observation period. • Respond to client security questionnaires and due-diligence requests in support of partner-firm engagements, maintaining a reusable evidence library to shorten turnaround. • Manage PCI DSS compliance for payment acceptance across Ascend and its partner firms, and own the third-party and vendor risk management program, including security review of new tools prior to adoption. • Define and enforce identity and access management standards in Microsoft 365 and Entra ID, including conditional access, multifactor authentication, and privileged access management. • Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, and ensure the security of tax production platforms (CCH Axcess, UltraTax) throughout the client-data lifecycle. • Establish and own the AI governance program: acceptable use policy, AI tool and model risk assessment, data-protection standards for client data in AI systems, and an intake process that moves at the speed of the business. • Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring of AI tool usage, and security review of third-party AI vendors and integrations before they touch client data. • Lead cybersecurity due diligence for acquisitions, surfacing material risk before close, and own the security workstream of the TST process for newly acquired partner firms; build a repeatable integration playbook that shortens time-to-secure as acquisition volume grows. • Build, manage, and develop a team of security engineers and analysts; set priorities, define performance standards, grow team capabilities, and hire A-players into key security seats. • Own the security awareness training and phishing simulation program across all partner firms, tracking and driving down phishing failure rates and reporting human-risk metrics alongside technical metrics.

🎯 Requisitos

• 10+ years in information security, with 5+ years leading security teams or programs. • Experience securing professional services, financial services, or other regulated environments handling sensitive client data; experience in a hypergrowth, acquisition-driven, multi-entity environment strongly preferred. • Deep working knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS. • Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems. • Hands-on depth across EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms. • Demonstrated incident response leadership, including incident command and executive communication during active incidents. • Strong vendor management and budget ownership experience. • CISSP, CISM, or equivalent certification preferred; Azure security certifications a plus.

🏖️ Benefícios

• Health insurance • 401(k) plans • Flexible work arrangements • Professional development opportunities • Equipment allowances

Candidatar-se

Vagas Similares

🕒 Julho 28

Highmark Health

10.000+ funcionários

🛡️ Seguros

💼 Consultoria

📦 Logística

Principal Information Security Architect at Highmark Health designing and advancing secure data architectures. Collaborating with various teams to protect sensitive information across its lifecycle.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $129.100 - $214.500 / ano

💰 $5.000.000 Grant em 2021-05

⏰ Tempo Integral

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🦅 Patrocina Visto H1B

infoinfo

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 28

Availity

1001 - 5000

🏥 Saúde

💼 Consultoria

📦 Logística

Chief Information Security Officer managing enterprise cybersecurity and risk programs for healthcare technology company. Overseeing security audits, compliance, and protecting sensitive information.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 28

Conduent

10.000+ funcionários

🤝 B2B

☁️ SaaS

🏢 Corporativo

IT Security Architect defining security architecture standards across identity, infrastructure, and cloud environments. Leading architecture for major initiatives, ensuring compliance with industry standards.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $130.000 - $160.000 / ano

💰 $93.000.000 Post-IPO Debt - Conduent em 2025-08

⏰ Tempo Integral

🟠 Sênior

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

OKSI

51 - 200

🎖️ Defesa

🚀 Aeroespacial

🤖 Inteligência Artificial

Product Security Engineer at Opto-Knowledge Systems Inc owning security across hardware and software systems. Leading threat modeling and compliance for product portfolio with collaboration across teams.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $154.000 - $210.000 / ano

💰 $206.500 Grant - Opto-Knowledge Systems em 2024-01

⏰ Tempo Integral

🟠 Sênior

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Julho 27

Grow Therapy

201 - 500

🏥 Saúde

⚕️ Seguro de Saúde

🏪 Marketplace

Staff Engineer, Security architecting secure infrastructure at Grow Therapy. Leading multi-year roadmap for security initiatives to protect customers and empower engineering organization.

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $182.000 - $288.000 / ano

⏰ Tempo Integral

🔴 Especialista

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório