Director, Cybersecurity

🕒 vor 2 Tagen

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Azure

Cyber Security

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Ascend

Ascend

1001 - 5000 Mitarbeiter

Gegründet 2023

🤝 B2B

💼 Beratung

💰 €2.018.785 Seed Round - Ascend im 2025-02

B2B • Consulting

Ascend ist eine moderne Plattform, die mit unternehmerischen Wirtschaftsprüfungsgesellschaften zusammenarbeitet und die Ressourcen und Vorteile einer großen Wirtschaftsprüfungsgesellschaft bietet, während die Unabhängigkeit jeder Firma gewahrt bleibt. Unterstützt von der menschenorientierten Private Equity Gesellschaft Alpine Investors und gegründet im Januar 2023, bietet Ascend Wachstumskapital, Talentakquise und -entwicklung, transformative Technologie, ein katalytisches Führungssystem, gemeinsame Back-Office-Dienste und modernisierte Aktienanreize, um regionalen Wirtschaftsprüfungsgesellschaften beim Skalieren zu helfen. Das Unternehmen wird bereits von Accounting Today als eine der Top 25 Firmen anerkannt.

Beschreibung

• Own the enterprise cybersecurity strategy and multi-year roadmap, sequencing initiatives against partner-firm seasonality (tax deadlines) and the broader TST (Technology Stack Transition) integration timeline; present strategy and progress to the Vice President, Technology Infrastructure & Cybersecurity. • Define, track, and report a concise set of security metrics and program-maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to executive leadership on a fixed cadence. • Develop and manage the cybersecurity budget for tooling, MSSP/vendor contracts, and headcount, keeping security cost transparent and competitive across partner firms. • Manage relationships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), securing preferred pricing and early access to product roadmaps and preview programs. • Own endpoint detection and response (CrowdStrike Falcon), security monitoring and log management, vulnerability management, and email security across Ascend and all partner firms. • Serve as incident commander for cybersecurity incidents; maintain and test the incident response plan through regular tabletop exercises, and lead post-incident reviews and remediation to closure. • Establish detection coverage, alert triage, and escalation standards, and determine the right outsourced-vs.-in-house MSSP model for 24x7 monitoring. • Define vulnerability and patch SLAs by asset criticality and partner with infrastructure and service-desk teams to ensure remediation lands; engage a qualified external firm to conduct periodic penetration testing. • Own the governance, risk, and compliance program, including enterprise risk assessments and security policies and standards aligned to NIST CSF 2.0. • Own the full SOC 2 Type II audit lifecycle — control design, evidence collection, and auditor management — sustaining a clean attestation through each annual observation period. • Respond to client security questionnaires and due-diligence requests in support of partner-firm engagements, maintaining a reusable evidence library to shorten turnaround. • Manage PCI DSS compliance for payment acceptance across Ascend and its partner firms, and own the third-party and vendor risk management program, including security review of new tools prior to adoption. • Define and enforce identity and access management standards in Microsoft 365 and Entra ID, including conditional access, multifactor authentication, and privileged access management. • Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, and ensure the security of tax production platforms (CCH Axcess, UltraTax) throughout the client-data lifecycle. • Establish and own the AI governance program: acceptable use policy, AI tool and model risk assessment, data-protection standards for client data in AI systems, and an intake process that moves at the speed of the business. • Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring of AI tool usage, and security review of third-party AI vendors and integrations before they touch client data. • Lead cybersecurity due diligence for acquisitions, surfacing material risk before close, and own the security workstream of the TST process for newly acquired partner firms; build a repeatable integration playbook that shortens time-to-secure as acquisition volume grows. • Build, manage, and develop a team of security engineers and analysts; set priorities, define performance standards, grow team capabilities, and hire A-players into key security seats. • Own the security awareness training and phishing simulation program across all partner firms, tracking and driving down phishing failure rates and reporting human-risk metrics alongside technical metrics.

🎯 Anforderungen

• 10+ years in information security, with 5+ years leading security teams or programs. • Experience securing professional services, financial services, or other regulated environments handling sensitive client data; experience in a hypergrowth, acquisition-driven, multi-entity environment strongly preferred. • Deep working knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS. • Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems. • Hands-on depth across EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms. • Demonstrated incident response leadership, including incident command and executive communication during active incidents. • Strong vendor management and budget ownership experience. • CISSP, CISM, or equivalent certification preferred; Azure security certifications a plus.

🏖️ Vorteile

• Health insurance • 401(k) plans • Flexible work arrangements • Professional development opportunities • Equipment allowances

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 2 Tagen

NMS

1001 - 5000

🍽️ Lebensmittel & Getränke

📦 Logistik

🏥 Gesundheitswesen

Remote Security Captain providing operational support for security services in Kuparuk oil field. Supervising personnel and ensuring compliance with health, safety, and security standards.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

The Home Depot

10.000+ Mitarbeiter

🏗️ Bauwesen

📦 Logistik

🛒 Einzelhandel

Cybersecurity Principal Engineer at The Home Depot focusing on AI-driven security and fraud detection. Leading implementations of AI security frameworks to protect sensitive data.

🇺🇸 Vereinigte Staaten – Remote

💵 $170.000 - $240.000 / Jahr

💰 Debt Financing im 2007-07

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

Highmark Health

10.000+ Mitarbeiter

🛡️ Versicherung

💼 Beratung

📦 Logistik

Principal Information Security Architect at Highmark Health designing and advancing secure data architectures. Collaborating with various teams to protect sensitive information across its lifecycle.

🇺🇸 Vereinigte Staaten – Remote

💵 $129.100 - $214.500 / Jahr

💰 €5.000.000 Grant im 2021-05

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🦅 H1B-Visum-Sponsor

info

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

Horizon3.ai

51 - 200

🔒 Cybersecurity

🤖 Künstliche Intelligenz

☁️ SaaS

Staff Defensive Security Software Engineer focused on developing deception capabilities within NodeZero for cybersecurity solutions. Collaborating across teams to enhance detection and response reliability.

🇺🇸 Vereinigte Staaten – Remote

💵 $240.000 - $270.000 / Jahr

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

Union Home Mortgage Corp.

1001 - 5000

🏦 Bankwesen

🏠 Immobilien

Cybersecurity Manager leading design, implementation, and improvement of cybersecurity programs protecting systems and data. Collaborates with internal teams and manages external partners in security operations.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cloud

Cyber Security