Director of Security

🕒 vor 3 Tagen

🇺🇸 Vereinigte Staaten – Remote

💵 $187.000 - $225.000 / Jahr

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Azure

Cloud

Cyber Security

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of Current

Current

1001 - 5000 Mitarbeiter

🤝 B2B

💼 Beratung

🏢 Unternehmen

B2B • Consulting • Enterprise

Current ist eine Plattform (früher Crete Professionals Alliance), die unabhängige Buchhaltungsfirmen dazu befähigt, durch die Kombination von Technologie, Talent, Kapital und Strategie zu skalieren. Gegründet im Jahr 2023, betreibt Current ein wachsendes Netzwerk von Partnerfirmen (die Webseite gibt 48 Firmen, über 2. 000 Mitarbeiter in 39 Bundesstaaten und 3 Ländern an) und bietet Dienstleistungen, die Firmen helfen, Wachstum zu beschleunigen, ohne die Unabhängigkeit zu opfern. Die Angebote und Fähigkeiten von Current betonen Tech-Transformation (Automatisierung, KI, optimierte Workflows), globale Servicebereitstellung, M&A und strategische Expansion, Talentkontinuität, Marken- und Marketingunterstützung sowie gemeinsame operative Infrastruktur. Current weist darauf hin, dass es keine lizenzierte CPA-Firma ist; Tochtergesellschaften bieten nicht-testierte Steuer-, Beratungs- und andere Dienstleistungen an, und Netzwerksfirmen arbeiten in einer alternativen Praxisstruktur.

Beschreibung

• Own the enterprise information security, compliance & business continuity program across Crete (corporate) and all member firms. • Build standardized, scalable security controls, governance, and operations across multiple independent control environments. • Define the multi-year security strategy and roadmap across Crete and member firms in a federated model, aligning priorities to business risk and acquisition cadence. • Establish and maintain the security policy framework, standards, and minimum control baseline across all firms; design pragmatic exception handling and remediation plans for varying maturity levels. • Build security operating rhythms and executive reporting: KPIs, risk posture, incident trends, audit/compliance status, and program progress for Crete leadership and firm leaders. • Partner with IT, data, and engineering leadership to embed security into operations, architecture decisions, and change management across the portfolio. • Lead security diligence for M&A: current-state control assessments, key risk identification, remediation estimates, and repeatable post-close stabilization playbooks (30/60/90-day plans). • Drive security integration of new firms (people/process/technology) across separate environments — identity, endpoint/email, logging/monitoring, data protection — with scalable onboarding playbooks and control alignment patterns. • Provide security architecture oversight for cloud and hybrid environments with emphasis on Azure, Intune, and Microsoft Defender; define secure patterns for privileged access, conditional access, PAM, RBAC, and separation of duties. • Oversee day-to-day security operations: vulnerability management, patch/risk prioritization, endpoint and email security, tooling lifecycle, and event triage across Crete and member firms. • Manage third-party MDR/SOC providers — scope, SLAs, escalation paths, detection coverage, playbooks, reporting — and drive continuous improvement of monitoring outcomes. • Own the incident response program end-to-end: runbooks, tabletop exercises, ransomware preparedness, forensics coordination, and post-incident reviews with corrective actions. • Implement consistent risk management across firms — periodic assessments, control testing, remediation tracking — and own third-party/vendor security risk management for corporate and shared vendors. • Support member firms with client-driven security and compliance requirements (NIST CSF, CIS, SOC 2 Type II); ensure evidence collection is repeatable and accurate. • Lead security awareness and training programs tailored to professional services workflows, with measurable adoption and behavioral outcomes. • Lead, coach, and develop the cybersecurity team; serve as escalation point for security decisions, incidents, and complex risk tradeoffs. • Build documentation, playbooks, and implementation guides that enable consistent security outcomes across firms; influence firm leaders and local teams to drive baseline control adoption.

🎯 Anforderungen

• 10+ years of progressive experience in information security or cybersecurity. • 3+ years leading and developing security teams. • Demonstrated M&A, private equity, or roll-up experience. • Strong understanding of cloud security principles with hands-on Azure and Microsoft security experience. • Experience managing and governing compliance standards (NIST, CSF, CIS, and SOC2 Type II preferred) • Experience managing business continuity programs and lifecycle • Microsoft Azure/Intune experience • Experience managing third-party security services (MDR/SOC, IR retainers, testing vendors). • Proven ability to design and run a complete enterprise security control program. • Excellent stakeholder management and executive communication skills. • Bachelor’s degree or equivalent experience; security certifications preferred (CISSP). • Professional services experience and /or accounting and CPA firm experience strongly preferred.

🏖️ Vorteile

• Health, Dental, and Vision Insurance (with options for fully paid employee only coverage for health and dental) • Company-Paid Life and Long-Term Disability Insurance • Ancillary Benefits such as supplemental life insurance and short-term disability options • Classic Safe Harbor 401(k) Plan with employer contributions • Opportunities for professional growth, learning, and development including access to Becker and LinkedIn Learning

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 3 Tagen

TRM Labs

201 - 500

₿ Crypto

📋 Compliance

🤝 B2B

Global Strategic Account Director accelerating data product launches within existing enterprise accounts and working with National Security and Defense agencies.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

TRM Labs

201 - 500

₿ Crypto

📋 Compliance

🤝 B2B

Account Director driving enterprise SaaS sales to the intelligence community, leveraging relationships and expertise in mission environments.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 3 Tagen

Danaher

10.000+ Mitarbeiter

🧬 Biotechnologie

🏥 Gesundheitswesen

🔬 Wissenschaft

Director of Enterprise Data Security leading cybersecurity initiatives at Danaher Corporation. Focused on protecting sensitive data and mitigating insider risk while collaborating with cross-functional teams.

🇺🇸 Vereinigte Staaten – Remote

💵 $170.000 - $210.000 / Jahr

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Cyber Security

🕒 vor 4 Tagen

Snowflake

5001 - 10000

☁️ SaaS

🏢 Unternehmen

🤝 B2B

Principal Security Engineer shaping Threat Intelligence program at Snowflake. Combining intelligence expertise with strong engineering and leadership skills to enhance security measures.

🇺🇸 Vereinigte Staaten – Remote

💵 $249.000 - $311.000 / Jahr

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 4 Tagen

GE Aerospace

10.000+ Mitarbeiter

🚀 Luft- und Raumfahrt

🏭 Fertigung

🎖️ Verteidigung

Director of Offensive Security responsible for shaping an AI-enabled offensive security program. Leading penetration testing, Red Team engagements, and delivering security validations in a remote setting.

🇺🇸 Vereinigte Staaten – Remote

💵 $152.000 - $220.000 / Jahr

💰 €2.000.000.000 Post-IPO Debt - GE Aerospace im 2025-07

⏰ Vollzeit

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich