Director, Cybersecurity

🔥 3 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Ascend

Ascend

1001 - 5000 employees

Founded 2023

🤝 B2B

💼 Consulting

💰 $2M Seed Round - Ascend on 2025-02

B2B • Consulting

Ascend is a modern platform that partners with entrepreneurial CPA firms, bringing the resources and advantages of a large accounting firm while preserving each firm's independence. Backed by people-focused private equity firm Alpine Investors and founded in January 2023, Ascend provides growth capital, talent acquisition and development, transformative technology, a catalytic leadership system, shared back-office services, and modernized equity incentives to help regional accounting firms scale. The company is already recognized as a Top 25 firm by Accounting Today.

📋 Description

• Own the enterprise cybersecurity strategy and multi-year roadmap, sequencing initiatives against partner-firm seasonality (tax deadlines) and the broader TST (Technology Stack Transition) integration timeline; present strategy and progress to the Vice President, Technology Infrastructure & Cybersecurity. • Define, track, and report a concise set of security metrics and program-maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to executive leadership on a fixed cadence. • Develop and manage the cybersecurity budget for tooling, MSSP/vendor contracts, and headcount, keeping security cost transparent and competitive across partner firms. • Manage relationships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), securing preferred pricing and early access to product roadmaps and preview programs. • Own endpoint detection and response (CrowdStrike Falcon), security monitoring and log management, vulnerability management, and email security across Ascend and all partner firms. • Serve as incident commander for cybersecurity incidents; maintain and test the incident response plan through regular tabletop exercises, and lead post-incident reviews and remediation to closure. • Establish detection coverage, alert triage, and escalation standards, and determine the right outsourced-vs.-in-house MSSP model for 24x7 monitoring. • Define vulnerability and patch SLAs by asset criticality and partner with infrastructure and service-desk teams to ensure remediation lands; engage a qualified external firm to conduct periodic penetration testing. • Own the governance, risk, and compliance program, including enterprise risk assessments and security policies and standards aligned to NIST CSF 2.0. • Own the full SOC 2 Type II audit lifecycle — control design, evidence collection, and auditor management — sustaining a clean attestation through each annual observation period. • Respond to client security questionnaires and due-diligence requests in support of partner-firm engagements, maintaining a reusable evidence library to shorten turnaround. • Manage PCI DSS compliance for payment acceptance across Ascend and its partner firms, and own the third-party and vendor risk management program, including security review of new tools prior to adoption. • Define and enforce identity and access management standards in Microsoft 365 and Entra ID, including conditional access, multifactor authentication, and privileged access management. • Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, and ensure the security of tax production platforms (CCH Axcess, UltraTax) throughout the client-data lifecycle. • Establish and own the AI governance program: acceptable use policy, AI tool and model risk assessment, data-protection standards for client data in AI systems, and an intake process that moves at the speed of the business. • Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring of AI tool usage, and security review of third-party AI vendors and integrations before they touch client data. • Lead cybersecurity due diligence for acquisitions, surfacing material risk before close, and own the security workstream of the TST process for newly acquired partner firms; build a repeatable integration playbook that shortens time-to-secure as acquisition volume grows. • Build, manage, and develop a team of security engineers and analysts; set priorities, define performance standards, grow team capabilities, and hire A-players into key security seats. • Own the security awareness training and phishing simulation program across all partner firms, tracking and driving down phishing failure rates and reporting human-risk metrics alongside technical metrics.

🎯 Requirements

• 10+ years in information security, with 5+ years leading security teams or programs. • Experience securing professional services, financial services, or other regulated environments handling sensitive client data; experience in a hypergrowth, acquisition-driven, multi-entity environment strongly preferred. • Deep working knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS. • Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems. • Hands-on depth across EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms. • Demonstrated incident response leadership, including incident command and executive communication during active incidents. • Strong vendor management and budget ownership experience. • CISSP, CISM, or equivalent certification preferred; Azure security certifications a plus.

🏖️ Benefits

• Health insurance • 401(k) plans • Flexible work arrangements • Professional development opportunities • Equipment allowances

Apply Now

Similar Jobs

🔥 4 hours ago

NMS

1001 - 5000

🍽️ Food & Beverage

📦 Logistics

🏥 Healthcare

Remote Security Captain providing operational support for security services in Kuparuk oil field. Supervising personnel and ensuring compliance with health, safety, and security standards.

🔥 9 hours ago

RYZE

11 - 50

🏥 Healthcare

💼 Consulting

📣 Marketing

Director of IT Infrastructure & Security at a fully remote, global company. Leading the build-out of IT systems and overseeing security protocols.

🔥 9 hours ago

The Home Depot

10,000+ employees

🏗️ Construction

📦 Logistics

🛒 Retail

Cybersecurity Principal Engineer at The Home Depot focusing on AI-driven security and fraud detection. Leading implementations of AI security frameworks to protect sensitive data.

🇺🇸 United States – Remote

💵 $170k - $240k / year

💰 Debt Financing on 2007-07

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

🔥 11 hours ago

Highmark Health

10,000+ employees

🛡️ Insurance

💼 Consulting

📦 Logistics

Principal Information Security Architect at Highmark Health designing and advancing secure data architectures. Collaborating with various teams to protect sensitive information across its lifecycle.

🔥 13 hours ago

Horizon3.ai

51 - 200

🔒 Cybersecurity

🤖 Artificial Intelligence

☁️ SaaS

Staff Defensive Security Software Engineer focused on developing deception capabilities within NodeZero for cybersecurity solutions. Collaborating across teams to enhance detection and response reliability.