Director of Information Security

Job not on LinkedIn

🔥 3 hours ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Sorren

Sorren

1001 - 5000 employees

Founded 2025

💼 Consulting

⚖️ Legal

🛡️ Insurance

Consulting • Legal • Insurance

Sorren is a Top-50 accounting and advisory firm formed by like-minded leaders from 13 firms, providing assurance, tax, accounting, advisory, and private client services. The firm offers audits, tax planning and representation, bookkeeping, controller/CFO services, business valuations, transaction and forensic advisory, and family office and estate planning services for businesses, nonprofits, government entities and high-net-worth individuals. Sorren emphasizes local community engagement, proactive strategic guidance, and tailored solutions to help clients grow and manage complex financial and compliance needs.

📋 Description

• Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities. • Define Microsoft 365 and Entra ID security configuration and hardening standards and work with infrastructure to implement them. • Establish AV, EDR, email filtering, email security, firewall, and network-device security standards and compliance. • Define and implement data protection controls, including classification, retention, encryption, and DLP. • Maintain security policies, technical standards, controls, exceptions, and audit processes. • Lead risk assessments, control reviews, security planning, remediation tracking, and corrective-action closure. • Own the risk register and coordinate security and vendor risk assessments. • Build and run the GLBA and FTC Safeguards program and address applicable HIPAA, PCI DSS, CCPA, CPRA, and other requirements. • Support client security reviews, cyber insurance requirements, audits, and regulatory or contractual compliance efforts. • Conduct recurring system access reviews and collect audit evidence. • Maintain the incident response plan and coordinate incident response activities, external responders, communications, and documentation. • Facilitate incident response tabletop exercises and post-exercise improvements. • Coordinate vulnerability scans and penetration tests and track remediation. • Own the security awareness and phishing simulation program. • Evaluate and manage managed-security and security-tool vendors and recommend partnership changes. • Conduct security and risk assessments for software, services, and vendor relationships. • Participate in acquisition-target security due diligence and document security posture for integration. • Monitor evolving cyber threats, regulations, and leading practices and translate them into security improvements.

🎯 Requirements

• 7+ years of progressive IT and security experience, including 3 or more years hands-on in information security • Ability to plan security controls and implement them independently • Hands-on experience securing Microsoft 365 and Entra ID, including Conditional Access, MFA, Microsoft Defender, mail-flow, and email authentication • Experience managing endpoints with Intune • Practical experience with EDR, AV, vulnerability scanning, access reviews, and incident response coordination • Experience delivering results through managed-security and vendor partners, including evaluating, directing, and holding them accountable • Working knowledge of GLBA, FTC Safeguards, privacy requirements, and compliance frameworks for financial or professional services data • Experience maintaining security policies and a risk register and converting them into implemented controls • Strong communication and collaboration skills across Infrastructure, Support, and business teams • Experience in professional services, accounting, or another regulated financial-data environment preferred • Experience integrating or standardizing security across a multi-location or acquisitive organization preferred • Familiarity with hosted or virtual desktop platforms and related vendor management preferred • Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials preferred

🏖️ Benefits

• Generous paid time off • Comprehensive medical, dental, and vision coverage • Life and disability insurance • 401(k) retirement savings plan • Paid holidays, including a firmwide winter break (December 24 – January 1) • Paid parental leave (available after one year of service) • Mentorship and career development programs • CPA exam support to help you succeed on the path to licensure • Firm-sponsored events and spontaneous team activities • Celebrations to mark milestones like the end of busy season and the holidays

Apply Now

Similar Jobs

🔥 4 hours ago

Banner Health

10,000+ employees

🏥 Healthcare

⚕️ Healthcare Insurance

Cybersecurity Engineer III securing Banner Health’s nonprofit healthcare infrastructure. Designing cyber solutions, leading incident response, compliance, integrations, and security projects.

🔥 6 hours ago

Guidehouse

10,000+ employees

🏥 Healthcare

🎖️ Defense

📦 Logistics

Guidehouse executive advising U.S. Defense and Security clients on DoD financial management engagements and pursuits. Building Air Force, Army, and Navy portfolios through executive engagement, thought leadership, and partner collaboration.

🔥 8 hours ago

Tremendous

51 - 200

💼 Consulting

📣 Marketing

📦 Logistics

Head of Security owning cybersecurity for Tremendous, a global business payouts platform. Building security posture, incident response, AI risk controls, and the future security team.

🔥 9 hours ago

BCD Travel

10,000+ employees

💼 Consulting

📦 Logistics

🏨 Hospitality

BCD Travel security director leading cybersecurity, risk, and assurance for Mid-Market operations. Translating enterprise strategy into secure execution for a global business travel company.

🔥 10 hours ago

Cotiviti

5001 - 10000

🏥 Healthcare

💼 Consulting

📦 Logistics

FedRAMP Information Systems Security Manager sustaining authorization and continuous compliance for Cotiviti’s cloud systems serving U.S. government healthcare customers. Leading security documentation, assessments, monitoring, and audit readiness.