
Director, Cybersecurity
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in United States.
• Take ownership of the enterprise cybersecurity strategy and long-term roadmap, prioritizing initiatives in alignment with partner-firm seasonality (tax deadlines) and the overall Technology Stack Transition (TST) integration schedule; present the strategy and updates to the Vice President of Technology Infrastructure & Cybersecurity.
• Establish, monitor, and report a clear set of security metrics and program maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to the executive leadership on a regular basis.
• Develop and oversee the cybersecurity budget for tools, MSSP/vendor contracts, and staffing, ensuring transparency and competitiveness in security costs across partner firms.
• Manage partnerships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), attaining preferred pricing and early access to product roadmaps and preview programs.
• Oversee endpoint detection and response (CrowdStrike Falcon), security monitoring, log management, vulnerability management, and email security across Ascend and all partner firms.
• Act as the incident commander for cybersecurity incidents; maintain and regularly test the incident response plan through tabletop exercises, leading post-incident reviews and ensuring remediation is completed.
• Establish detection coverage, alert triage, and escalation protocols, determining the appropriate outsourced vs. in-house MSSP model for continuous monitoring.
• Set vulnerability and patch SLAs based on asset criticality and collaborate with infrastructure and service desk teams to ensure remediation occurs; engage a qualified external firm for periodic penetration testing.
• Manage the governance, risk, and compliance program, which includes conducting enterprise risk assessments and developing security policies and standards aligned with NIST CSF 2.0.
• Lead the complete SOC 2 Type II audit lifecycle — from control design to evidence collection and auditor management — ensuring a clean attestation through each annual observation period.
• Respond to client security questionnaires and due diligence inquiries in support of partner-firm engagements, maintaining a reusable evidence library to expedite responses.
• Oversee PCI DSS compliance for payment acceptance across Ascend and its partner firms, as well as manage the third-party and vendor risk management program, including the security review of new tools prior to their adoption.
• Define and enforce identity and access management standards in Microsoft 365 and Entra ID, covering conditional access, multi-factor authentication, and privileged access management.
• Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, ensuring security throughout the client-data lifecycle in tax production platforms (CCH Axcess, UltraTax).
• Establish and manage the AI governance program: acceptable use policies, AI tool and model risk assessments, data protection standards for client data in AI systems, and a streamlined intake process that aligns with business speed.
• Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring AI tool usage, and conducting security reviews of third-party AI vendors and integrations before they interact with client data.
• Lead cybersecurity due diligence for acquisitions, identifying material risks before closing, and manage the security workstream of the TST process for newly acquired partner firms; create a repeatable integration playbook to reduce time-to-secure as acquisition volume increases.
• Build, manage, and develop a team of security engineers and analysts; set priorities, define performance metrics, enhance team capabilities, and recruit top talent for critical security roles.
• Oversee the security awareness training and phishing simulation program across all partner firms, monitoring and reducing phishing failure rates and reporting on human-risk metrics alongside technical metrics.
• A minimum of 10 years in information security, with at least 5 years in leadership roles for security teams or programs.
• Experience in securing professional services, financial services, or other regulated environments that manage sensitive client data; experience in a fast-paced, acquisition-oriented, multi-entity setting is highly preferred.
• Extensive knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS.
• Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems.
• Practical experience with EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms.
• Proven leadership in incident response, including incident command and effective executive communication during active incidents.
• Strong experience in vendor management and budget oversight.
• CISSP, CISM, or equivalent certification is preferred; Azure security certifications are a plus.
• Health insurance
• 401(k) plans
• Flexible work arrangements
• Professional development opportunities
• Equipment allowances
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.