Director, Cybersecurity

Posted Jul 29

This is a fully remote position, open to applicants in United States.

📋 Description

• Take ownership of the enterprise cybersecurity strategy and long-term roadmap, prioritizing initiatives in alignment with partner-firm seasonality (tax deadlines) and the overall Technology Stack Transition (TST) integration schedule; present the strategy and updates to the Vice President of Technology Infrastructure & Cybersecurity.

• Establish, monitor, and report a clear set of security metrics and program maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to the executive leadership on a regular basis.

• Develop and oversee the cybersecurity budget for tools, MSSP/vendor contracts, and staffing, ensuring transparency and competitiveness in security costs across partner firms.

• Manage partnerships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), attaining preferred pricing and early access to product roadmaps and preview programs.

• Oversee endpoint detection and response (CrowdStrike Falcon), security monitoring, log management, vulnerability management, and email security across Ascend and all partner firms.

• Act as the incident commander for cybersecurity incidents; maintain and regularly test the incident response plan through tabletop exercises, leading post-incident reviews and ensuring remediation is completed.

• Establish detection coverage, alert triage, and escalation protocols, determining the appropriate outsourced vs. in-house MSSP model for continuous monitoring.

• Set vulnerability and patch SLAs based on asset criticality and collaborate with infrastructure and service desk teams to ensure remediation occurs; engage a qualified external firm for periodic penetration testing.

• Manage the governance, risk, and compliance program, which includes conducting enterprise risk assessments and developing security policies and standards aligned with NIST CSF 2.0.

• Lead the complete SOC 2 Type II audit lifecycle — from control design to evidence collection and auditor management — ensuring a clean attestation through each annual observation period.

• Respond to client security questionnaires and due diligence inquiries in support of partner-firm engagements, maintaining a reusable evidence library to expedite responses.

• Oversee PCI DSS compliance for payment acceptance across Ascend and its partner firms, as well as manage the third-party and vendor risk management program, including the security review of new tools prior to their adoption.

• Define and enforce identity and access management standards in Microsoft 365 and Entra ID, covering conditional access, multi-factor authentication, and privileged access management.

• Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, ensuring security throughout the client-data lifecycle in tax production platforms (CCH Axcess, UltraTax).

• Establish and manage the AI governance program: acceptable use policies, AI tool and model risk assessments, data protection standards for client data in AI systems, and a streamlined intake process that aligns with business speed.

• Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring AI tool usage, and conducting security reviews of third-party AI vendors and integrations before they interact with client data.

• Lead cybersecurity due diligence for acquisitions, identifying material risks before closing, and manage the security workstream of the TST process for newly acquired partner firms; create a repeatable integration playbook to reduce time-to-secure as acquisition volume increases.

• Build, manage, and develop a team of security engineers and analysts; set priorities, define performance metrics, enhance team capabilities, and recruit top talent for critical security roles.

• Oversee the security awareness training and phishing simulation program across all partner firms, monitoring and reducing phishing failure rates and reporting on human-risk metrics alongside technical metrics.


⛳️ Requirements

• A minimum of 10 years in information security, with at least 5 years in leadership roles for security teams or programs.

• Experience in securing professional services, financial services, or other regulated environments that manage sensitive client data; experience in a fast-paced, acquisition-oriented, multi-entity setting is highly preferred.

• Extensive knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS.

• Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems.

• Practical experience with EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms.

• Proven leadership in incident response, including incident command and effective executive communication during active incidents.

• Strong experience in vendor management and budget oversight.

• CISSP, CISM, or equivalent certification is preferred; Azure security certifications are a plus.


🏝️ Benefits

• Health insurance

• 401(k) plans

• Flexible work arrangements

• Professional development opportunities

• Equipment allowances

People also viewed

Sony Interactive Entertainment23 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads23 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j23 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting1 day ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International1 day ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers