
Director of Information Security
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Develop, sustain, and execute the organization’s information security program, roadmap, and annual goals.
• Establish security configuration and hardening standards for Microsoft 365 and Entra ID, collaborating with infrastructure for implementation.
• Set standards for antivirus, endpoint detection and response, email filtering, email security, firewall, and network-device security compliance.
• Define and execute data protection measures, including classification, retention, encryption, and data loss prevention (DLP).
• Maintain security policies, technical standards, controls, exceptions, and audit procedures.
• Lead risk evaluations, control assessments, security planning, remediation tracking, and closure of corrective actions.
• Manage the risk register and coordinate security and vendor risk evaluations.
• Develop and manage the GLBA and FTC Safeguards program while addressing relevant HIPAA, PCI DSS, CCPA, CPRA, and additional compliance requirements.
• Assist with client security evaluations, cyber insurance prerequisites, audits, and regulatory or contractual compliance initiatives.
• Conduct regular system access audits and gather evidence for compliance.
• Maintain the incident response strategy and coordinate incident response efforts, including external responders, communications, and documentation.
• Facilitate incident response tabletop drills and implement improvements based on post-exercise evaluations.
• Coordinate vulnerability assessments and penetration testing, tracking remediation efforts.
• Oversee the security awareness and phishing simulation initiatives.
• Assess and manage managed-security and security-tool vendors, recommending any necessary partnership adjustments.
• Conduct security and risk evaluations for software, services, and vendor partnerships.
• Participate in security due diligence for acquisition targets and document their security posture for integration.
• Monitor emerging cyber threats, regulatory changes, and best practices, translating these into security enhancements.
• 7+ years of progressive experience in IT and security, including at least 3 years of hands-on expertise in information security.
• Capability to plan and independently implement security controls.
• Practical experience in securing Microsoft 365 and Entra ID, including Conditional Access, MFA, Microsoft Defender, mail flow, and email authentication.
• Experience managing endpoints using Intune.
• Hands-on expertise with EDR, antivirus, vulnerability scanning, access audits, and coordination of incident response.
• Proven ability to deliver outcomes through managed-security and vendor partnerships, including evaluation, direction, and accountability.
• Working knowledge of GLBA, FTC Safeguards, privacy regulations, and compliance frameworks related to financial or professional services data.
• Experience in maintaining security policies and a risk register, translating them into actionable controls.
• Strong communication and collaboration abilities across Infrastructure, Support, and business teams.
• Experience in professional services, accounting, or another regulated financial-data environment is preferred.
• Experience in integrating or standardizing security in a multi-location or acquisitive organization is preferred.
• Familiarity with hosted or virtual desktop solutions and related vendor management is preferred.
• Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials are preferred.
• Generous paid time off.
• Comprehensive medical, dental, and vision insurance.
• Life and disability coverage.
• 401(k) retirement savings plan.
• Paid holidays, including a company-wide winter break (December 24 – January 1).
• Paid parental leave (available after one year of service).
• Mentorship and professional development programs.
• CPA exam assistance to help you succeed on your path to licensure.
• Firm-sponsored events and spontaneous team activities.
• Celebrations to mark milestones such as the conclusion of busy seasons and holidays.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.