Remotery

Director of Information Security

Posted Aug 5

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop, sustain, and execute the organization’s information security program, roadmap, and annual goals.

• Establish security configuration and hardening standards for Microsoft 365 and Entra ID, collaborating with infrastructure for implementation.

• Set standards for antivirus, endpoint detection and response, email filtering, email security, firewall, and network-device security compliance.

• Define and execute data protection measures, including classification, retention, encryption, and data loss prevention (DLP).

• Maintain security policies, technical standards, controls, exceptions, and audit procedures.

• Lead risk evaluations, control assessments, security planning, remediation tracking, and closure of corrective actions.

• Manage the risk register and coordinate security and vendor risk evaluations.

• Develop and manage the GLBA and FTC Safeguards program while addressing relevant HIPAA, PCI DSS, CCPA, CPRA, and additional compliance requirements.

• Assist with client security evaluations, cyber insurance prerequisites, audits, and regulatory or contractual compliance initiatives.

• Conduct regular system access audits and gather evidence for compliance.

• Maintain the incident response strategy and coordinate incident response efforts, including external responders, communications, and documentation.

• Facilitate incident response tabletop drills and implement improvements based on post-exercise evaluations.

• Coordinate vulnerability assessments and penetration testing, tracking remediation efforts.

• Oversee the security awareness and phishing simulation initiatives.

• Assess and manage managed-security and security-tool vendors, recommending any necessary partnership adjustments.

• Conduct security and risk evaluations for software, services, and vendor partnerships.

• Participate in security due diligence for acquisition targets and document their security posture for integration.

• Monitor emerging cyber threats, regulatory changes, and best practices, translating these into security enhancements.


⛳️ Requirements

• 7+ years of progressive experience in IT and security, including at least 3 years of hands-on expertise in information security.

• Capability to plan and independently implement security controls.

• Practical experience in securing Microsoft 365 and Entra ID, including Conditional Access, MFA, Microsoft Defender, mail flow, and email authentication.

• Experience managing endpoints using Intune.

• Hands-on expertise with EDR, antivirus, vulnerability scanning, access audits, and coordination of incident response.

• Proven ability to deliver outcomes through managed-security and vendor partnerships, including evaluation, direction, and accountability.

• Working knowledge of GLBA, FTC Safeguards, privacy regulations, and compliance frameworks related to financial or professional services data.

• Experience in maintaining security policies and a risk register, translating them into actionable controls.

• Strong communication and collaboration abilities across Infrastructure, Support, and business teams.

• Experience in professional services, accounting, or another regulated financial-data environment is preferred.

• Experience in integrating or standardizing security in a multi-location or acquisitive organization is preferred.

• Familiarity with hosted or virtual desktop solutions and related vendor management is preferred.

• Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials are preferred.


🏝️ Benefits

• Generous paid time off.

• Comprehensive medical, dental, and vision insurance.

• Life and disability coverage.

• 401(k) retirement savings plan.

• Paid holidays, including a company-wide winter break (December 24 – January 1).

• Paid parental leave (available after one year of service).

• Mentorship and professional development programs.

• CPA exam assistance to help you succeed on your path to licensure.

• Firm-sponsored events and spontaneous team activities.

• Celebrations to mark milestones such as the conclusion of busy seasons and holidays.

People also viewed

ASG Technologies9 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike9 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International10 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape10 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity11 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist13 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers