Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Sorren

Director of Information Security

Sorren

Director of Information Security protecting Sorren’s accounting and advisory services through enterprise security programs. Managing Microsoft security controls, compliance, risk, incident response, and vendor partnerships remotely.

Posted 8/5/2026full-timeRemote • 🇺🇸 United StatesLeadWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in developing and executing information security programs, including risk assessments, compliance with regulations such as GLBA and HIPAA, and managing security tools and vendor relationships. Proficient in implementing security controls for Microsoft 365 and Entra ID, along with incident response coordination and security policy maintenance.

Highest-signal resume keywords
Information Security Program DevelopmentMicrosoft 365 Security ConfigurationRisk Assessment and ManagementCompliance with GLBA and HIPAAIncident Response Coordination

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecurityRisk AssessmentData Protection ControlsVulnerability ScanningIncident ResponseMicrosoft DefenderEmail SecurityEndpoint Management with IntuneSecurity Policy MaintenanceSecurity Awareness Training
Soft Skills
Strong CommunicationCollaboration Skills
Tools & Technologies
Microsoft 365Entra IDEDRAVFirewallDLPEmail FilteringManaged-Security VendorsPenetration Testing ToolsCyber Insurance Requirements
Certifications & Qualifications
CISSPCISMCISACRISCMicrosoft Security Certifications
Industry Keywords
GLBAFTC SafeguardsHIPAAPCI DSSCCPACPRAFinancial Services ComplianceProfessional ServicesRegulated Data EnvironmentCyber Threat Monitoring

About the role

Key responsibilities & impact
  • Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities.
  • Define Microsoft 365 and Entra ID security configuration and hardening standards and work with infrastructure to implement them.
  • Establish AV, EDR, email filtering, email security, firewall, and network-device security standards and compliance.
  • Define and implement data protection controls, including classification, retention, encryption, and DLP.
  • Maintain security policies, technical standards, controls, exceptions, and audit processes.
  • Lead risk assessments, control reviews, security planning, remediation tracking, and corrective-action closure.
  • Own the risk register and coordinate security and vendor risk assessments.
  • Build and run the GLBA and FTC Safeguards program and address applicable HIPAA, PCI DSS, CCPA, CPRA, and other requirements.
  • Support client security reviews, cyber insurance requirements, audits, and regulatory or contractual compliance efforts.
  • Conduct recurring system access reviews and collect audit evidence.
  • Maintain the incident response plan and coordinate incident response activities, external responders, communications, and documentation.
  • Facilitate incident response tabletop exercises and post-exercise improvements.
  • Coordinate vulnerability scans and penetration tests and track remediation.
  • Own the security awareness and phishing simulation program.
  • Evaluate and manage managed-security and security-tool vendors and recommend partnership changes.
  • Conduct security and risk assessments for software, services, and vendor relationships.
  • Participate in acquisition-target security due diligence and document security posture for integration.
  • Monitor evolving cyber threats, regulations, and leading practices and translate them into security improvements.

Requirements

What you’ll need
  • 7+ years of progressive IT and security experience, including 3 or more years hands-on in information security
  • Ability to plan security controls and implement them independently
  • Hands-on experience securing Microsoft 365 and Entra ID, including Conditional Access, MFA, Microsoft Defender, mail-flow, and email authentication
  • Experience managing endpoints with Intune
  • Practical experience with EDR, AV, vulnerability scanning, access reviews, and incident response coordination
  • Experience delivering results through managed-security and vendor partners, including evaluating, directing, and holding them accountable
  • Working knowledge of GLBA, FTC Safeguards, privacy requirements, and compliance frameworks for financial or professional services data
  • Experience maintaining security policies and a risk register and converting them into implemented controls
  • Strong communication and collaboration skills across Infrastructure, Support, and business teams
  • Experience in professional services, accounting, or another regulated financial-data environment preferred
  • Experience integrating or standardizing security across a multi-location or acquisitive organization preferred
  • Familiarity with hosted or virtual desktop platforms and related vendor management preferred
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials preferred

Benefits

Comp & perks
  • Generous paid time off
  • Comprehensive medical, dental, and vision coverage
  • Life and disability insurance
  • 401(k) retirement savings plan
  • Paid holidays, including a firmwide winter break (December 24 – January 1)
  • Paid parental leave (available after one year of service)
  • Mentorship and career development programs
  • CPA exam support to help you succeed on the path to licensure
  • Firm-sponsored events and spontaneous team activities
  • Celebrations to mark milestones like the end of busy season and the holidays