See all jobs on JobTailor
Search thousands of fresh jobs every day.
- Fresh listings
- Fast filters
- No subscription required

Director of Information Security
SorrenDirector of Information Security protecting Sorren’s accounting and advisory services through enterprise security programs. Managing Microsoft security controls, compliance, risk, incident response, and vendor partnerships remotely.
Core Competencies
Role fitUse this summary to align your resume positioning with the role.
Demonstrates extensive experience in developing and executing information security programs, including risk assessments, compliance with regulations such as GLBA and HIPAA, and managing security tools and vendor relationships. Proficient in implementing security controls for Microsoft 365 and Entra ID, along with incident response coordination and security policy maintenance.
ATS Keywords
Tailor your resumeTip: use these terms in your resume and cover letter to boost ATS matches.
About the role
Key responsibilities & impact- Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities.
- Define Microsoft 365 and Entra ID security configuration and hardening standards and work with infrastructure to implement them.
- Establish AV, EDR, email filtering, email security, firewall, and network-device security standards and compliance.
- Define and implement data protection controls, including classification, retention, encryption, and DLP.
- Maintain security policies, technical standards, controls, exceptions, and audit processes.
- Lead risk assessments, control reviews, security planning, remediation tracking, and corrective-action closure.
- Own the risk register and coordinate security and vendor risk assessments.
- Build and run the GLBA and FTC Safeguards program and address applicable HIPAA, PCI DSS, CCPA, CPRA, and other requirements.
- Support client security reviews, cyber insurance requirements, audits, and regulatory or contractual compliance efforts.
- Conduct recurring system access reviews and collect audit evidence.
- Maintain the incident response plan and coordinate incident response activities, external responders, communications, and documentation.
- Facilitate incident response tabletop exercises and post-exercise improvements.
- Coordinate vulnerability scans and penetration tests and track remediation.
- Own the security awareness and phishing simulation program.
- Evaluate and manage managed-security and security-tool vendors and recommend partnership changes.
- Conduct security and risk assessments for software, services, and vendor relationships.
- Participate in acquisition-target security due diligence and document security posture for integration.
- Monitor evolving cyber threats, regulations, and leading practices and translate them into security improvements.
Requirements
What you’ll need- 7+ years of progressive IT and security experience, including 3 or more years hands-on in information security
- Ability to plan security controls and implement them independently
- Hands-on experience securing Microsoft 365 and Entra ID, including Conditional Access, MFA, Microsoft Defender, mail-flow, and email authentication
- Experience managing endpoints with Intune
- Practical experience with EDR, AV, vulnerability scanning, access reviews, and incident response coordination
- Experience delivering results through managed-security and vendor partners, including evaluating, directing, and holding them accountable
- Working knowledge of GLBA, FTC Safeguards, privacy requirements, and compliance frameworks for financial or professional services data
- Experience maintaining security policies and a risk register and converting them into implemented controls
- Strong communication and collaboration skills across Infrastructure, Support, and business teams
- Experience in professional services, accounting, or another regulated financial-data environment preferred
- Experience integrating or standardizing security across a multi-location or acquisitive organization preferred
- Familiarity with hosted or virtual desktop platforms and related vendor management preferred
- Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials preferred
Benefits
Comp & perks- Generous paid time off
- Comprehensive medical, dental, and vision coverage
- Life and disability insurance
- 401(k) retirement savings plan
- Paid holidays, including a firmwide winter break (December 24 – January 1)
- Paid parental leave (available after one year of service)
- Mentorship and career development programs
- CPA exam support to help you succeed on the path to licensure
- Firm-sponsored events and spontaneous team activities
- Celebrations to mark milestones like the end of busy season and the holidays