Director of Information Security

Sorren, Inc.

$135K — $160K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of IT and security experience, with 3+ years in information security.
  • Hands-on background in security control planning and implementation.
  • Deep experience securing Microsoft 365 and Entra ID, plus managing endpoints with Intune.
  • Practical expertise in EDR, AV, vulnerability scanning, and incident response coordination.
  • Experience in managing and holding security vendors accountable for results.
  • Knowledge of compliance requirements in financial and professional services, including GLBA and FTC Safeguards.
  • Strong communication skills for cross-team collaboration.

Responsibilities

  • Develop and execute the information security program, aligning with business goals.
  • Define security standards for Microsoft 365 and oversee compliance with the infrastructure team.
  • Establish baselines for AV/EDR configurations and ensure scalable alerting.
  • Implement data protection controls, including classification, retention, and DLP.
  • Oversee email security standards and ensure compliance with firewall updates.
  • Maintain security policies and controls while improving audit processes.
  • Lead risk assessments, prioritize remediation, and maintain a risk register.

Benefits

  • Generous paid time off.
  • Comprehensive medical, dental, and vision coverage, plus life and disability insurance.
  • 401(k) retirement savings plan.
  • Paid holidays, including a year-end winter break.
  • Paid parental leave after one year of service.
  • Mentorship and career development programs.
  • CPA exam support to aid licensure success.
  • Firm-sponsored events and team activities.
Full Job Description

Position Summary:

Key Responsibilities:

•    Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
•    Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
•    Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
•    Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
•    Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
•    Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
•    Lead risk assessments[JD1.1], control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services.  This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure
•    Own risk register and tracking and run security and vendor risk assessments as the practice matures.
•    Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
•    Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
•    Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
•    Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation. 
•    Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
•    Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
•    Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
•    Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
•    Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
•    Take part in security due diligence on acquisition targets and document their security posture to inform integration.
•    Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.


Required Qualifications:

•    7+ years of progressive IT and security experience, including 3 or more years hands on in information security. 
•    Proven ability to plan security controls and implement them yourself.
•    Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune.
•    Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response.
•    A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable.
•    Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks.
•    Experience maintaining security policies and a risk register and turning them into implemented controls.
•    Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done.

Preferred Qualifications:

•    Experience in professional services, accounting, or another regulated, financial-data environment.
•    Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization.
•    Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them.
•    Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.

Compensation range for this role is $135,000 - $160,000.

Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location. Discretionary incentive compensation is based on firm, group, and individual performance.

What We Offer*:

  • Generous paid time off
  • Comprehensive medical, dental, and vision coverage, plus life and disability insurance
  • 401(k) retirement savings plan
  • Paid holidays, including a firmwide winter break (December 24 – January 1)
  • Paid parental leave (available after one year of service)
  • Mentorship and career development programs
  • CPA exam support to help you succeed on the path to licensure
  • Firm-sponsored events and spontaneous team activities
  • Celebrations to mark milestones like the end of busy season and the holidays

*Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.

Similar Jobs

More Jobs at Sorren, Inc.

More Information Technology Jobs

Find similar Director of Information Security jobs: