Security Lead

Cohen & Co.

$115K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of cybersecurity or related experience in risk and compliance management.
  • Familiar with frameworks like NIST, CIS, ISO 27001, and SOC 2.
  • Practical knowledge of Microsoft 365, Azure security, and identity access management.
  • CISSP, CISM, or similar security certifications are preferred.
  • Experience managing third-party security providers or services.
  • Ability to communicate effectively with both technical and executive audiences.

Responsibilities

  • Develop and maintain an information security roadmap aligned with business goals.
  • Create and operationalize security policies, standards, and procedures.
  • Lead cybersecurity risk assessments and maintain a risk register.
  • Oversee daily security operations including monitoring and incident response.
  • Coordinate security practices within teams involving cloud and DevOps.
  • Translate security risks into understandable terms for senior stakeholders.

Benefits

  • Collaborative work environment with multiple teams in cybersecurity.
  • Opportunities for training and certifications in security frameworks.
  • Exposure to diverse security challenges across platforms and environments.
  • Mentorship and development within a growing security team.
Full Job Description
What You'll Do

The Security Lead is responsible for shaping and operating the organization's information security program. This is a hands-on leadership role that combines security strategy, governance, risk management, compliance, incident response, and day-to-day execution with a team of security professionals. The role partners closely with, Infrastructure, DevOps, Risk, Legal, leadership, and external security partners to reduce cyber risk while enabling the business.

Responsibilities

Security Strategy & Governance
  • Develop and maintain a practical information security roadmap aligned with business priorities, client expectations, and organizational risk tolerance.
  • Create, maintain, and operationalize security policies, standards, procedures, and control documentation.
  • Use recognized frameworks such as NIST Cybersecurity Framework, CIS Controls, ISO 27001 concepts, and SOC 2 control expectations where appropriate.
  • Define security program metrics, risk indicators, and reporting materials for executive leadership.


Risk Management & Compliance
  • Lead recurring cybersecurity risk assessments and maintain a prioritized risk register with remediation plans.
  • Support client security questionnaires, vendor due diligence, cyber insurance requests, and audit evidence collection.
  • Partner with business and technology owners to evaluate risk for new systems, vendors, integrations, and technology changes.
  • Coordinate remediation of audit findings, assessment results, and control gaps.


Security Operations & Incident Response
  • Oversee day-to-day security operations, including monitoring, alert review, vulnerability management, endpoint protection, identity controls, and threat response.
  • Own and maintain the incident response plan, escalation process, communication templates, and post-incident review process.
  • Coordinate with internal teams and third-party providers such as MSSP, SOC, penetration testing firms, cyber insurance contacts, and outside counsel when needed.
  • Lead or support tabletop exercises, phishing response, vulnerability remediation, and security improvement initiatives.


Architecture, Cloud & DevSecOps Enablement
  • Partner with Infrastructure, DevOps, application, and business technology teams to embed security into architecture, implementation, and change management.
  • Advise on secure configuration for Microsoft 365, Azure, identity and access management, network security, endpoint security, cloud workloads, and SaaS platforms.
  • Promote secure development, secure deployment, secrets management, least privilege access, logging, and configuration baselines.
  • Evaluate security tools and processes for fit, cost, redundancy, and measurable risk reduction.


Leadership, Communication & Security Culture
  • Translate technical security risks into business language for senior leadership and stakeholders.
  • Provide clear recommendations on security priorities, investment needs, and risk tradeoffs.
  • Lead security awareness, phishing education, onboarding security training, and ongoing employee communications.
  • Mentor technical team members and coordinate work across internal staff, contractors, and managed security providers.
  • undefined


Who You Are

Qualifications
  • Working knowledge of risk and control frameworks such as NIST CSF, CIS Controls, ISO 27001, SOC 2, or similar standards.
  • Practical experience with Microsoft 365, Azure or cloud security concepts, identity and access management, endpoint protection, vulnerability management, and incident response.
  • Ability to communicate security risks and recommendations clearly to both executive and technical audiences.
  • Demonstrated ability to balance security requirements with business practicality in a professional services environment is preferred.
  • CISSP, CISM, CRISC, Security+, Azure security, or other relevant security certifications.
  • Experience supporting SOC 2, cyber insurance, client security reviews, regulatory inquiries, or external security assessments.
  • Experience managing third-party security providers, MSSPs, SOC services, penetration testing firms, or security consultants.
  • Experience building or formalizing a security program in a small or mid-size organization.
  • Familiarity with data privacy, third-party risk management, AI governance, secure software delivery, or professional services compliance expectations.


Education and Experience
  • 4-8 years of progressive experience in cybersecurity, IT risk, infrastructure security, security operations, or a closely related technology function.
  • 2+ years of experience leading security initiatives, coordinating cross-functional work, or managing security operations, compliance, or risk activities.


Work Environment
  • The work environment is a business office environment. There may be occasions travel to trainings, conferences, or client sites as required. Client offices and other facilities which may present a variety of work environments beyond a traditional business office environment and is characteristic of the conditions an employee encounters while performing the essential functions of this job. Evening and weekend coverage needed during peak seasons. On-call shifts and after-hours support as needed.


Physical Demands
  • The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Physical demands may include talking, hearing, sitting for extended periods, standing, walking, repetitive motion using a keyboard and telephone, and lifting and carrying supplies and equipment. The visual acuity requirements include viewing a computer monitor and extensive reading.

Similar Jobs

More Jobs at Cohen & Co.

  • Security Lead
    $115K — $130K *
    Cleveland, OH 44130 (Cuyahoga County)
    Information Technology
    In-Person
  • Security Lead
    $115K — $130K *
    Youngstown, OH 44512 (Mahoning County)
    Information Technology
    In-Person
  • Security Lead
    $115K — $130K *
    Akron, OH 44312 (Summit County)
    Information Technology
    In-Person
  • Tax Senior Accountant, Private Funds
    $70K — $125K *
    Philadelphia, PA 19120 (Philadelphia County)
    Legal & Accounting
    In-Person
  • Tax Senior Accountant, Private Funds
    $70K — $125K *
    St. Clair Shores, MI 48080 (Macomb County)
    Legal & Accounting
    In-Person

More Information Technology Jobs

Find similar Security Lead jobs: