Security Lead

Cohen & Co.

$115K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years of cybersecurity or IT risk management experience in a professional services context.
  • Practical knowledge of risk and compliance frameworks like NIST CSF and SOC 2.
  • Experienced in Microsoft 365, Azure security concepts, and incident response processes.
  • Ability to communicate security risks to both technical and executive audiences effectively.
  • Relevant security certifications such as CISSP, CISM, or Azure security certifications.

Responsibilities

  • Develop and execute an information security strategy aligned with business goals and risk tolerance.
  • Conduct continuous cybersecurity risk assessments and maintain a detailed risk register.
  • Manage daily security operations including monitoring, vulnerability management, and incident response.
  • Coordinate security measures across multiple teams including Infrastructure and DevOps.
  • Communicate technical risks and security recommendations to senior leadership and stakeholders.

Benefits

  • Opportunity to shape and influence the organization's information security program.
  • Hands-on leadership role working with various teams and external partners.
  • Support for professional development through ongoing trainings and certifications.
  • Flexible work environment with potential for remote work and travel options.
Full Job Description
What You'll Do

The Security Lead is responsible for shaping and operating the organization's information security program. This is a hands-on leadership role that combines security strategy, governance, risk management, compliance, incident response, and day-to-day execution with a team of security professionals. The role partners closely with, Infrastructure, DevOps, Risk, Legal, leadership, and external security partners to reduce cyber risk while enabling the business.

Responsibilities

Security Strategy & Governance
  • Develop and maintain a practical information security roadmap aligned with business priorities, client expectations, and organizational risk tolerance.
  • Create, maintain, and operationalize security policies, standards, procedures, and control documentation.
  • Use recognized frameworks such as NIST Cybersecurity Framework, CIS Controls, ISO 27001 concepts, and SOC 2 control expectations where appropriate.
  • Define security program metrics, risk indicators, and reporting materials for executive leadership.


Risk Management & Compliance
  • Lead recurring cybersecurity risk assessments and maintain a prioritized risk register with remediation plans.
  • Support client security questionnaires, vendor due diligence, cyber insurance requests, and audit evidence collection.
  • Partner with business and technology owners to evaluate risk for new systems, vendors, integrations, and technology changes.
  • Coordinate remediation of audit findings, assessment results, and control gaps.


Security Operations & Incident Response
  • Oversee day-to-day security operations, including monitoring, alert review, vulnerability management, endpoint protection, identity controls, and threat response.
  • Own and maintain the incident response plan, escalation process, communication templates, and post-incident review process.
  • Coordinate with internal teams and third-party providers such as MSSP, SOC, penetration testing firms, cyber insurance contacts, and outside counsel when needed.
  • Lead or support tabletop exercises, phishing response, vulnerability remediation, and security improvement initiatives.


Architecture, Cloud & DevSecOps Enablement
  • Partner with Infrastructure, DevOps, application, and business technology teams to embed security into architecture, implementation, and change management.
  • Advise on secure configuration for Microsoft 365, Azure, identity and access management, network security, endpoint security, cloud workloads, and SaaS platforms.
  • Promote secure development, secure deployment, secrets management, least privilege access, logging, and configuration baselines.
  • Evaluate security tools and processes for fit, cost, redundancy, and measurable risk reduction.


Leadership, Communication & Security Culture
  • Translate technical security risks into business language for senior leadership and stakeholders.
  • Provide clear recommendations on security priorities, investment needs, and risk tradeoffs.
  • Lead security awareness, phishing education, onboarding security training, and ongoing employee communications.
  • Mentor technical team members and coordinate work across internal staff, contractors, and managed security providers.
  • undefined


Who You Are

Qualifications
  • Working knowledge of risk and control frameworks such as NIST CSF, CIS Controls, ISO 27001, SOC 2, or similar standards.
  • Practical experience with Microsoft 365, Azure or cloud security concepts, identity and access management, endpoint protection, vulnerability management, and incident response.
  • Ability to communicate security risks and recommendations clearly to both executive and technical audiences.
  • Demonstrated ability to balance security requirements with business practicality in a professional services environment is preferred.
  • CISSP, CISM, CRISC, Security+, Azure security, or other relevant security certifications.
  • Experience supporting SOC 2, cyber insurance, client security reviews, regulatory inquiries, or external security assessments.
  • Experience managing third-party security providers, MSSPs, SOC services, penetration testing firms, or security consultants.
  • Experience building or formalizing a security program in a small or mid-size organization.
  • Familiarity with data privacy, third-party risk management, AI governance, secure software delivery, or professional services compliance expectations.


Education and Experience
  • 4-8 years of progressive experience in cybersecurity, IT risk, infrastructure security, security operations, or a closely related technology function.
  • 2+ years of experience leading security initiatives, coordinating cross-functional work, or managing security operations, compliance, or risk activities.


Work Environment
  • The work environment is a business office environment. There may be occasions travel to trainings, conferences, or client sites as required. Client offices and other facilities which may present a variety of work environments beyond a traditional business office environment and is characteristic of the conditions an employee encounters while performing the essential functions of this job. Evening and weekend coverage needed during peak seasons. On-call shifts and after-hours support as needed.


Physical Demands
  • The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Physical demands may include talking, hearing, sitting for extended periods, standing, walking, repetitive motion using a keyboard and telephone, and lifting and carrying supplies and equipment. The visual acuity requirements include viewing a computer monitor and extensive reading.

Similar Jobs

More Jobs at Cohen & Co.

More Information Technology Jobs

Find similar Security Lead jobs: