Responsibilities
- Develop a long-term security vision and implementation plan across multiple entities operating in a decentralized structure, prioritizing initiatives based on business risk and acquisition timelines.
- Create and enforce a unified set of security policies, standards, and minimum control requirements across all organizations, with adaptable exception and remediation processes for varying levels of maturity.
- Establish regular security performance reviews and executive reporting on key metrics including risk exposure, incident trends, compliance status, and program effectiveness.
- Collaborate with technology, data, and engineering leaders to integrate security into system design, operational procedures, and change management practices.
- Lead pre-acquisition security assessments, identify critical risks, estimate remediation efforts, and develop standardized post-merger integration plans for new entities.
- Manage the secure onboarding of acquired organizations by aligning identity, endpoint, email, monitoring, and data protection systems using repeatable integration frameworks.
- Provide strategic direction for secure cloud and hybrid architectures, with a focus on Azure, Intune, and Microsoft Defender, including privileged access, conditional access, and role-based controls.
- Oversee daily security operations including vulnerability management, patch prioritization, endpoint and email protection, tool lifecycle, and event analysis across all entities.
- Manage relationships with external MDR and SOC providers, ensuring defined scopes, SLAs, detection coverage, response playbooks, and continuous improvement in monitoring outcomes.
- Own the end-to-end incident response lifecycle, including response plans, simulation exercises, ransomware readiness, forensic coordination, and post-event improvement actions.
- Implement a standardized approach to risk assessment, control validation, and remediation tracking across organizations, including oversight of third-party and vendor security risk.
- Assist member organizations in meeting client-specific compliance requirements such as NIST CSF, CIS, and SOC 2 Type II, with reliable and repeatable evidence collection processes.
- Design and lead security awareness and training initiatives tailored to professional services environments, with measurable improvements in user behavior and adoption.
- Supervise, mentor, and grow a cybersecurity team while serving as the final escalation point for security decisions, incidents, and complex risk evaluations.
- Develop and maintain security documentation, operational playbooks, and implementation guides to ensure consistent control application and influence adoption across decentralized teams.
Benefits
- Comprehensive health, dental, and vision insurance with fully employer-paid options for employee-only health and dental coverage
- Employer-provided life insurance and long-term disability coverage
- Additional voluntary benefits including supplemental life and short-term disability insurance
- Safe Harbor 401(k) plan with employer contributions
Work Arrangement
Remote (Worldwide) — United States, Global
Other
Professional growth and development opportunities including access to Becker and LinkedIn Learning platforms