Director of Information Security
Sorren
Information Security Manager
Our Firm Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We don't just work with numbers—we work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services.
At Sorren, we believe that success is a shared journey. Our culture fosters collaboration, innovation, and professional growth, ensuring that every team member has the support and opportunities they need to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand.
We're committed to helping you grow, whether that means advancing your career, expanding your expertise, or achieving a fulfilling work-life balance. Because at Sorren, your success is our success.
Your Journey Our team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning their efforts with firm values, they establish a foundation for long-term success and growth. All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth, contributing to the firm's success through collaboration, exceptional service, and continuous growth.
Position Summary:
Key Responsibilities:
- Develop, maintain, and execute the firm's information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
- Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
- Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
- Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
- Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
- Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
- Lead risk assessments, control reviews, and security planning activities across the firm's infrastructure, applications, endpoints, and cloud services. This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure.
- Own risk register and tracking and run security and vendor risk assessments as the practice matures.
- Build and run the firm's GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
- Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
- Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
- Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation.
- Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
- Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
- Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
- Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
- Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
- Take part in security due diligence on acquisition targets and document their security posture to inform integration.
- Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.
Required Qualifications:
• 7+ years of progressive IT and security experience, including 3 or more years hands on in information security. • Proven ability to plan security controls and implement them yourself. • Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune. • Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response. • A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable. • Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks. • Experience maintaining security policies and a risk register and turning them into implemented controls. • Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done.
Preferred Qualifications:
• Experience in professional services, accounting, or another regulated, financial-data environment. • Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization. • Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them. • Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.
Why Choose Us?
At Sorren, we're invested in your growth—both personally and professionally. We'll support you as you advance in your career while also giving you the flexibility to enjoy life outside of work. We believe balance fuels success, and we've designed our culture and benefits to reflect that.
What We Offer*:
- Generous paid time off
- Comprehensive medical, dental, and vision coverage, plus life and disability insurance
- 401(k) retirement savings plan
- Paid holidays, including a firmwide winter break (December 24 – January 1)
- Paid parental leave (available after one year of service)
- Mentorship and career development programs
- CPA exam support to help you succeed on the path to licensure
- Firm-sponsored events and spontaneous team activities
- Celebrations to mark milestones like the end of busy season and the holidays
*Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.
$170.5k - $272.75k
...technology company delivering mission-critical solutions to government and commercial customers. We are seeking an experienced Director of Information Security to lead our cybersecurity program and ensure the protection of sensitive national security information.SummaryThe...SuggestedPermanent employmentFull timeContract workFor contractorsWork experience placementWork at officeRemote work- Job Requirements Phenom is looking for a Director of Security & Trust Enablement to build and scale the services that connect our Security... ...QualificationsBachelor’s degree or higher in Cybersecurity, Information Technology, or related field5+ years of experience in cybersecurity...Suggested
- Job Posting:JR101916 Director of Information Security (Open)Department:Information Technology, PMPosition Type:RegularOpen Date:06-30-2026Close Date:$140,000 - $150,000Job Description:The Director of Information Security position is responsible for developing and executing...SuggestedFull timeWork at office
$160k - $170k
Position Details Position Information About HofstraHofstra University is nationally ranked... ...CategoryAdministrationSchool/DivisionITS Information Security (division)DepartmentITS Information... ...Chief Information Officer (CIO), the Director of Information Security is a member of...SuggestedFull timeWork experience placement- Posting Details Announcement Information Job SummaryThe Center for Information Technology (CIT) invites qualified applicants for the position of Director of Information Security, a strategic leadership role responsible for advancing Oberlin College & Conservatory’s enterprise...SuggestedFull timeContract workWork at office
- New York, New YorkHybridFull Time$180k - $220kJob Title: Director of Information Security / CISOLocation: New York, NY (Hybrid)This established data management and secure communications firm provides critical information services to highly regulated industries. Operating...
- ...MMC in Harlan, IA seeks an Information Systems Director to oversee the IS department, security, and system implementations. The role partners with various departments to align technology with organizational needs and to ensure robust security and reliable operations. The...
- ...continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across...Work at office
- ...A clinical-stage biotech company in Chesterbrook is seeking a Director of IT to implement technology strategies and operations focused on compliance and innovation. This role requires extensive IT experience in a regulated environment and knowledge in cybersecurity and...
- ...Capital One is seeking an experienced Director, Assistant General Counsel for the Global Payment Network - Network Participant Risk. The role advises on legal risks in network participant relationships, including issuers, acquirers, and network alliances. The attorney...
- ...Seeking a hands-on and strategic Director of Information Security, this full-time remote position will lead and enhance the company's cybersecurity, data privacy, and compliance programs while collaborating with various departments to ensure secure business operations...Full timeRemote work
- ...Asana seeks a Manager of Offensive Security to lead its Offensive Security function in Warsaw. You will own and grow a team covering red team, application security, and vulnerability management, driving strategic direction and hands-on execution of the program. The role...Work at office
- ...ConocoPhillips is seeking a seasoned security leader to serve as Security Director within Global Security. This role provides enterprise leadership, governance, and oversight of security programs protecting personnel, facilities, operations, and reputation. As a member...
- ...The Trevor Project is seeking a Director, Trust, Safety & Policy Compliance to lead TrevorSpace safety operations and policy enforcement. This role requires ownership of incident response, risk management, and scalable governance in a high‑stakes online environment. You...
- ...education institution in Dalton, Georgia, is seeking a Director of Computing and Information Services. This role involves managing the college's IT... ...include managing budgets and serving as the Information Security Officer. Comprehensive benefits and a competitive salary...
- ...Staffmark Group in Moorpark, CA is seeking an IT Director to lead technology strategy, strengthen infrastructure and cybersecurity,... ...scalable business results. Candidates should have 7–10+ years in information technology, 3–5+ years in IT leadership, a bachelor’s in CS/IT...
$97k - $189k
...candidate possesses a Bachelor's degree in Computer Engineering or a related field and brings at least 10 years of IT experience with a focus on Information Security. This position offers a competitive salary, typically in the $97,000 to $189,000 range. #J-18808-Ljbffr...$126.8k - $339.66k
...ADP is hiring a Sr. Director Zero Trust & Data Security The Senior Director of Zero Trust & Data Security is responsible for defining and leading... ...Security Lead the data security strategy to ensure enterprise information is protected across its lifecycle. Data classification...Minimum wageTemporary workLocal areaRemote work- ...Ignyte Insurance is seeking a Head of Security to manage the full security program across its companies. This role involves overseeing... ...during acquisitions. Applicants must have 10+ years in information security, with significant leadership experience and expertise...Remote work
- ...Peraton is seeking a seasoned security executive to serve as Director of Information Assurance, the senior IA leader accountable for Peraton's ISSM program across classified computing environments. This role leads a distributed team of direct-report managers plus their...Work at office
- ...aero is seeking a Special Security Director to lead security programs safeguarding sensitive information and ensuring compliance with federal standards. This role requires over 8 years of security experience and managing team operations. Successful candidates will possess...Relocation package
$150k - $258.75k
...Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls... ...Description: DePuy Synthes is recruiting for a(n) Director, Incident Response & Threat; this Hybrid... ...Bachelor’s degree in Computer Science, Information Security, Engineering, or a related...Local areaImmediate start$137.4k - $206.2k
...Job Summary: The Director of Identity is responsible for maturing the enterprise Identity... ...operations, architecture, and emerging identity security capabilities. This role provides... ...Minimum Qualifications: Bachelor's degree in Information Technology, Information Security,...Hourly payMinimum wageFull timeLocal area$200k - $230k
...Overview The Director, Identity and Access Management (IAM) is responsible for defining... ...enable business strategy, scalability, security, and regulatory compliance. This role shifts... ...in Computer Science, Engineering, Information Systems, or equivalent experience. Experience...Temporary workShift work- ...About the Position The Director of Information Security’s responsibilities will include: Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent...Full timeRemote work
- ...Operations. The employee serves as GAO's senior security and emergency management expert. The... ...of personnel, industrial, physical, and information security and emergency management... ...this agency Duties Help As a Director of Security, MS-0080-II,your typical work...Full timePart timeWork experience placementWork at officeRelocation
- ...A prominent school district in Chicago is seeking an Executive Director of Information Security. The ideal candidate will establish and manage comprehensive information security programs to mitigate risks and ensure compliance. Responsibilities include leading security...Full time
- ...Amazon is seeking a transformational leader for its Threat Intelligence team in Herndon, VA. You will guide a global group of security engineers, PMs, and intel analysts to generate strategic insights, drive programs, and improve Amazon's security posture at scale across...
- ...Takeuchi Mfg (US) Ltd in Pendergrass, GA seeks a strategic Director of Information Technology to align technology with business goals, drive growth, and advance our digital/AI transformation. Lead IT operations, cybersecurity posture, cloud infrastructure, and major ERP...
$137.4k - $206.2k
Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture, engineering, and exposure management... ...:Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline;...Hourly payMinimum wageFull timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!
- director of corporate security United States
- chief security officer United States
- head of security United States
- director of security United States
- entry level information security analyst United States
- information technology security engineer United States
- information security analyst United States
- sr information security engineer United States
- senior director information security United States
- director information security United States


