Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director of Information Security

$135k - $160k

Sorren, Inc.

Our Firm
Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We don’t just work with numbers—we work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services. 

At Sorren, we believe that success is a shared journey. Our culture fosters collaboration, innovation, and professional growth, ensuring that every team member has the support and opportunities they need to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand. 

We’re committed to helping you grow, whether that means advancing your career, expanding your expertise, or achieving a fulfilling work-life balance. Because at Sorren, your success is our success. 

Your Journey
Our team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning their efforts with firm values, they establish a foundation for long-term success and growth. All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth, contributing to the firm’s success through collaboration, exceptional service, and continuous growth.

Position Summary:

Key Responsibilities:

• Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
• Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
• Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
• Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
• Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
• Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
• Lead risk assessments[JD1.1], control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services. This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure
• Own risk register and tracking and run security and vendor risk assessments as the practice matures.
• Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
• Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
• Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
• Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation. 
• Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
• Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
• Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
• Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
• Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
• Take part in security due diligence on acquisition targets and document their security posture to inform integration.
• Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.


Required Qualifications:

• 7+ years of progressive IT and security experience, including 3 or more years hands on in information security. 
• Proven ability to plan security controls and implement them yourself.
• Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune.
• Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response.
• A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable.
• Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks.
• Experience maintaining security policies and a risk register and turning them into implemented controls.
• Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done.

Preferred Qualifications:

• Experience in professional services, accounting, or another regulated, financial-data environment.
• Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization.
• Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them.
• Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.

Compensation range for this role is $135,000 - $160,000.

Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location. Discretionary incentive compensation is based on firm, group, and individual performance.

Why Choose Us? 

At Sorren, we’re invested in your growth—both personally and professionally. We’ll support you as you advance in your career while also giving you the flexibility to enjoy life outside of work. We believe balance fuels success, and we’ve designed our culture and benefits to reflect that.

What We Offer*:

  • Generous paid time off
  • Comprehensive medical, dental, and vision coverage, plus life and disability insurance
  • 401(k) retirement savings plan
  • Paid holidays, including a firmwide winter break (December 24 – January 1)
  • Paid parental leave (available after one year of service)
  • Mentorship and career development programs
  • CPA exam support to help you succeed on the path to licensure
  • Firm-sponsored events and spontaneous team activities
  • Celebrations to mark milestones like the end of busy season and the holidays

*Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.

© 2025 “Sorren” is the brand name under which Sorren CPAs, P.C. and Sorren, Inc. and its subsidiary entities provide professional services. Sorren CPAs P.C. and Sorren, Inc. and its subsidiary entities practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations, and professional standards. Sorren CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients, and Sorren, Inc. and its subsidiary entities provide tax and business consulting services to their clients. Sorren, Inc. and its subsidiary entities are not licensed CPA firms.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Director of Information Security in United States vacancy
  • Job Posting:JR101916 Director of Information Security (Open)Department:Information Technology, PMPosition Type:RegularOpen Date:06-30-2026Close Date:$140,000 - $150,000Job Description:The Director of Information Security position is responsible for developing and executing... 
    Suggested
    Full time
    Work at office

    Bowie State University

    Bowie, MD
    1 day ago
  • $160k - $170k

    Position Details Position Information About HofstraHofstra University is nationally ranked...  ...CategoryAdministrationSchool/DivisionITS Information Security (division)DepartmentITS Information...  ...Chief Information Officer (CIO), the Director of Information Security is a member of... 
    Suggested
    Full time
    Work experience placement

    Hofstra University

    Hempstead, NY
    3 days ago
  • Posting Details Announcement Information Job SummaryThe Center for Information Technology (CIT) invites qualified applicants for the position of Director of Information Security, a strategic leadership role responsible for advancing Oberlin College & Conservatory’s enterprise... 
    Suggested
    Full time
    Contract work
    Work at office

    Oberlin College and Conservatory

    Oberlin, OH
    3 days ago
  •  ...Director of Information Security Company: Akamai Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: FedRAMP, NIST RMF, NIST SP 800-53, Vulnerability management, Encryption, Security monitoring, Cloud security Requirements: 12+ years... 
    Suggested
    Full time
    Remote work

    Akamai

    United States
    1 day ago
  •  ...RTX Corporation is seeking a Director of Product Cyber Supply Chain Risk Management to lead cyber supply chain risk strategy across product...  ..., Supply Chain, Quality, and Enterprise Services to embed secure-by-design practices and assurance artifacts throughout development... 
    Suggested
    Remote work

    Prattwhitney

    United States
    2 days ago
  •  ...Summary: Leads the company's cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access... 
    Contract work
    Live in
    Flexible hours
    Night shift

    Drury Hotels Company, LLC

    Saint Louis, MO
    3 days ago
  •  ...A fast-growing software organization in the self-funded medical benefits ecosystem is seeking a Director of Information Security to own the security program end to end. This leader will set strategy, build governance, oversee tooling, manage certifications, and represent... 
    Contract work
    Work at office

    Humans Doing

    Smyrna, GA
    1 day ago
  •  ...About 7AI 7AI is the foundational AI security company. Founded in 2024 by Cybereason co-founders Lior Div and Yonatan Striem-Amit...  ...us to defend them. Overview You'll take ownership of information security and information systems, building the programs, policies... 

    SevenAI

    Boston, MA
    2 days ago
  •  ...Position Summary The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the... 
    Full time
    For contractors
    Remote work

    Fetch

    United States
    4 days ago
  • $105k - $130k

     ...Director of Information Security Bookmark this Posting Print Preview | Apply for this Job Position Details Position Information Position Title Director of Information Security Department Information Services - Office of VP -Group Pay Type Exempt Appointment... 
    Full time
    H1b
    Work at office
    Remote work
    Relocation
    Work visa

    Connecticut College

    New London, CT
    5 days ago
  •  ...To support a growing cybersecurity initiative, the full-time Senior Director of Information Security will manage the development and execution of a scalable security program for a diverse portfolio of SaaS products, collaborating closely with multiple business units to... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    5 days ago
  •  ...Leading the development of a comprehensive information security and compliance strategy, the full-time remote Senior Director of Information Security and Compliance will oversee the maturity of the security program, manage key teams, and serve as the executive voice during... 
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    4 days ago
  •  ...Capital One is seeking an experienced Director, Assistant General Counsel for the Global Payment Network - Network Participant Risk. The role advises on legal risks in network participant relationships, including issuers, acquirers, and network alliances. The attorney... 

    Capital One National Association

    Eastern, KY
    3 days ago
  • $212.4k

     ...world. The opportunity The Global Lead Security Compliance & Enforcement owns the strategy...  ...defensible, audit-ready governance. The Director creates clear global accountability for...  ...Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners... 
    Summer holiday
    Local area
    Flexible hours

    EY

    Atlanta, GA
    1 day ago
  •  ...UnitedHealth Group seeks a Senior Director, Data Security to lead enterprise data security across cloud, on-prem, and SaaS. You will mature DSPM, data discovery, tagging, access governance, and data lifecycle controls while coordinating with privacy, legal, and platform... 
    Work at office
    Local area
    Remote work

    UnitedHealth-Grou

    United States
    4 days ago
  •  ...Cencora, a leader in healthcare logistics, seeks a Senior Director, Secure MA&D to own enterprise cybersecurity strategy across pre-close due diligence, Day 1 readiness, and post-close integration. You will guide governance, risk, and program ownership for acquisitions... 

    Cencora

    Indianapolis, IN
    3 days ago
  •  ...Charles Schwab is seeking a Director-level Product leader for Client Authentication Core Capabilities to drive a scalable, secure identity experience across digital, phone, branch, and third-party channels. You will guide a team of product managers and owners focused on... 

    Charles Schwab

    El Paso, TX
    3 days ago
  •  ...Director Of Cyber Risk ManagementITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required...  ...service at any time.Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO)... 
    Work at office
    Shift work

    StateJobsNY

    New York, NY
    3 days ago
  • $154.4k - $261.25k

     ...US-Nationwide-FIELD Full time 20187025 What Information Security and Risk contributes to Cardinal Health Information Technology oversees...  ...and completes risk assessments. Job Summary The Director, Security Architecture is responsible for establishing, leading... 
    Full time
    Temporary work
    Local area
    Immediate start
    Flexible hours

    Cardinal Health

    Honolulu, HI
    2 days ago
  •  ...EY is seeking a Global Lead Security Compliance & Enforcement Director to shape the global security compliance program within Technology Assurance. You will own strategy, operating model, and enforcement, coordinating across CTOs, risk, audit, and technology teams to... 

    EY

    Dallas, TX
    1 day ago
  •  ...Schwab is seeking a Director-level leader for Client Authentication, responsible for core authentication capabilities that secure client access across digital and phone channels. You will guide a team of product managers and owners, shaping strategy and execution in a... 

    Charles Schwab

    Austin, TX
    21 hours ago
  •  ...Executive Director Of Security & Information ProtectionOdyssey is seeking an Executive Director of Security & Information Protection to lead the recently formed Security & Information Protection group. This role carries enterprise-level responsibility for both strategic... 
    Contract work
    For contractors
    Work experience placement
    Remote work

    Odyssey Systems

    Wakefield, MA
    4 days ago
  •  ...organizational objectives, regulatory requirements, and industry best practices. This leader drives a risk- informed culture and enables the business to innovate securely while maintaining compliance and operational resilience. Roles & Responsibilities... 

    Intuitive

    Sunnyvale, CA
    5 days ago
  • $152.7k - $294k

     ...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The Global Information Security Strategist is a senior role responsible for shaping and implementing the long‑term information security strategy of the firm... 
    Summer holiday
    Flexible hours
    Shift work

    EY

    Boston, MA
    3 days ago
  • $141.6k - $283.25k

     ...and animals everywhere. Job Details Summary The Senior Director of Enterprise Security Architecture (ESA) leads the definition, governance, and...  ...technology teams, other corporate support functions, and other Information Security organizations to protect the corporate brand,... 
    Full time
    Work experience placement
    Work at office
    Local area

    Cencora

    Wausau, WI
    4 days ago
  •  ...Global Lending Services LLC is seeking a Senior Director, IT Security to lead the design, implementation, and oversight of the company’s information security program. This on-site role partners with executives to identify, assess, and mitigate information security risks... 

    Global Lending Services LLC

    Anderson, SC
    3 days ago
  •  ...continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across... 
    Work at office

    MX

    Lehi, UT
    3 days ago
  •  ...E-logic, Inc. seeks an experienced Security Director to design, implement, and govern the cybersecurity program (GRC) for the State of Texas DIR STS SecOps contract. The role ensures compliance with NIST, PCI-DSS, IRS 1075, CJIS, and HIPAA while guiding enterprise security... 
    Contract work

    eLogic

    Austin, TX
    3 days ago
  •  ...enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems,...  ...initiatives. Collaborates with enterprise architecture, information security, infrastructure, and application development teams to... 
    Full time
    Contract work
    Local area
    Worldwide

    MicroTechnologies

    Brooklyn, NY
    1 day ago
  •  ...Coupang seeks a Director on the Tech Infrastructure Security team to own the IAM platform and scale security services across thousands of microservices. You will hire and retain top engineers, shape team culture, and drive strategic investments. You will collaborate... 

    OpenTalent

    Seattle, WA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!