Director of Information Security
$135k - $160kSorren, Inc.
Our Firm
Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We don’t just work with numbers—we work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services.
At Sorren, we believe that success is a shared journey. Our culture fosters collaboration, innovation, and professional growth, ensuring that every team member has the support and opportunities they need to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand.
We’re committed to helping you grow, whether that means advancing your career, expanding your expertise, or achieving a fulfilling work-life balance. Because at Sorren, your success is our success.
Your Journey
Our team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning their efforts with firm values, they establish a foundation for long-term success and growth. All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth, contributing to the firm’s success through collaboration, exceptional service, and continuous growth.
Position Summary:
Key Responsibilities:
• Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
• Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
• Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
• Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
• Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
• Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
• Lead risk assessments[JD1.1], control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services. This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure
• Own risk register and tracking and run security and vendor risk assessments as the practice matures.
• Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
• Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
• Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
• Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation.
• Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
• Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
• Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
• Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
• Conduct security and risk assessments of proposed software, services, and vendor relationships as part of the software request and approval process.
• Take part in security due diligence on acquisition targets and document their security posture to inform integration.
• Maintain awareness of evolving cyber threats, regulatory developments, and leading practices relevant to professional services and accounting firms, and translate them into practical improvements.
Required Qualifications:
• 7+ years of progressive IT and security experience, including 3 or more years hands on in information security.
• Proven ability to plan security controls and implement them yourself.
• Deep hands-on experience securing Microsoft 365 and Entra ID (Conditional Access, MFA, Microsoft Defender, mail-flow and email authentication) and managing endpoints with Intune.
• Practical experience with EDR and AV, vulnerability scanning, access reviews, and coordinating incident response.
• A track record of delivering results through managed-security and vendor partners, including evaluating them, directing their work, and holding them accountable.
• Working knowledge of regulatory and compliance requirements for financial or professional services data, including GLBA and FTC Safeguards and general privacy and compliance frameworks.
• Experience maintaining security policies and a risk register and turning them into implemented controls.
• Strong communication and collaboration skills, with the ability to coordinate across the Infrastructure, Support, and business teams to get changes done.
Preferred Qualifications:
• Experience in professional services, accounting, or another regulated, financial-data environment.
• Experience integrating or standardizing security across a multi-location or acquisitive (M&A) organization.
• Familiarity with hosted or virtual desktop platforms and the vendor management that goes with them.
• Relevant certifications such as CISSP, CISM, CISA, CRISC, Microsoft security certifications, or similar credentials.
Compensation range for this role is $135,000 - $160,000.
Actual compensation is influenced by a variety of factors including but not limited to skills, experience, qualifications, and geographic location. Discretionary incentive compensation is based on firm, group, and individual performance.
Why Choose Us?
At Sorren, we’re invested in your growth—both personally and professionally. We’ll support you as you advance in your career while also giving you the flexibility to enjoy life outside of work. We believe balance fuels success, and we’ve designed our culture and benefits to reflect that.
What We Offer*:
- Generous paid time off
- Comprehensive medical, dental, and vision coverage, plus life and disability insurance
- 401(k) retirement savings plan
- Paid holidays, including a firmwide winter break (December 24 – January 1)
- Paid parental leave (available after one year of service)
- Mentorship and career development programs
- CPA exam support to help you succeed on the path to licensure
- Firm-sponsored events and spontaneous team activities
- Celebrations to mark milestones like the end of busy season and the holidays
*Benefits are available to full-time employees regularly scheduled to work at least 30 hours per week.
© 2025 “Sorren” is the brand name under which Sorren CPAs, P.C. and Sorren, Inc. and its subsidiary entities provide professional services. Sorren CPAs P.C. and Sorren, Inc. and its subsidiary entities practice as an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable laws, regulations, and professional standards. Sorren CPAs P.C. is a licensed independent CPA firm that provides attest services to its clients, and Sorren, Inc. and its subsidiary entities provide tax and business consulting services to their clients. Sorren, Inc. and its subsidiary entities are not licensed CPA firms.
- Job Posting:JR101916 Director of Information Security (Open)Department:Information Technology, PMPosition Type:RegularOpen Date:06-30-2026Close Date:$140,000 - $150,000Job Description:The Director of Information Security position is responsible for developing and executing...SuggestedFull timeWork at office
$160k - $170k
Position Details Position Information About HofstraHofstra University is nationally ranked... ...CategoryAdministrationSchool/DivisionITS Information Security (division)DepartmentITS Information... ...Chief Information Officer (CIO), the Director of Information Security is a member of...SuggestedFull timeWork experience placement- Posting Details Announcement Information Job SummaryThe Center for Information Technology (CIT) invites qualified applicants for the position of Director of Information Security, a strategic leadership role responsible for advancing Oberlin College & Conservatory’s enterprise...SuggestedFull timeContract workWork at office
- ...Director of Information Security Company: Akamai Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: FedRAMP, NIST RMF, NIST SP 800-53, Vulnerability management, Encryption, Security monitoring, Cloud security Requirements: 12+ years...SuggestedFull timeRemote work
- ...RTX Corporation is seeking a Director of Product Cyber Supply Chain Risk Management to lead cyber supply chain risk strategy across product... ..., Supply Chain, Quality, and Enterprise Services to embed secure-by-design practices and assurance artifacts throughout development...SuggestedRemote work
- ...Summary: Leads the company's cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access...Contract workLive inFlexible hoursNight shift
- ...A fast-growing software organization in the self-funded medical benefits ecosystem is seeking a Director of Information Security to own the security program end to end. This leader will set strategy, build governance, oversee tooling, manage certifications, and represent...Contract workWork at office
- ...About 7AI 7AI is the foundational AI security company. Founded in 2024 by Cybereason co-founders Lior Div and Yonatan Striem-Amit... ...us to defend them. Overview You'll take ownership of information security and information systems, building the programs, policies...
- ...Position Summary The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the...Full timeFor contractorsRemote work
$105k - $130k
...Director of Information Security Bookmark this Posting Print Preview | Apply for this Job Position Details Position Information Position Title Director of Information Security Department Information Services - Office of VP -Group Pay Type Exempt Appointment...Full timeH1bWork at officeRemote workRelocationWork visa- ...To support a growing cybersecurity initiative, the full-time Senior Director of Information Security will manage the development and execution of a scalable security program for a diverse portfolio of SaaS products, collaborating closely with multiple business units to...Full timeRemote work
- ...Leading the development of a comprehensive information security and compliance strategy, the full-time remote Senior Director of Information Security and Compliance will oversee the maturity of the security program, manage key teams, and serve as the executive voice during...Full timeRemote work
- ...Capital One is seeking an experienced Director, Assistant General Counsel for the Global Payment Network - Network Participant Risk. The role advises on legal risks in network participant relationships, including issuers, acquirers, and network alliances. The attorney...
$212.4k
...world. The opportunity The Global Lead Security Compliance & Enforcement owns the strategy... ...defensible, audit-ready governance. The Director creates clear global accountability for... ...Leaders, Technology Risk & Compliance, Information Security leadership, risk and control owners...Summer holidayLocal areaFlexible hours- ...UnitedHealth Group seeks a Senior Director, Data Security to lead enterprise data security across cloud, on-prem, and SaaS. You will mature DSPM, data discovery, tagging, access governance, and data lifecycle controls while coordinating with privacy, legal, and platform...Work at officeLocal areaRemote work
- ...Cencora, a leader in healthcare logistics, seeks a Senior Director, Secure MA&D to own enterprise cybersecurity strategy across pre-close due diligence, Day 1 readiness, and post-close integration. You will guide governance, risk, and program ownership for acquisitions...
- ...Charles Schwab is seeking a Director-level Product leader for Client Authentication Core Capabilities to drive a scalable, secure identity experience across digital, phone, branch, and third-party channels. You will guide a team of product managers and owners focused on...
- ...Director Of Cyber Risk ManagementITS provides operational support to state agencies on a 24x7x365 basis; some positions may be required... ...service at any time.Under the direction of a Deputy Chief Information Security Officer within the Chief Information Security Office (CISO)...Work at officeShift work
$154.4k - $261.25k
...US-Nationwide-FIELD Full time 20187025 What Information Security and Risk contributes to Cardinal Health Information Technology oversees... ...and completes risk assessments. Job Summary The Director, Security Architecture is responsible for establishing, leading...Full timeTemporary workLocal areaImmediate startFlexible hours- ...EY is seeking a Global Lead Security Compliance & Enforcement Director to shape the global security compliance program within Technology Assurance. You will own strategy, operating model, and enforcement, coordinating across CTOs, risk, audit, and technology teams to...
- ...Schwab is seeking a Director-level leader for Client Authentication, responsible for core authentication capabilities that secure client access across digital and phone channels. You will guide a team of product managers and owners, shaping strategy and execution in a...
- ...Executive Director Of Security & Information ProtectionOdyssey is seeking an Executive Director of Security & Information Protection to lead the recently formed Security & Information Protection group. This role carries enterprise-level responsibility for both strategic...Contract workFor contractorsWork experience placementRemote work
- ...organizational objectives, regulatory requirements, and industry best practices. This leader drives a risk- informed culture and enables the business to innovate securely while maintaining compliance and operational resilience. Roles & Responsibilities...
$152.7k - $294k
...diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world. The Global Information Security Strategist is a senior role responsible for shaping and implementing the long‑term information security strategy of the firm...Summer holidayFlexible hoursShift work$141.6k - $283.25k
...and animals everywhere. Job Details Summary The Senior Director of Enterprise Security Architecture (ESA) leads the definition, governance, and... ...technology teams, other corporate support functions, and other Information Security organizations to protect the corporate brand,...Full timeWork experience placementWork at officeLocal area- ...Global Lending Services LLC is seeking a Senior Director, IT Security to lead the design, implementation, and oversight of the company’s information security program. This on-site role partners with executives to identify, assess, and mitigate information security risks...
- ...continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across...Work at office
- ...E-logic, Inc. seeks an experienced Security Director to design, implement, and govern the cybersecurity program (GRC) for the State of Texas DIR STS SecOps contract. The role ensures compliance with NIST, PCI-DSS, IRS 1075, CJIS, and HIPAA while guiding enterprise security...Contract work
- ...enterprise Identity and Access Management (IAM) program to ensure secure, reliable, and compliant access to critical business systems,... ...initiatives. Collaborates with enterprise architecture, information security, infrastructure, and application development teams to...Full timeContract workLocal areaWorldwide
- ...Coupang seeks a Director on the Tech Infrastructure Security team to own the IAM platform and scale security services across thousands of microservices. You will hire and retain top engineers, shape team culture, and drive strategic investments. You will collaborate...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!
- head of security United States
- director of corporate security United States
- chief security officer United States
- director of security United States
- information system security engineer United States
- information security compliance analyst United States
- information security United States
- information security analyst United States
- senior director information security United States
- sr information security engineer United States

