Director of Information Security

🏢 Sorren · all Sorren jobs
📍 United States
📅 Posted 2026-08-07 · via Himalayas
🏷 Information-Security-Director,Cybersecurity-Director,IT-Security-Management,CISO,Information-Security-Leadership,Director-of-Information-Security,Director-Of-Cybersecurity
Apply on original site ↗

Our Firm
Sorren is a top 50 national advisory firm that blends deep expertise with a human-first approach. We don’t just work with numbers—we work with people, building lasting relationships and delivering strategic solutions in accounting, assurance, tax, advisory, and private client services.

At Sorren , we believe that success is a shared journey. Our culture fosters collaboration, innovation, and professional growth, ensuring that every team member has the support and opportunities they need to thrive. We offer a high-performing yet balanced work environment where career development and personal well-being go hand in hand.

We’re committed to helping you grow, whether that means advancing your career, expanding your expertise, or achieving a fulfilling work-life balance. Because at Sorren , your success is our success.

Your Journey
Our team members support the firm by delivering timely, accurate work and maintaining clear communication. They take ownership of their development, seek feedback, and build strong relationships. By managing responsibilities effectively and aligning their efforts with firm values, they establish a foundation for long-term success and growth. All team members are expected to excel in Relationships, Communication, Quality Service, Operational Excellence, and Innovation & Growth, contributing to the firm’s success through collaboration, exceptional service, and continuous growth.
Position Summary:
Key Responsibilities:

• Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations.
• Define the security configuration and hardening standards for Microsoft 365 and Entra ID and work in conjunction with the infrastructure team to ensure they are met.
• Set the AV and EDR configuration baseline and make sure security alerting and reporting scale as we grow.
• Define and put in place data protection controls across platforms, including classification, retention, encryption, and DLP.
• Set our email filtering and security posture standards and work with the infrastructure team to ensure they are met. Oversee firewall and network-device patch and update compliance.
• Maintain security policies, technical standards, controls, exceptions, and mature how we audit against them.
• Lead risk assessments[JD1.1], control reviews, and security planning activities across the firm’s infrastructure, applications, endpoints, and cloud services. This includes identifying risks, prioritizing remediation, tracking corrective actions, and validating closure
• Own risk register and tracking and run security and vendor risk assessments as the practice matures.
• Build and run the firm’s GLBA and FTC Safeguards program, accounting for other requirements such as HIPAA, PCI DSS, and state privacy laws (for example CCPA and CPRA) where applicable.
• Support client security reviews, cyber insurance requirements, and regulatory or contractual compliance efforts by preparing evidence, documenting controls, and coordinating remediation plans.
• Set up recurring system access reviews and support internal and external audit needs, including evidence collection.
• Maintain the incident response plan and be the point person for incident response activities, including any communication, coordinating external responders, and documentation.
• Plan and facilitate periodic incident response tabletop exercises and post-exercise improvement activities.
• Run and coordinate vulnerability scans and penetration tests and track remediation to closure.
• Own the security awareness and phishing simulation program, including strategy, reporting, and continuous improvement.
• Evaluate, direct, and hold managed-security and security-tool vendors accountable for results, while continuously assessing the effectiveness of current security partnerships and recommending changes where appropriate.
• Conduct security an

← All remote jobs