Director of Security
Location
United States
Posted
34 days ago
Salary
$187K - $225K / year
Seniority
Lead
Job Description
Director of Security
Current
Role Description Own the enterprise information security, compliance & business continuity program across Crete (corporate) and all member firms. Build standardized, scalable security controls, governance, and operations across multiple independent control environments. - Define the multi-year security strategy and roadmap across Crete and member firms in a federated model, aligning priorities to business risk and acquisition cadence. - Establish and maintain the security policy framework, standards, and minimum control baseline across all firms; design pragmatic exception handling and remediation plans for varying maturity levels. - Build security operating rhythms and executive reporting: KPIs, risk posture, incident trends, audit/compliance status, and program progress for Crete leadership and firm leaders. - Partner with IT, data, and engineering leadership to embed security into operations, architecture decisions, and change management across the portfolio. - Lead security diligence for M&A: current-state control assessments, key risk identification, remediation estimates, and repeatable post-close stabilization playbooks (30/60/90-day plans). - Drive security integration of new firms (people/process/technology) across separate environments — identity, endpoint/email, logging/monitoring, data protection — with scalable onboarding playbooks and control alignment patterns. - Provide security architecture oversight for cloud and hybrid environments with emphasis on Azure, Intune, and Microsoft Defender; define secure patterns for privileged access, conditional access, PAM, RBAC, and separation of duties. - Oversee day-to-day security operations: vulnerability management, patch/risk prioritization, endpoint and email security, tooling lifecycle, and event triage across Crete and member firms. - Manage third-party MDR/SOC providers — scope, SLAs, escalation paths, detection coverage, playbooks, reporting — and drive continuous improvement of monitoring outcomes. - Own the incident response program end-to-end: runbooks, tabletop exercises, ransomware preparedness, forensics coordination, and post-incident reviews with corrective actions. - Implement consistent risk management across firms — periodic assessments, control testing, remediation tracking — and own third-party/vendor security risk management for corporate and shared vendors. - Support member firms with client-driven security and compliance requirements (NIST CSF, CIS, SOC 2 Type II); ensure evidence collection is repeatable and accurate. - Lead security awareness and training programs tailored to professional services workflows, with measurable adoption and behavioral outcomes. - Lead, coach, and develop the cybersecurity team; serve as escalation point for security decisions, incidents, and complex risk tradeoffs. - Build documentation, playbooks, and implementation guides that enable consistent security outcomes across firms; influence firm leaders and local teams to drive baseline control adoption. Qualifications - 10+ years of progressive experience in information security or cybersecurity. - 3+ years leading and developing security teams. - Demonstrated M&A, private equity, or roll-up experience. - Strong understanding of cloud security principles with hands-on Azure and Microsoft security experience. - Experience managing and governing compliance standards (NIST, CSF, CIS, and SOC2 Type II preferred). - Experience managing business continuity programs and lifecycle. - Microsoft Azure/Intune experience. - Experience managing third-party security services (MDR/SOC, IR retainers, testing vendors). - Proven ability to design and run a complete enterprise security control program. - Excellent stakeholder management and executive communication skills. - Bachelor’s degree or equivalent experience; security certifications preferred (CISSP). - Professional services experience and/or accounting and CPA firm experience strongly preferred. Benefits - The total rewards package at Current includes base salary, bonus, and benefits. - Our salary ranges are competitive within the accounting industry and are updated regularly using the most reliable compensation survey data for our industry. - New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers. - We provide a robust benefits package, including: - Health, Dental, and Vision Insurance (with options for fully paid employee only coverage for health and dental). - Company-Paid Life and Long-Term Disability Insurance. - Ancillary Benefits such as supplemental life insurance and short-term disability options. - Classic Safe Harbor 401(k) Plan with employer contributions. - Opportunities for professional growth, learning, and development including access to Becker and LinkedIn Learning. Equal Opportunity We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or any other applicable legally protected characteristic.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Formulating and executing service delivery strategies aligned with quality standards. • Working with clients to understand requirements and planning technical activities. • Leading project’s technical team within the scope of the engagement. • Documenting and presenting product security risks in both technical and business language. • Conducting technical QA and presenting deliverables to technical and business audiences. • Building and developing relationships with cross-client teams and partners. • Ensuring client satisfaction and business growth by communicating lessons learned.
Cloud Security Engineer
GleanSearch across all your company's apps to find exactly what you need and discover the things you should know.
• Collaborate with cross-functional teams to design and architect secure cloud infrastructure solutions on AWS and Azure • Identify potential security vulnerabilities and gaps in existing infrastructure and propose remediation plans • Implement cloud-native security technologies and best practices to address identified gaps • Analyze security logs and metrics to proactively detect and respond to security incidents • Develop and deploy security controls, such as identity and access management (IAM), network security policies, and encryption mechanisms • Leverage software engineering skills to create security-specific features, particularly in the areas of authentication, authorization, and rate limiting • Create documentation and train and guide team members and other stakeholders on security best practices
Software Engineer, Platform Security
GleanSearch across all your company's apps to find exactly what you need and discover the things you should know.
• Design, develop, and maintain secure software for core platform functionalities • Collaborate with cross-functional teams (engineering, product) to integrate security best practices throughout the development lifecycle • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies • Conduct security code reviews and identify potential security risks in existing codebases • Develop and implement automated security testing procedures • Respond to security incidents and participate in incident response procedures • Continuously improve the platform's security posture by identifying and implementing security enhancements • Document security processes, procedures, and best practices
Security Architect
ZscalerZscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th
• Build secure agent runtimes, libraries, and reference implementations while implementing core agent patterns like planner/executor, tool routing, and RAG boundaries • Build and secure MCP servers, clients, tool registries, and connector patterns with robust authentication, authorization, and audit logging • Enforce secure-by-default controls including schema validation, tool allowlists, redaction, and policy checks • Threat model and test agent workflows for prompt injection and data exfiltration to build repeatable security evaluations


