[Hiring] Director of Security @Crete Professionals Alliance
Director of Security @Crete Professionals Alliance
All Others
Salary usd 187,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4wks ago

[Hiring] Director of Security @Crete Professionals Alliance

4wks ago - Crete Professionals Alliance is hiring a remote Director of Security. πŸ’Έ Salary: usd 187,000 - 225,000 per year πŸ“Location: USA

Role Description

Own the enterprise information security, compliance & business continuity program across Crete (corporate) and all member firms. Build standardized, scalable security controls, governance, and operations across multiple independent control environments.

  • Define the multi-year security strategy and roadmap across Crete and member firms in a federated model, aligning priorities to business risk and acquisition cadence.
  • Establish and maintain the security policy framework, standards, and minimum control baseline across all firms; design pragmatic exception handling and remediation plans for varying maturity levels.
  • Build security operating rhythms and executive reporting: KPIs, risk posture, incident trends, audit/compliance status, and program progress for Crete leadership and firm leaders.
  • Partner with IT, data, and engineering leadership to embed security into operations, architecture decisions, and change management across the portfolio.
  • Lead security diligence for M&A: current-state control assessments, key risk identification, remediation estimates, and repeatable post-close stabilization playbooks (30/60/90-day plans).
  • Drive security integration of new firms (people/process/technology) across separate environments β€” identity, endpoint/email, logging/monitoring, data protection β€” with scalable onboarding playbooks and control alignment patterns.
  • Provide security architecture oversight for cloud and hybrid environments with emphasis on Azure, Intune, and Microsoft Defender; define secure patterns for privileged access, conditional access, PAM, RBAC, and separation of duties.
  • Oversee day-to-day security operations: vulnerability management, patch/risk prioritization, endpoint and email security, tooling lifecycle, and event triage across Crete and member firms.
  • Manage third-party MDR/SOC providers β€” scope, SLAs, escalation paths, detection coverage, playbooks, reporting β€” and drive continuous improvement of monitoring outcomes.
  • Own the incident response program end-to-end: runbooks, tabletop exercises, ransomware preparedness, forensics coordination, and post-incident reviews with corrective actions.
  • Implement consistent risk management across firms β€” periodic assessments, control testing, remediation tracking β€” and own third-party/vendor security risk management for corporate and shared vendors.
  • Support member firms with client-driven security and compliance requirements (NIST CSF, CIS, SOC 2 Type II); ensure evidence collection is repeatable and accurate.
  • Lead security awareness and training programs tailored to professional services workflows, with measurable adoption and behavioral outcomes.
  • Lead, coach, and develop the cybersecurity team; serve as escalation point for security decisions, incidents, and complex risk tradeoffs.
  • Build documentation, playbooks, and implementation guides that enable consistent security outcomes across firms; influence firm leaders and local teams to drive baseline control adoption.

Qualifications

  • 10+ years of progressive experience in information security or cybersecurity.
  • 3+ years leading and developing security teams.
  • Demonstrated M&A, private equity, or roll-up experience.
  • Strong understanding of cloud security principles with hands-on Azure and Microsoft security experience.
  • Experience managing and governing compliance standards (NIST, CSF, CIS, and SOC2 Type II preferred).
  • Experience managing business continuity programs and lifecycle.
  • Microsoft Azure/Intune experience.
  • Experience managing third-party security services (MDR/SOC, IR retainers, testing vendors).
  • Proven ability to design and run a complete enterprise security control program.
  • Excellent stakeholder management and executive communication skills.
  • Bachelor’s degree or equivalent experience; security certifications preferred (CISSP).
  • Professional services experience and/or accounting and CPA firm experience strongly preferred.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Director of Security @Crete Professionals Alliance
All Others
Salary usd 187,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 4wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 160,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 160,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews
Unlock All Jobs Now

Maybe later