Roles and Responsibilities
Develop the compliance roadmap and lead SOC 2 and ISO 27001 certification programs.
Collaborate with the Identity and Access Management team to strengthen the company’s identity posture and AI governance guardrails.
Direct the End-User Services team in deploying endpoint protection solutions, including mobile device management, conditional access, verified identity, and related security capabilities.
Develop and operate a comprehensive threat and vulnerability management program.
Develop and manage a comprehensive threat hunting, event analysis, and incident response capability.
Perform detailed and complex security analysis, including malware analysis.
Provide technical leadership for all relevant information security platforms.
Serve as the final escalation point for threat hunting, event detection and analysis, and incident response.
Oversee and directly participate in the administration of the firm’s SIEM and other relevant information security technology platforms.
Lead the response to and containment of information security-related incidents.
Ensure indicators of attack and indicators of compromise are promptly integrated into relevant systems and platforms.
Manage threat intelligence sources, including both human-readable and machine-readable intelligence.
Partner with IT, Legal, and Internal Audit to develop and maintain security best practices and policies for internal systems.
Play a primary role in the selection of new information security technologies.
Support the development of information security team members and facilitate knowledge transfer to other IT and firmwide groups.
Job Requirements
10+ years of experience in cybersecurity operations, including 5+ years leading cybersecurity teams at the manager, director, or higher level.
Proven experience owning enterprise cybersecurity strategy, including capital and operating budgets.
Deep hands-on expertise across all aspects of a comprehensive cybersecurity program.
Experience managing hybrid environments that span on-premises or colocation infrastructure and at least one major cloud platform, such as AWS, Azure, or GCP.
Deep knowledge of and experience with industry compliance programs, including SOC 2, ISO 27001, GDPR, DORA, and related frameworks.
Strong foundation in disaster recovery, business continuity, and high-availability architecture.
Experience with infrastructure automation, configuration management, and modern operations practices.
Track record of building, leading, and retaining high-performing technical teams.
Legally authorized to work in the United States.

