Director, Information Security (52333)
Summary
Leads a cybersecurity team to build and mature detection, response, and threat intelligence capabilities, ensuring resilience against cyber threats across on-prem and cloud environments.
Citrin Cooperman offers a dynamic work environment, fostering professional growth and collaboration. We’re continuously seeking talented individuals who bring a problem-solving mindset, fresh perspectives, and sharp technical expertise. We know you have choices, so our team of collaborative, innovative professionals are ready to support your professional development. At Citrin Cooperman, we offer competitive compensation and benefits and most importantly, the flexibility to manage your personal and professional life to focus on what matters most to you!
We are seeking an Director, Information Security, to join our Information Security team within the Information Technology department. They’re responsible for building, leading, and maturing the enterprise capability to detect, investigate, and respond to cyber threats, as well as prevent them in the future.
This role oversees the cyber resilience functions, detection engineering, security operations center, threat intelligence, and incident response functions. It’s accountable for visibility, reduction of attacker dwell time, operational readiness, and effective containment of cyber incidents.
Responsibilities are, but not limited to:
- Security Operations & Engineering –
- Define operational frameworks, including but not limited to runbooks and escalation models.
- Build and lead the SOC teams to deliver 24/7 monitoring, investigation, triage and escalation capabilities.
- Enhance detection coverage and containment efficiency through analytics, automation, and orchestration.
- Collaborate with IT teams to design integrations, logging pipelines, and secure baselines across on-prem and cloud environments.
- Oversee security tool portfolio and ensure ongoing maturity and roadmaps.
- Guide security configuration standards, hardening baselines, patching strategy and vulnerability prioritization.
- Conduct tabletop exercises and simulation drills while integrating lessons and learning into operational workflow and improvements.
- Oversee security third-party relationships, ensuring SLAs, service quality, performance and contract alignment.
- Threat Management –
- Produce threat briefings and maintain a threat landscape dashboard.
- Oversee threat intelligence collection, enrichment, and operational functions.
- Lead proactive threat hunting, anomaly detection, and adversary simulation activities.
- Incident Response –
- Oversee forensics activities, evidence handling, and post-incident reporting.
- Manage the security incident response program, including but not limited to roles, escalation paths, and communication frameworks.
- Maintain and test incident response playbooks for various emerging and ongoing threats.
- Reporting & Metrics –
- Track program maturity, key risk indicators, and compliance progress.
- Produce dashboards and reports for various levels of management.