Director, Cybersecurity

Ascend

United States

On-site

USD 180,000 - 280,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ascend is seeking a Director of Cybersecurity to build and run an enterprise cybersecurity program protecting client financial data across Ascend and its partner firms. You will own strategy, operations, incident response, and governance across NIST CSF 2.0, SOC 2 Type II, and PCI DSS, while leading AI governance and Zero Trust initiatives within a fast-growing, acquisition-driven environment.

You will report to the Vice President, Technology Infrastructure & Cybersecurity, and guide a team

Qualifications

  • 10+ years in information security and 5+ years leading security teams
  • Experience with professional services or regulated environments handling sensitive client data
  • Deep knowledge of NIST CSF 2.0, SOC 2 Type II, and PCI DSS
  • Hands-on incident response leadership and incident command experience
  • Budget ownership and vendor management experience

Responsibilities

  • Own enterprise cybersecurity strategy and multi-year roadmap.
  • Define security metrics and program maturity indicators.
  • Manage cybersecurity budget and headcount.
  • Manage relationships with MSSP and security vendors.
  • Own endpoint detection, security monitoring, vulnerability management, and email security.
  • Serve as incident commander and conduct post-incident reviews.
  • Establish detection coverage and determine outsourced-vs-in-house MSSP model.
  • Oversee SOC 2 Type II audit lifecycle and audit readiness.
  • Lead cybersecurity due diligence for acquisitions and security workstreams.
  • Build and develop a team of security engineers and analysts.

Skills

Information security leadership
Incident response leadership
Vendor management
Budget ownership
Security strategy
Threat detection

Education

CISSP or CISM certification

Tools

CrowdStrike Falcon
EDR
SIEM
Identity & Access Management (IAM)
Zero Trust
NIST CSF 2.0

Job description

About Ascend

Ascend empowers entrepreneurial CPAs to reach their goals with an innovative growth model that brings their firms into the new age. Backed by private equity from people-focused Alpine Investors, Ascend is building a modern platform for regional accounting firms that enables them to stay independent while accessing the resources of a large CPA firm to help them grow. Ascend provides access to growth capital, robust talent acquisition, best-of-breed technology, a catalytic leadership system, shared back-office services, and modernized equity incentives so that firms can surmount today’s industry challenges and reach their full potential. Founded in January 2023, the company attained revenues sufficient to qualify it as a Top 100 U.S. accounting firm within six months of operations.

About Ascend

Ascend empowers entrepreneurial CPAs to reach their goals with an innovative growth model that brings their firms into the new age. Backed by private equity from people-focused Alpine Investors, Ascend is building a modern platform for regional accounting firms that enables them to stay independent while accessing the resources of a large CPA firm to help them grow. Ascend provides access to growth capital, robust talent acquisition, best-of-breed technology, a catalytic leadership system, shared back-office services, and modernized equity incentives so that firms can surmount today’s industry challenges and reach their full potential. Founded in January 2023, the company attained revenues sufficient to qualify it as a Top 100 U.S. accounting firm within six months of operations.

For more information, visit ascendtogether.com.

About Alpine Investors

Alpine Investors is a people-driven private equity firm that is committed to building great companies by working with, learning from, and developing exceptional people. Alpine prides itself on fostering cultures where people value empowerment, diversity, fairness, integrity, and intellectual honesty. Founded in 2001, Alpine specializes in investments in companies in the software and services industries. Alpine has over $17 billion in AUM and has offices in San Francisco, New York, and Salt Lake City.

For more information on the firm, visit www.alpineinvestors.com

Position Summary

Ascend is seeking a Director of Cybersecurity to build and run the enterprise cybersecurity program that protects sensitive client financial data across Ascend and its growing network of tax, audit, and client advisory services (CAS) partner firms. This individual will own security strategy, operations, and incident response; governance, risk, and compliance (NIST CSF 2.0, SOC 2 Type II, PCI DSS); identity and Zero Trust; AI governance and agentic security; and the security workstream of every acquisition — building a program designed to scale with the pace of acquisition without slowing the business down.

The Director of Cybersecurity will report to the Vice President, Technology Infrastructure & Cybersecurity.

Key Responsibilities
Cybersecurity Strategy, Program & Budget Leadership
  • Own the enterprise cybersecurity strategy and multi-year roadmap, sequencing initiatives against partner-firm seasonality (tax deadlines) and the broader TST (Technology Stack Transition) integration timeline; present strategy and progress to the Vice President, Technology Infrastructure & Cybersecurity.
  • Define, track, and report a concise set of security metrics and program-maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to executive leadership on a fixed cadence.
  • Develop and manage the cybersecurity budget for tooling, MSSP/vendor contracts, and headcount, keeping security cost transparent and competitive across partner firms.
  • Manage relationships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), securing preferred pricing and early access to product roadmaps and preview programs.
Security Operations & Incident Response
  • Own endpoint detection and response (CrowdStrike Falcon), security monitoring and log management, vulnerability management, and email security across Ascend and all partner firms.
  • Serve as incident commander for cybersecurity incidents; maintain and test the incident response plan through regular tabletop exercises, and lead post-incident reviews and remediation to closure.
  • Establish detection coverage, alert triage, and escalation standards, and determine the right outsourced-vs.-in-house MSSP model for 24x7 monitoring.
  • Define vulnerability and patch SLAs by asset criticality and partner with infrastructure and service-desk teams to ensure remediation lands; engage a qualified external firm to conduct periodic penetration testing.
Governance, Risk & Compliance
  • Own the governance, risk, and compliance program, including enterprise risk assessments and security policies and standards aligned to NIST CSF 2.0.
  • Own the full SOC 2 Type II audit lifecycle — control design, evidence collection, and auditor management — sustaining a clean attestation through each annual observation period.
  • Respond to client security questionnaires and due-diligence requests in support of partner-firm engagements, maintaining a reusable evidence library to shorten turnaround.
  • Manage PCI DSS compliance for payment acceptance across Ascend and its partner firms, and own the third‑party and vendor risk management program, including security review of new tools prior to adoption.
Identity, Zero Trust & AI Governance
  • Define and enforce identity and access management standards in Microsoft 365 and Entra ID, including conditional access, multifactor authentication, and privileged access management.
  • Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, and ensure the security of tax production platforms (CCH Axcess, UltraTax) throughout the client-data lifecycle.
  • Establish and own the AI governance program: acceptable use policy, AI tool and model risk assessment, data-protection standards for client data in AI systems, and an intake process that moves at the speed of the business.
  • Define and enforce security controls for agentic AI, including identity and least‑privilege access for AI agents, monitoring of AI tool usage, and security review of third‑party AI vendors and integrations before they touch client data.
Acquisition Security, Team & Culture
  • Lead cybersecurity due diligence for acquisitions, surfacing material risk before close, and own the security workstream of the TST process for newly acquired partner firms; build a repeatable integration playbook that shortens time-to-secure as acquisition volume grows.
  • Build, manage, and develop a team of security engineers and analysts; set priorities, define performance standards, grow team capabilities, and hire A-players into key security seats.
  • Own the security awareness training and phishing simulation program across all partner firms, tracking and driving down phishing failure rates and reporting human-risk metrics alongside technical metrics.
Qualifications
  • 10+ years in information security, with 5+ years leading security teams or programs.
  • Experience securing professional services, financial services, or other regulated environments handling sensitive client data; experience in a hypergrowth, acquisition-driven, multi-entity environment strongly preferred.
  • Deep working knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS.
  • Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems.
  • Hands‑on depth across EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms.
  • Demonstrated incident response leadership, including incident command and executive communication during active incidents.
  • Strong vendor management and budget ownership experience.
  • CISSP, CISM, or equivalent certification preferred; Azure security certifications a plus.

At Ascend, we provide a fair and equal employment opportunity for all candidates regardless of race, color, religion, national origin, gender, pregnancy, sexual orientation, gender identity/expression, age, marital status, disability, or any other legally protected characteristic. Ascend hires and promotes individuals solely based on qualifications for the position to be filled and business needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Cybersecurity Strategy & Incident Response
Director of Cybersecurity Strategy & Incident Response

Ascend • United States

On-site
USD 180,000 - 280,000
Senior Security Engineer
Senior Security Engineer

TrulyHired • New York (NY)

On-site
USD 104,000 - 149,000
Health insurance
Dental insurance
Vision insurance
+7
Security Architect
Security Architect

Ascendion • United States

Remote
USD 120,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+6
Director, Cyber Security
Director, Cyber Security

Ziply Fiber • Kirkland (WA)

On-site
USD 180,000 - 230,000
Medical
dental
vision
+9
Director of Cybersecurity
Director of Cybersecurity

Altar'd State • Knoxville (TN)

On-site
USD 130,000 - 160,000
Director of Cyber Security
Director of Cyber Security

Vista Search Partners • Los Angeles (CA)

On-site
USD 200,000 - 300,000
Medical
Dental
Vision
+3
Compliance & Enterprise Security Manager
Compliance & Enterprise Security Manager

Ascendo Resources • Houston (TX)

On-site
USD 140,000 - 190,000
Cyber Security Consultant
Cyber Security Consultant

Ascendion • United States

Hybrid
USD 210,000 - 215,000
Medical Insurance
Dental Insurance
Vision Insurance
+7
Director, Cybersecurity Practice
Director, Cybersecurity Practice

Socket.dev • Atlanta (GA)

On-site
USD 180,000 - 240,000
Director of Cybersecurity Consulting Delivery and Operations
Director of Cybersecurity Consulting Delivery and Operations

TekStream Solutions • Atlanta (GA)

On-site
USD 180,000 - 280,000