Description
Company Description
The Vertex Companies, LLC (VERTEX) is a $180M global consulting firm that integrates strategic advisory, project management, and dispute resolution services for organizations facing complex challenges in a world of risk. We embody our core values of embracing lifelong learning, operating with urgency, maximizing value, and driving collaboration to better outcomes for our clients, colleagues, and communities. Join us if you are looking for a career that offers you a chance to love what you do and deliver meaningful impact.
Job Description
The Director of Information Security to lead the organization's cybersecurity, risk, and compliance programs across a modern, cloud-first enterprise spanning US, UK, and UAE operations. Reporting to the CISO, this senior leader will own the security strategy and its execution — with a central mandate to achieve and sustain SOC 2, HIPAA, and GDPR compliance while enabling business growth and an exceptional, low-friction end-user experience.
The Director will secure a SaaS-first ecosystem, Microsoft 365 E5, Azure, Salesforce, Egnyte, Box, Workday, and enterprise SSO/identity platforms and will build and direct a distributed security organization that includes onshore, offshore and specialist SOC/MSSP partners. The ideal candidate pairs deep technical security expertise with the leadership maturity to run governance programs, manage global teams, and influence at the executive level.
Core Responsibilities
- Partner with the CISO to operationalize the enterprise information security strategy, translating strategic priorities into executable roadmaps, governance programs, and measurable risk reduction outcomes.
- Build, lead, and develop a global security organization, including GRC teams, SOC/MSSP partners, and cross-functional stakeholders, ensuring accountability, service quality, and follow-the-sun support.
- Partner with HR, Legal, Privacy, business leadership, and IT teams to strengthen governance, accountability, and enterprise-wide ownership of security and compliance initiatives.
- Establish security KPIs, risk metrics, and control maturity roadmaps that provide executive leadership with clear visibility into security posture, performance, and continuous improvement opportunities.
- Conduct enterprise risk assessments, vendor reviews, and control gap analyses while maintaining cybersecurity risk registers and presenting key risk insights to leadership.
- Lead third-party security risk management programs, including vendor due diligence, security assessments, contractual requirements, and ongoing monitoring activities.
- Own and manage the security project portfolio, coordinating internal teams, MSSP partners, and external vendors to deliver strategic security initiatives and business objectives.
- Support the secure adoption of emerging technologies, including AI, automation, and cloud collaboration platforms, by embedding security-by-design principles into business and technology initiatives.
Operations
- Manage the SOC 2 compliance program from control design and implementation through evidence collection, continuous monitoring, audit readiness, certification, and ongoing attestation.
- Lead enterprise HIPAA compliance efforts, ensuring administrative, physical, and technical safeguards meet Security and Privacy Rule requirements for protecting PHI.
- Oversee GDPR compliance in partnership with Legal and Privacy teams, including data protection principles, records of processing activities, data subject rights, cross-border data transfer controls, and breach notification readiness.
- Develop, implement, and maintain security policies, standards, and procedures aligned with regulatory requirements and industry frameworks, including SOC 2, HIPAA, GDPR, ISO 27001, and NIST.
- Manage the security posture and secure configuration of enterprise SaaS and cloud platforms, including Microsoft 365 E5, Azure, Salesforce, Egnyte, Box, Workday, and related technologies.
- Strengthen enterprise identity and access management through Microsoft Entra ID, SSO, MFA, Conditional Access, access reviews, and least-privilege controls.
- Advance secure end-user computing through endpoint protection, remote-work security controls, phishing resistance initiatives, and security awareness programs that minimize business disruption.
- Own enterprise security incident response, including investigation, containment, remediation, recovery, and regulatory reporting, while coordinating with SOC, MSSP, and IT operations teams to maintain 24×7 readiness.
Qualifications & Competencies
- Bachelor's degree and 12 years of related experience or a Master's degree and 8 years of related experience, and at least 5 years in management capacity.
- Hands‑on experience owning SOC 2 audits and compliance‑evidence programs to successful attestation.
- Strong working knowledge of the HIPAA Security and Privacy Rules and safeguards.
- Demonstrated experience implementing and operating GDPR data‑protection controls.
- Experience securing SaaS platforms such as Microsoft 365, Azure, Salesforce, Box, Egnyte, and Workday.
- Strong expertise in IAM, MFA, Conditional Access, and Zero Trust principles.
- Experience managing onshore and offshore security teams and outsourced SOC/MSSP partnerships.
Knowledge & Skills
- Must have at least one Certifications such as CISSP, CISM OR CRISC
- Experience in regulated industries (healthcare, engineering, professional services).
- Familiarity with Microsoft Defender, Purview, CASB, and cloud security posture management (CSPM) tools.
- Experience supporting CMMC or other government/defense compliance frameworks.
- Experienced in leading SOC 2, HIPAA, and GDPR programs, audits, and ongoing compliance activities.
- Skilled in designing and managing security for SaaS‑first and cloud‑native environments.
- Proven ability to secure enterprise SSO, identity platforms, and access‑control frameworks.
- Applies practical judgment to prioritize cybersecurity risks and drive effective mitigation.
- Hands‑on experience managing security incidents, escalations, and operational response activities.
- Clearly communicates with technical teams, business users, leaders while translating security risk into business impact.
- Builds strong partnerships with IT, Legal, HR, Privacy, and business leaders to advance shared security objectives.
- Leads onshore and offshore teams with clear direction, accountability, and cross‑cultural awareness.
- Balances strong user protection with productivity, usability, and a seamless technology experience.
Additional Information
At VERTEX, we invest in top talent with a highly competitive total compensation package that rewards performance and supports long‑term success. Total compensation includes a base salary and a discretionary variable bonus program, depending on your level. Our comprehensive benefits package offers multiple healthcare and dental plan options, as well as company‑paid Life Insurance, Short‑Term Disability, and Long‑Term Disability coverage—ensuring peace of mind for you and your family.
We offer a 401(k) plan with immediate matching and full vesting, empowering employees to build financial security from day one. Additional benefits include Flexible Spending Accounts, a robust Employee Assistance Program, and a suite of exclusive perks that enhance everyday life.
At The Vertex Companies, our salary ranges are intentionally designed to support meaningful career growth over time. These ranges allow employees to develop, expand their impact, and increase their earnings as they progress within their job level. A new hire’s starting compensation is determined by their experience, geographical location, scope of the role at the time of hire, and Company affordability. Our ranges are structured to reward growth and performance, ensuring there is room for advancement and long‑term opportunity.
The Salary Ranges For This Role Are As Follows
$159,000 - $432,000 USD annually (Geographical Tier AA - Sample Locations: NY Metro, San Franscisco, San Jose, Seattle)
$146,000 - $398,000 USD annually (Geographical Tier A - Sample Locations: Irvine CA, Middlesex NJ, Tacoma WA, Boston, Alexandria)
$134,000 - $365,000 USD annually (Geographical Tier B - Sample Locations - Baltimore, Chicago, Anchorage, Portland)
$122,000 - $332,000 USD annually (Geographical Tier C - Sample Locations - Atlanta, Charlotte, Cincinnati, Miami)
$116,000 - $316,000 USD annually (Geographical Tier D - Sample Locations - Mississippi, Mobile AL, Bowling Green KY, Tulsa)
Time away matters—so we provide a generous paid time off program, including vacation, sick time, and paid holidays (with prorated options for eligible part‑time employees).
At VERTEX, growth never stops. Our signature “Lifetime of Learning” program offers tuition reimbursement and personalized support for employees pursuing advanced education—helping you sharpen your skills and accelerate your career.