- Company Name
- Vernovis
- Job Title
- Director of Information Security
- Job Description
-
**Job Title:** Director of Information Security
**Role Summary**
Lead the design and implementation of a modern information security program in a Microsoft-centric cloud environment, focusing on security maturity, risk mitigation, and aligned security practices.
**Expectations**
Partner with IT leadership to embed security into cloud, identity, and endpoint ecosystems; lead ISO 27001 compliance and Zero Trust adoption while delivering measurable security outcomes through technical expertise and cross-functional collaboration.
**Key Responsibilities**
- Design, implement, and improve security programs across cloud, endpoint, identity, and on-prem environments for threat prevention, detection, and response.
- Oversee incident response preparedness, execution, and post-incident analysis to refine security capabilities.
- Lead ISO 27001 certification and compliance by mapping standards to operational controls.
- Evaluate and integrate security tools (e.g., Microsoft 365, Azure, Entra ID, Defender) and architectures aligned with business needs.
- Develop and execute a Zero Trust roadmap using identity-based security, device trust, and continuous monitoring.
- Conduct risk assessments, threat modeling, and vulnerability analysis to proactively mitigate risks.
- Mentor security teams, build high-performing capabilities, and collaborate with IT/business stakeholders to align initiatives with operational and strategic goals.
**Required Skills**
- Advanced expertise in identity and access management (IAM), cloud security, endpoint protection, incident response, and modern security architecture.
- Proven experience with Microsoft security tools: Entra ID (Azure AD), Conditional Access, Intune, Defender, Microsoft 365.
- Demonstrated ability to lead incident response efforts, including real-world event management and tabletop exercises.
- Strong leadership, communication, and influence skills to translate technical risk into actionable strategies for IT and business leaders.
- Analytical and problem-solving skills for prioritizing and managing multiple security initiatives under time constraints.
**Required Education & Certifications**
- Bachelor’s degree in computer science, cybersecurity, or related field (or equivalent technical experience).
- Demonstrated career progression to leadership roles in information security.
- Preferred certifications: CISSP, CISM, or ISO 27001 certification.
Cincinnati, United states
Hybrid
30-12-2025