Director, Cybersecurity
Cloud Platforms
Cloud Security
Cloud Security Posture Management
Cybersecurity Tools
Identity and Access Management
Incident Response
Information Security
InfoSec
Management
Microsoft Security
Project Management
Security Awareness
Security Compliance
Security Operations
Security Standards
Security Testing
Threat Intelligence
Vulnerability Management
Job Description
Asset Living is seeking a cybersecurity leader to drive enterprise strategy, governance, and day-to-day security operations in a serverless, cloud-first Microsoft 365 environment. This role standardizes the cybersecurity program, builds a scalable security operating model, and delivers a multi-year roadmap aligned to NIST CSF 2.0 and CIS Controls v8.1.
Responsibilities
- Lead the development, maintenance, and continuous improvement of enterprise threat detection and incident response playbooks and runbooks, covering detection, containment, mitigation, remediation, recovery, and post-incident lessons learned across the organization.
- Drive enterprise cyber-attack preparedness and crisis readiness by aligning people, processes, technologies, and testing programs to minimize operational risk and business impact.
- Develop, maintain, and operationalize enterprise incident response and crisis management, including response plans, tabletop exercises, recovery testing, and stakeholder communications to support rapid containment and effective decision-making.
- Implement and optimize security awareness training using industry best practices and measurable performance metrics to reduce human risk and provide leadership visibility into awareness, engagement, and effectiveness of risk mitigation.
- Continuously improve outsourced cybersecurity services by maturing security monitoring, threat detection and response, vulnerability management, cloud security, threat intelligence, and security validation programs to strengthen security posture.
- Own and optimize enterprise security monitoring and protection capabilities, including EDR, ITDR, MDR, SIEM, vulnerability management, and cloud posture.
- Oversee continuous threat exposure management through network vulnerability scanning, external penetration testing, and dark web scans.
- Maintain visibility and control over the organization’s cloud application portfolio through continuous discovery, classification, risk evaluation, and security oversight.
- Oversee enterprise identity and access management, driving adoption of Entra ID SSO, SCIM-based automated provisioning, and centralized identity governance across connected applications.
- Oversee enterprise identity and access governance for both Entra-integrated and non-SSO applications, ensuring secure authentication and authorization, user lifecycle management, and periodic access reviews.
- Develop, maintain, and annually update security policies and procedures while conducting regular tabletop exercises to validate incident response readiness, including DR, IR, and BC.
- Oversee management and optimization of email firewalls including DMARC policy, and network firewalls with IDS/IPS.
- Provide monthly executive reporting.
- Build and manage clear internal cybersecurity team roles, responsibilities, and operating processes aligned with strategic MSSP partnerships.
- Leverage deep Microsoft 365 Defender and Azure expertise to maximize security telemetry, visibility, and threat response through strategic integration of Microsoft with third-party security platforms.
- Establish clearly defined roles, responsibilities, escalation paths, and accountability across internal teams and MSSP partners to ensure effective security operations, service delivery, continuous improvement, and organizational maturity.
Requirements
- Relevant education in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field is preferred; equivalent professional experience will be considered.
- 8+ years of progressive IT and cybersecurity experience.
- 3+ years in a cybersecurity leadership role.
- Experience leading cybersecurity transformation initiatives aligned to NIST CSF 2.0 and CIS Controls.
Technologies
- Microsoft 365, Microsoft 365 Defender, Azure, Entra ID, Defender, Intune, Purview, SCIM
- MSSPs, EDR, ITDR, MDR, SIEM, Vulnerability Management, Cloud Posture
- DMARC, IDS/IPS
- NIST CSF 2.0, CIS Controls v8.1
- Tabletop exercises, dark web scans, external penetration testing, network vulnerability scanning
- DR, IR, BC, security validation programs, threat intelligence