MANAGING DIRECTOR, INFORMATION SECURITY

Cresset CapitalChicago, IL
$210,000 - $300,000Hybrid

About The Position

We are seeking an experienced Managing Director, Information Security to lead Cresset's enterprise information security program. This senior technology leadership role is responsible for developing and executing the firm's information security strategy, protecting client and firm information assets, and leading the Information Security team. Reporting to the Chief Technology Officer, this role partners closely with Technology, Compliance, Legal, HR, and business leaders to strengthen Cresset's security posture while supporting the firm's continued growth and regulatory obligations. The successful candidate combines strong technical expertise with practical leadership and is comfortable balancing security, operational efficiency, and business enablement. We expect our employees to work in the office three days per week as part of our hybrid work environment.

Requirements

  • Bachelor's degree in Information Security, Computer Science, or a related field; advanced degree preferred.
  • 10+ years of progressive information security experience.
  • 5+ years leading enterprise information security teams, preferably as a Head of Information Security, Director of Information Security, Senior Director, or similar leadership role.
  • Experience building or significantly maturing an enterprise information security program within wealth management, financial services, or another highly regulated industry.
  • Demonstrated success developing high-performing teams and managing external vendors and strategic partners.
  • Deep understanding of Identity & Access Management, including authentication, authorization, RBAC, PAM, SSO, MFA, and identity governance.
  • Experience implementing and managing modern IAM platforms such as SailPoint, Okta, CyberArk, Ping Identity, or Microsoft Entra ID.
  • Strong knowledge of cloud security, data protection, DLP technologies, CASB/SSE platforms, SIEM, SOAR, and endpoint security.
  • Experience securing cloud-first, SaaS-centric environments.
  • Strong understanding of cybersecurity and privacy regulations applicable to financial services, including SEC Regulation S-P, Regulation S-ID, GLBA, FFIEC, PCI-DSS, GDPR, and CCPA.
  • Proven ability to develop security strategy, build consensus, and lead organizational change across technical and business stakeholders.
  • Strong communication skills with the ability to translate technical risks into business terms for executive leadership and business partners.
  • Excellent analytical, problem-solving, and risk-based decision-making skills.
  • Demonstrated ability to build trusted relationships across Technology, Compliance, Legal, and business functions.

Nice To Haves

  • One or more of the following certifications is strongly preferred: CISSP CISM CISA CRISC CCSP Or equivalent industry certifications

Responsibilities

  • Develop and execute Cresset's multi-year information security roadmap aligned with the firm's technology strategy and business priorities.
  • Maintain the firm's Information Security Program, including security policies, standards, and governance processes.
  • Assess the current security environment and develop prioritized plans to strengthen the firm's overall security posture.
  • Partner with the CTO, Compliance, Legal, HR, and business leaders to identify, assess, and mitigate cybersecurity risks.
  • Lead security architecture and technology decisions supporting cloud, endpoint, network, identity, and data protection capabilities.
  • Develop and manage the Information Security budget, vendor relationships, and technology investments in partnership with Technology leadership.
  • Provide regular reporting on security initiatives, key risks, and program maturity to executive leadership.
  • Lead, mentor, and develop the Information Security organization, including leaders responsible for Identity & Access Management (IAM) and Network Security/Data Protection.
  • Foster a collaborative, service-oriented security culture that enables the business while appropriately managing risk.
  • Establish clear operational processes, performance expectations, and accountability across the Information Security team.
  • Provide coaching and career development for security engineers and analysts.
  • Manage relationships with security vendors, managed service providers, and consulting partners.
  • Lead the firm's Identity & Access Management (IAM) program, including identity lifecycle management, privileged access management (PAM), single sign-on (SSO), multi-factor authentication (MFA), and identity governance.
  • Oversee the evaluation, implementation, and ongoing management of IAM technologies including Okta, SailPoint, CyberArk, Microsoft Entra ID, or similar platforms.
  • Ensure effective user provisioning, deprovisioning, access reviews, privileged access controls, and role-based access management.
  • Partner with IT, HR, and business leaders to improve onboarding, offboarding, and access governance processes.
  • Lead the firm's data protection and network security program to safeguard sensitive client and firm information across cloud, web, email, endpoint, and network environments.
  • Oversee Data Loss Prevention (DLP) capabilities, including data classification, policy development, monitoring, and continuous optimization.
  • Ensure security controls are integrated across the broader security ecosystem, including CASB, SSE, SIEM, SOAR, EDR, and IAM platforms.
  • Monitor key security metrics and continuously improve detection, prevention, and response capabilities.
  • Partner with Compliance and Legal to ensure the Information Security Program supports applicable regulatory requirements, including SEC Regulation S-P, Regulation S-ID, GLBA, and other relevant cybersecurity and privacy standards.
  • Support regulatory examinations, internal audits, and client cybersecurity due diligence activities.
  • Lead enterprise cyber risk assessments, data classification initiatives, and third-party cybersecurity risk management.
  • Partner with firm leadership to evaluate cyber insurance coverage and overall cyber risk management strategies.
  • Lead the firm's cybersecurity incident response program, including preparation, detection, containment, recovery, and post-incident review.
  • Coordinate incident response activities across Technology, Compliance, Legal, Communications, and business stakeholders.
  • Conduct periodic tabletop exercises and continuously improve incident response readiness.
  • Oversee vulnerability management, endpoint protection, logging and monitoring, penetration testing, and threat detection capabilities.
  • Partner with Technology leadership to support business continuity and disaster recovery planning.
  • Lead the firm's security awareness and education program, including role-based training for employees.
  • Promote a culture of cybersecurity awareness throughout the organization.
  • Evaluate emerging technologies and recommend improvements to the firm's overall security program.
  • Support client and prospect cybersecurity due diligence requests and represent the Information Security program during security assessments.

Benefits

  • competitive compensation package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service