MANAGING DIRECTOR, INFORMATION SECURITY
Summary
Senior technology leader responsible for developing and executing the enterprise information security strategy at a multi-family office and private investment firm. Oversees IAM (Okta, SailPoint, CyberArk, Microsoft Entra ID), data protection, network security, incident response, and regulatory compliance (SEC Reg S-P, GLBA).
About Cresset
Cresset is a firm built by clients, for clients. As an independent, award-winning multi-family office and private investment firm, we are reimagining the way wealth is experienced. Our purpose is to help ensure that both wealth and life are fully optimized—integrated, intentional, and aligned with each client’s vision of success.
We provide access to the caliber of talent, ideas, and investment opportunities typically available to the largest single-family offices and institutions. Our approach is personalized, entrepreneurial, and client-first.
Proudly owned by our clients and employees, Cresset was built to endure. We are creating a 100+ year firm—one focused on delivering an exceptional experience, not only for the families we serve but for the team that serves them. Recognized by Barron’s and Forbes among the nation’s top RIA firms, and as one of the industry’s best places to work,* Cresset is guided by long-term relationships, shared success, and a belief that wealth should serve a life well lived.
Job Description
We are seeking an experienced Managing Director, Information Security to lead Cresset's enterprise information security program. This senior technology leadership role is responsible for developing and executing the firm's information security strategy, protecting client and firm information assets, and leading the Information Security team.
Reporting to the Chief Technology Officer, this role partners closely with Technology, Compliance, Legal, HR, and business leaders to strengthen Cresset's security posture while supporting the firm's continued growth and regulatory obligations. The successful candidate combines strong technical expertise with practical leadership and is comfortable balancing security, operational efficiency, and business enablement.
We expect our employees to work in the office three days per week as part of our hybrid work environment.
Key Responsibilities
Security Strategy, Governance & Leadership
- Develop and execute Cresset's multi-year information security roadmap aligned with the firm's technology strategy and business priorities.
- Maintain the firm's Information Security Program, including security policies, standards, and governance processes.
- Assess the current security environment and develop prioritized plans to strengthen the firm's overall security posture.
- Partner with the CTO, Compliance, Legal, HR, and business leaders to identify, assess, and mitigate cybersecurity risks.
- Lead security architecture and technology decisions supporting cloud, endpoint, network, identity, and data protection capabilities.
- Develop and manage the Information Security budget, vendor relationships, and technology investments in partnership with Technology leadership.
- Provide regular reporting on security initiatives, key risks, and program maturity to executive leadership.
Team Leadership
- Lead, mentor, and develop the Information Security organization, including leaders responsible for Identity & Access Management (IAM) and Network Security/Data Protection.
- Foster a collaborative, service-oriented security culture that enables the business while appropriately managing risk.
- Establish clear operational processes, performance expectations, and accountability across the Information Security team.
- Provide coaching and career development for security engineers and analysts.
- Manage relationships with security vendors, managed service providers, and consulting partners.
Identity & Access Management
- Lead the firm's Identity & Access Management (IAM) program, including identity lifecycle management, privileged access management (PAM), single sign-on (SSO), multi-factor authentication (MFA), and identity governance.
- Oversee the evaluation, implementation, and ongoing management of IAM technologies including Okta, SailPoint, CyberArk, Microsoft Entra ID, or similar platforms.
- Ensure effective user provisioning, deprovisioning, access reviews, privileged access controls, and role-based access management.
- Partner with IT, HR, and business leaders to improve onboarding, offboarding, and access governance processes.
Data Protection & Network Security
- Lead the firm's data protection and network security program to safeguard sensitive client and firm information across cloud, web, email, endpoint, and network environments.
- Oversee Data Loss Prevention (DLP) capabilities, including data classification, policy development, monitoring, and continuous optimization.
- Ensure security controls are integrated across the broader security ecosystem, including CASB, SSE, SIEM, SOAR, EDR, and IAM platforms.
- Monitor key security metrics and continuously improve detection, prevention, and response capabilities.
Regulatory Compliance & Risk Management
- Partner with Compliance and Legal to ensure the Information Security Program supports applicable regulatory requirements, including SEC Regulation S-P, Regulation S-ID, GLBA, and other relevant cybersecurity and privacy standards.
- Support regulatory examinations, internal audits, and client cybersecurity due diligence activities.
- Lead enterprise cyber risk assessments, data classification initiatives, and third-party cybersecurity risk management.
- Partner with firm leadership to evaluate cyber insurance coverage and overall cyber risk management strategies.
Security Operations & Incident Response
- Lead the firm's cybersecurity incident response program, including preparation, detection, containment, recovery, and post-incident review.
- Coordinate incident response activities across Technology, Compliance, Legal, Communications, and business stakeholders.
- Conduct periodic tabletop exercises and continuously improve incident response readiness.
- Oversee vulnerability management, endpoint protection, logging and monitoring, penetration testing, and threat detection capabilities.
- Partner with Technology leadership to support business continuity and disaster recovery planning.
Security Culture & Awareness
- Lead the firm's security awareness and education program, including role-based training for employees.
- Promote a culture of cybersecurity awareness throughout the organization.
- Evaluate emerging technologies and recommend improvements to the firm's overall security program.
- Support client and prospect cybersecurity due diligence requests and represent the Information Security program during security assessments.