Director, Cybersecurity
About Ascend
Ascend empowers entrepreneurial CPAs to reach their goals with an innovative growth model that brings their firms into the new age. Backed by private equity from people-focused Alpine Investors, Ascend is building a modern platform for regional accounting firms that enables them to stay independent while accessing the resources of a large CPA firm to help them grow.
Ascend provides access to growth capital, robust talent acquisition, best-of-breed technology, a catalytic leadership system, shared back-office services, and modernized equity incentives so that firms can surmount today’s industry challenges and reach their full potential.
Founded in January 2023, the company attained revenues sufficient to qualify it as a Top 100 U.S. accounting firm within six months of operations. For more information, visit ascendtogether.com.
About Alpine Investors
Apline Investors is a people-driven private equity firm that is committed to building great companies by working with, learning from, and developing exceptional people. Alpine prides itself on fostering cultures where people value empowerment, diversity, fairness, integrity, and intellectual honesty.
Apline specializes in investments in companies in the software and services industries. Alpine has over $17 billion in AUM and has offices in San Francisco, New York, and Salt Lake City.
Position Summary
Ascend is seeking a Director of Cybersecurity to build and run the enterprise cybersecurity program that protects sensitive client financial data across Ascend and its growing network of tax, audit, and client advisory services (CAS) partner firms.
Key Responsibilities
Cybersecurity Strategy, Program & Budget Leadership
- Own the enterprise cybersecurity strategy and multi-year roadmap, sequencing initiatives against partner-firm seasonality (tax deadlines) and the broader TST (Technology Stack Transition) integration timeline;
- Present strategy and progress to the Vice President, Technology Infrastructure & Cybersecurity.
- Define, track, and report a concise set of security metrics and program-maturity indicators (NIST CSF 2.0 function scores, MTTD/MTTR, patch/vulnerability SLA attainment, phishing failure rate, control coverage) to executive leadership on a fixed cadence.
- Develop and manage the cybersecurity budget for tooling, MSSP/vendor contracts, and headcount, keeping security cost transparent and competitive across partner firms.
- Manage relationships and contracts with managed security service providers and security vendors (e.g., Microsoft, CrowdStrike), securing preferred pricing and early access to product roadmaps and preview programs.
Security Operations & Incident Response
- Own endpoint detection and response (CrowdStrike Falcon), security monitoring and log management, vulnerability management, and email security across Ascend and all partner firms.
- Serve as incident commander for cybersecurity incidents; maintain and test the incident response plan through regular tabletop exercises, and lead post-incident reviews and remediation to closure.
- Establish detection coverage, alert triage, and escalation standards, and determine the right outsourced-vs.-in-house MSSP model for 24x7 monitoring.
- Define vulnerability and patch SLAs by asset criticality and partner with infrastructure and service-desk teams to ensure remediation lands; engage a qualified external firm to conduct periodic penetration testing.
Governance, Risk & Compliance
- Own the governance, risk, and compliance program, including enterprise risk assessments and security policies and standards aligned to NIST CSF 2.0.
- Own the full SOC 2 Type II audit lifecycle — control design, evidence collection, and auditor management — sustaining a clean attestation through each annual observation period.
- Respond to client security questionnaires and due-diligence requests in support of partner-firm engagements, maintaining a reusable evidence library to shorten turnaround.
- Manage PCI DSS compliance for payment acceptance across Ascend and its partner firms, and own the third-party and vendor risk management program, including security review of new tools prior to adoption.
Identity, Zero Trust & AI Governance
- Define and enforce identity and access management standards in Microsoft 365 and Entra ID, including conditional access, multifactor authentication, and privileged access management.
- Advance the Zero Trust architecture across Zscaler ZIA/ZPA and the Azure Virtual Desktop environment managed through Nerdio, and ensure the security of tax production platforms (CCH Axcess, UltraTax) throughout the client-data lifecycle.
- Establish and own the AI governance program: acceptable use policy, AI tool and model risk assessment, data-protection standards for client data in AI systems, and an intake process that moves at the speed of the business.
- Define and enforce security controls for agentic AI, including identity and least-privilege access for AI agents, monitoring of AI tool usage, and security review of third-party AI vendors and integrations before they touch client data.
Acquisition Security, Team & Culture
- Lead cybersecurity due diligence for acquisitions, surfacing material risk before close, and own the security workstream of the TST process for newly acquired partner firms; build a repeatable integration playbook that shortens time-to-secure as acquisition volume grows.
- Build, manage, and develop a team of security engineers and analysts; set priorities, define performance standards, grow team capabilities, and hire A-players into key security seats.
- Own the security awareness training and phishing simulation program across all partner firms, tracking and driving down phishing failure rates and reporting human-risk metrics alongside technical metrics.
Qualifications
10+ years in information security, with 5+ years leading security teams or programs.
Experience securing professional services, financial services, or other regulated environments handling sensitive client data; experience in a hypergrowth, acquisition-driven, multi-entity environment strongly preferred.
Deep working knowledge of NIST CSF 2.0, SOC 2 Type II (including managing annual audit cycles), and PCI DSS.
Familiarity with AI security and governance, including the NIST AI Risk Management Framework and securing agentic/LLM-based systems.
Hands-on depth across EDR, SIEM, identity and access management, email security, and Zero Trust/SSE platforms.
Demonstrated incident response leadership, including incident command and executive communication during active incidents.
Strong vendor management and budget ownership experience.
CISSP, CISM, or equivalent certification preferred; Azure security certifications a plus.
At Ascend, we provide a fair and equal employment opportunity for all candidates regardless of race, color, religion, national origin, gender, pregnancy, sexual orientation, gender identity/expression, age, marital status, disability, or any other legally protected characteristic. Ascend hires and promotes individuals solely based on qualifications for the position to be filled and business needs.