Job Description:
Voyant is a top provider of collaborative financial planning and wealth management software for financial professionals and their clients. The company’s product suite enables advisors to spend less time building plans and more time growing their business. Combining cutting-edge technology and compelling visuals, Voyant turns advisors into consultants and provides clients with a clear and comprehensive view of their financial landscape. Voyant empowers advisors to interact on a new level with financial plans personalized to meet clients’ unique goals.
The Job/What You'll Do:
As the Director of Information Security at Voyant, you will play a crucial role in shaping and maintaining the security landscape of our organization. Your expertise will be pivotal in developing internal processes, procedures, and policies related to all things security, with a focus on cybersecurity. This position is not one of formally directing employees, but rather directing all of security programs for the organization. The Director of Information Security reports directly to the CTO and is the point person at Voyant for all things security in its internal operations and in its SaaS products.
Responsibilities:
- In concert with the Director of Compliance, manage formal IT audits, including SOC II, and internal IT audits. (The ideal candidate will work toward developing automated solutions to ease the manual work involved in these audits.)
- Evaluate Voyant’s current security posture and identify vulnerabilities and threats to Voyant’s information assets, as well as Voyant’s SaaS offerings.
- Develop and maintain company-wide information security policies to mitigate risks and ensure compliance with regulatory requirements, reviewing all IT and Security policies on an annual basis, and developing new policies and procedures as needed.
- Coordinate with Voyant’s MSP for Intrusion Detection and Vulnerability Management. Investigating MSP alerts, monitor MSP products, and review monthly reports.
- Monitor the external threat environment for emerging threats and advise relevant stakeholders on the appropriate courses of action.
- Coordinate the development and implementation of incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event.
- Plan and organize the execution of network, and application penetration testing, with the possibility of also inaugurating red/blue team exercises.
- Review the results of application penetration tests.
- Organize periodic threat modelling sessions with application and operations teams.
- Develop and maintain security awareness training for employees.
- Stay up-to-date with the latest cybersecurity trends, threats, and best practices.
- Ensure that security is embedded in the project delivery process by providing appropriate information security policies, practices, and guidelines.
- Respond to customer and potential customer inquiries related to security.
- Contribute to periodic risk assessments to identify and remediate security gaps.
- Work closely with Voyant's IT and DevOps teams to implement various initiatives.
Knowledge, Skills, Abilities:
- In-depth Knowledge of SOC II compliance.
- Familiarity with security frameworks and standards (e.g., NIST, ISO 27001, CIS).
- Familiarity with AWS services, specifically: WAF, Security Hub, GuardDuty, Shield, ALB, EC2, S3, RDS, VPC.
- Excellent communication skills, both written and verbal.
Education & Experience:
- Experience in information security, cybersecurity, and IT audit management.
- IT and System Administration experience.
- Experience with Office.com Security and Compliance management
- Experience with automation tools and methodologies to streamline security processes.
- Certifications such as CISSP, CISM, CISA, or equivalent are a plus.
Candidates must be legally authorized to work in the US to be considered. We are unable to provide visa sponsorship for this position.
#LI-DNP
Who We Are & What We Offer:
AssetMark’s mission is centered around helping financial advisors make a difference in the lives of their clients. To help them do that, we aim to provide advisors with holistic support. We offer compelling technology that facilitates a better client experience, consulting services that ensure advisors’ businesses are running at their best and a comprehensive suite of investment solutions. AssetMark’s platform empowers advisors to provide the highest level of service possible to their clients.
AssetMark’s culture is driven by our mission and connected by our values; Heart, Integrity, Excellence and Respect. You will join a team that lives these values every day by doing the best and what is right in all we do and encouraging different ideas for continual success and innovation. Additionally, we offer a wide range of benefits to meet the needs of our team members and their families.
- Flex Time Off or Paid Time/Sick Time Off
- 401K – 6% Employer Match
- Medical, Dental, Vision – HDHP or PPO
- HSA – Employer contribution (HDHP only)
- Volunteer Time Off
- Career Development / Recognition
- Fitness Reimbursement
- Hybrid Work Schedule
As an Equal Opportunity Employer, AssetMark is committed to building a diverse and inclusive workplace where everyone feels valued.