Jobs · Information Technology · Maryland

Director of Cybersecurity, Governance, Risk and Compliance

Gross, Mendelsohn & Associates, P.A. · Baltimore, MD · 4 mo ago
On-siteInformation TechnologyFull-time

Cybersecurity & IT Governance Leadership

Serve as the firm’s senior leader for cybersecurity governance, risk, and compliance advisory services.
Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, and related standards.
Lead end-to-end CUI and federal compliance programs, including development and maintenance of System Security Plans (SSP) and Plans of Action & Milestones (POA&M)
Conduct NIST SP 800-171 gap assessments and develop prioritized remediation roadmaps
Support clients with DFARS 252.204-7012 compliance, SPRS scoring, and CMMC readiness initiatives
Prepare clients for audits, mock assessments, and government inquiries

IT Infrastructure & Security Oversight

Oversee implementation and validation of technical cybersecurity controls, including:
Multi-factor authentication
Encryption (data at rest and in transit)
Endpoint protection
Logging, SIEM, and continuous monitoring
Network segmentation
Secure configuration and hardening standards
Provide advisory oversight of secure cloud environments, including Microsoft GCC High, Azure Government, and AWS GovCloud
Establish identity and access management frameworks and privileged access controls
Evaluate backup, disaster recovery, and business continuity processes
Direct incident response strategy and regulatory reporting obligations

Supply Chain & Flow-Down Advisory

Advisory prime contractors on subcontractor cybersecurity flow-down requirements
Assess subcontractor readiness and compliance risk exposure
Support documentation required for federal scrutiny

Training & Continuous Improvement

Develop and deliver CUI-specific and role-based cybersecurity training
Implement measurable security awareness initiatives, including phishing simulations
Lead annual program reviews and continuous improvement initiatives

Maintain Compliance Posture

Maintain compliance posture during infrastructure changes, acquisitions, or system transitions

Executive Advisory & Reporting

Prepare executive-level cybersecurity risk reports and board-ready briefings
Translate complex technical risk into actionable business guidance
Collaborate with firm leadership to expand cybersecurity service offerings

Similar jobs

Director of Cybersecurity

Altar'd StateKnoxville, TN· 3 wk ago
Information Technologyapply on standoutforgood.wd12.myworkdayjobs.com