Director of Information Security
Summary
The Director of Information Security will lead the organization's information security program, ensuring compliance with defense industry regulations, managing information security, and supervising a team of ~5 professionals. This role requires deep expertise in defense contractor security requirements and the ability to balance rigorous security controls with operational efficiency.
Responsibilities
- Lead and mentor a team of information security professionals including compliance specialists, compliance managers, and/or analysts
- Develop and execute the information security strategy aligned with business objectives and threat landscape
- Collaborate with executive leadership on security risk management, investment priorities, and incident response
- Lead and write procedures on approving security exceptions, foreign travel, and deviations following established risk management frameworks
- Build compliance approaches for NIST SP 800-171, CMMC, DFARS, ITAR, EAR, and other defense industry information security requirements
- Develop and maintain security policies, procedures, and standards
- Conduct information security risk assessments and manage risk treatment plans
- Oversee security audits, assessments, and government inspections
- Maintain relationships with government and third party representatives
- Review and advise on continuous monitoring, compliance practices, and security automation priorities
- Develop security metrics and reporting for leadership and government customers
- Manage security budget and resource allocation
- Serve as trusted advisor to business units on security requirements
- Facilitate security discussions with customers and partners
- Balance security requirements with mission effectiveness and operational efficiency
- Promote security awareness culture throughout the organization
Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; Master's degree preferred
- Minimum 10 years of progressive information security experience
- Minimum 5 years in leadership role managing security teams
- Minimum 5 years working in defense contractor or government environment
- Experience managing security programs supporting classified systems and information
- Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance
- Expert knowledge of NIST SP 800-171, CMMC 2.0, and DFARS cybersecurity requirements
- Working knowledge of NIST Cybersecurity Framework, ISO 27001/27002, and CIS Controls
- Understanding of cloud security principles and FedRAMP requirements
- Familiarity with network security, endpoint protection, SIEM, and security operations technologies
- Knowledge of export control regulations (ITAR/EAR) and related IT security implications
- Strong leadership and people management capabilities
- Excellent written and verbal communication skills, including ability to present to executive audiences
- Risk management and decision-making under uncertainty
- Project and program management
- Budget management and financial planning
- Vendor management and contract oversight
- Ability to translate complex technical security concepts for non-technical stakeholders
- U.S. Citizen, U.S. Permanent Resident (Green Card holder) or asylee/refugee status as defined by 8 U.S.C. 1324b(a)(3) required
- No clearance required
Preferred Certifications
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CCP (CMMC Certified Professional)
- CCA (CMMC Certified Assessor)
- CAP (Certified Authorization Professional)
- Security+ or equivalent DoD 8570 IAT Level II certification
Additional Preferred Experience
- Experience in aerospace, intelligence, or weapons systems environment
- FedRAMP (Federal Risk and Authorization Management Program)
- FIPS 140-2/140-3 cryptographic module validation
- DoD Cloud Computing SRG
- NIST SP 800-37 (RMF Application) and SP 800-53
- ISO 27001 certification experience
- Security architecture design
- Software security and secure development lifecycle
- Supply chain risk management
- Export control and OPSEC experience
- Government liaison and relationship management
- Change management and organizational transformation
Physical Demands
- Ability to work in an office environment (Constant)
- Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)
Pay
The salary range for this role is $170,500 - $272,750. AeroVironment considers several factors when extending an offer, including but not limited to, the location, the role and associated responsibilities, a candidate's work experience, education/training, and key skills.
Benefits
AV offers an excellent benefits package including medical, dental, vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown.