Jobs · Information Technology · Pennsylvania

Director of Information Security

AV · Pottstown, PA · 2 days ago
On-siteInformation Technology$171k–$273k/yrFull-time

About the role

The Director of Information Security will lead the organization's information security program, ensuring compliance with defense industry regulations, managing information security, and supervising a team of ~5 professionals. This role requires deep expertise in defense contractor security requirements and the ability to balance rigorous security controls with operational efficiency.

Responsibilities

  • Lead and mentor a team of information security professionals including compliance specialists, compliance managers, and/or analysts
  • Develop and execute the information security strategy aligned with business objectives and threat landscape
  • Collaborate with executive leadership on security risk management, investment priorities, and incident response
  • Lead and write procedures on approving security exceptions, foreign travel, and deviations following established risk management frameworks
  • Build compliance approaches for NIST SP 800-171, CMMC, DFARS, ITAR, EAR, and other defense industry information security requirements
  • Develop and maintain security policies, procedures, and standards
  • Conduct information security risk assessments and manage risk treatment plans
  • Oversee security audits, assessments, and government inspections
  • Maintain relationships with government and third party representatives
  • Review and advise on continuous monitoring, compliance practices, and security automation priorities
  • Develop security metrics and reporting for leadership and government customers
  • Manage security budget and resource allocation
  • Serve as trusted advisor to business units on security requirements
  • Facilitate security discussions with customers and partners
  • Balance security requirements with mission effectiveness and operational efficiency
  • Promote security awareness culture throughout the organization

Qualifications

  • Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. Master's degree preferred
  • Experience: Minimum 10 years of progressive information security experience. Minimum 5 years in leadership role managing security teams. Minimum 5 years working in defense contractor or government environment. Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance
  • Technical Knowledge: Expert knowledge of NIST SP 800-171, CMMC 2.0, and DFARS cybersecurity requirements. Working knowledge of NIST Cybersecurity Framework, ISO 27001/27002, and CIS Controls. Understanding of cloud security principles and FedRAMP requirements. Familiarity with network security, endpoint protection, SIEM, and security operations technologies. Knowledge of export control regulations (ITAR/EAR) and related IT security implications
  • Compliance Frameworks: NIST SP 800-171 (Protecting CUI in Nonfederal Systems), CMMC 2.0, and DFARS
  • Skills: Strong leadership and people management capabilities. Excellent written and verbal communication skills, including ability to present to executive audiences. Risk management and decision-making under uncertainty. Project and program management. Budget management and financial planning. Vendor management and contract oversight. Ability to translate complex technical security concepts for non-technical stakeholders
  • Certifications: CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CCP (CMMC Certified Professional), CCA (CMMC Certified Assessor), CAP (Certified Authorization Professional). Security+ or equivalent DoD 8570 IAT Level II certification

Additional Experience

  • Experience in aerospace, intelligence, or weapons systems environment
  • FedRAMP (Federal Risk and Authorization Management Program)
  • FIPS 140-2/140-3 cryptographic module validation
  • DoD Cloud Computing SRG
  • NIST SP 800-37 (RMF Application) and SP 800-53
  • ISO 27001 certification experience
  • Security architecture design
  • Software security and secure development lifecycle
  • Supply chain risk management
  • Export control and OPSEC experience
  • Government liaison and relationship management
  • Change management and organizational transformation

Similar jobs