Director of Information Security
AV · Pottstown, PA · 2 days ago
On-siteInformation Technology$171k–$273k/yrFull-time
About the role
The Director of Information Security will lead the organization's information security program, ensuring compliance with defense industry regulations, managing information security, and supervising a team of ~5 professionals. This role requires deep expertise in defense contractor security requirements and the ability to balance rigorous security controls with operational efficiency.
Responsibilities
- Lead and mentor a team of information security professionals including compliance specialists, compliance managers, and/or analysts
- Develop and execute the information security strategy aligned with business objectives and threat landscape
- Collaborate with executive leadership on security risk management, investment priorities, and incident response
- Lead and write procedures on approving security exceptions, foreign travel, and deviations following established risk management frameworks
- Build compliance approaches for NIST SP 800-171, CMMC, DFARS, ITAR, EAR, and other defense industry information security requirements
- Develop and maintain security policies, procedures, and standards
- Conduct information security risk assessments and manage risk treatment plans
- Oversee security audits, assessments, and government inspections
- Maintain relationships with government and third party representatives
- Review and advise on continuous monitoring, compliance practices, and security automation priorities
- Develop security metrics and reporting for leadership and government customers
- Manage security budget and resource allocation
- Serve as trusted advisor to business units on security requirements
- Facilitate security discussions with customers and partners
- Balance security requirements with mission effectiveness and operational efficiency
- Promote security awareness culture throughout the organization
Qualifications
- Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field. Master's degree preferred
- Experience: Minimum 10 years of progressive information security experience. Minimum 5 years in leadership role managing security teams. Minimum 5 years working in defense contractor or government environment. Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance
- Technical Knowledge: Expert knowledge of NIST SP 800-171, CMMC 2.0, and DFARS cybersecurity requirements. Working knowledge of NIST Cybersecurity Framework, ISO 27001/27002, and CIS Controls. Understanding of cloud security principles and FedRAMP requirements. Familiarity with network security, endpoint protection, SIEM, and security operations technologies. Knowledge of export control regulations (ITAR/EAR) and related IT security implications
- Compliance Frameworks: NIST SP 800-171 (Protecting CUI in Nonfederal Systems), CMMC 2.0, and DFARS
- Skills: Strong leadership and people management capabilities. Excellent written and verbal communication skills, including ability to present to executive audiences. Risk management and decision-making under uncertainty. Project and program management. Budget management and financial planning. Vendor management and contract oversight. Ability to translate complex technical security concepts for non-technical stakeholders
- Certifications: CISSP (Certified Information Systems Security Professional), CISA (Certified Information Systems Auditor), CCP (CMMC Certified Professional), CCA (CMMC Certified Assessor), CAP (Certified Authorization Professional). Security+ or equivalent DoD 8570 IAT Level II certification
Additional Experience
- Experience in aerospace, intelligence, or weapons systems environment
- FedRAMP (Federal Risk and Authorization Management Program)
- FIPS 140-2/140-3 cryptographic module validation
- DoD Cloud Computing SRG
- NIST SP 800-37 (RMF Application) and SP 800-53
- ISO 27001 certification experience
- Security architecture design
- Software security and secure development lifecycle
- Supply chain risk management
- Export control and OPSEC experience
- Government liaison and relationship management
- Change management and organizational transformation