Information Assurance Lead - Governance, Risk, Compliance
About the role
Axiom Space is seeking a bold and dynamic Information Assurance Lead who is fueled by high accountability, execution horsepower, and driven to understand our world, science/technology, and life itself, for the benefit of all on Earth and beyond. The Information Assurance (IA) Lead provides the strategic direction and technical oversight necessary to ensure Axiom Space systems and processes meet rigorous security, regulatory, and compliance obligations.
Responsibilities
- Lead the design and implementation of the Information Assurance roadmap, ensuring all internal and customer-facing systems align with the organizational risk appetite and modern threat landscapes.
- Function as the primary point of contact and lead for all security audits and certifications (NIST, CMMC, ISO 27001).
- Oversee technical security assessments and threat modeling for complex networks.
- Utilize frameworks like MITRE ATT&CK to model adversary tactics, techniques, and procedures (TTPs), identify deviations from policy and authorize remediation strategies based on recognized countermeasures.
- Partner with Engineering, Legal, and Program stakeholders to integrate robust security controls and defensive mitigations into the system development life cycle (SDLC).
- Lead the integration of cybersecurity requirements into the procurement lifecycle; partner with Safety and Mission Assurance to define technical security baselines for suppliers and manage the end-to-end audit process to ensure compliance with NIST 800-53/171 and CMMC standards.
- Drive automation in the compliance space by integrating security tooling (SIEM, GRC platforms, etc.) to create a continuous monitoring environment, mapping alerts, and telemetry to MITRE frameworks to ensure comprehensive defensive coverage.
- Translate complex security risks into business contexts for leadership, providing actionable insights on emerging adversary trends, defensive readiness, and regulatory changes.
- Implement and maintain agile project management methodologies throughout the project lifecycle.
Qualifications
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related discipline; or equivalent practical experience, defined as 8+ years of progressively responsible experience in Information Assurance, Cybersecurity, Risk Management, or IT Audit.
- Minimum of 8+ years in technical cybersecurity roles, including at least 3 years with a primary focus on cybersecurity compliance, governance, risk, or audit functions.
- Certifications: Relevant industry certifications strongly preferred, such as CISSP, CISM, CISA, GSNA, CCA, or comparable credentials demonstrating expertise in security leadership, governance, and assurance.
- Demonstrated expert-level knowledge of NIST cybersecurity frameworks (e.g., SP 800-53, SP 800-171), CMMC requirements, and the safeguarding of sensitive, regulated, and export-controlled information (ITAR/EAR), and practical application of threat informed defense models (MITRE ATT&CK/D3FEND/SPARTA).
Skills
- Passion for space and the mission
- Entrepreneurial, growth mindset
- High EQ and ability to collaborate within teams and cross-functionally
- Tech-solutioning in using systems and tools to move smarter and faster
Work Environment
Generally, an office environment, but can involve inside or outside work depending on the task. This position may require access to export controlled technical data or technology subject to NASA regulations, International Traffic in Arms Regulations (ITAR), or Export Administration Regulations (EAR).
Work may involve sitting or standing for extended periods (90% of the time) and may require lifting and carrying up to 25 lbs. (5% of the time). Standard office equipment (PC, phone, printer, etc.) will be used.