Senior Director, Cybersecurity & Enterprise Infrastructure
About the Role
The Senior Director, Cybersecurity & Enterprise Infrastructure is the accountable leader for the security, resilience, and technical foundation of Rimkus's technology estate. Reporting to the Chief Transformation Officer, this leader owns enterprise cybersecurity, cloud and hybrid infrastructure, endpoint and identity platforms, the enterprise data platform, the technology integration of acquired businesses, and the compliance and audit program that evidences all of it. This is a leader-of-leaders role, directing a multidisciplinary organization of infrastructure engineers, data engineers, systems and security staff, and the IT systems director function.
Rimkus operates in a client environment where confidentiality, privileged information, and defensible data handling are core to the business. As a private-equity-backed, acquisitive professional services firm, the company is subject to sponsor-directed security assessments, client due diligence, and formal audit expectations while simultaneously acquiring and integrating businesses on a recurring basis. Cybersecurity is the center of gravity for this role, and every acquisition either strengthens or dilutes it. The position carries an explicit mandate to standardize, consolidate, and modernize rather than merely operate.
Scope & Organizational Context
- Security ownership: Accountable cybersecurity leader, including security strategy, security operations, incident response, and the formal compliance and audit program. Owns the technology compliance control library and evidence readiness.
- Technical breadth: Microsoft Entra ID and M365 E5 identity estate, Azure and hybrid infrastructure, network and remote access, endpoint and device management, backup/DR, the enterprise data and analytics platform, and enterprise applications infrastructure.
- Organizational mandate: Rebuild depth and continuity following the departure of long-tenured technical staff. Eliminate key-person dependency through documentation, cross-training, hiring, and automation.
- Transformation mandate: Consolidate and standardize a technology estate grown through acquisition by retiring redundant platforms, unifying identity and endpoint management, and establishing a repeatable integration playbook.
- Inorganic growth: Own the technology and security workstream across the full deal lifecycle—pre-LOI and confirmatory diligence, Day 1 readiness, post-close integration, and platform rationalization.
- Stakeholders: Executive leadership, Transformation organization, Corporate Development, private-equity sponsor’s technology operating team, Legal and Risk, Compliance, Finance, HR, business-line and acquired-entity leadership, clients, and external assessment, audit, and managed-service partners.
Responsibilities
Cybersecurity Strategy & Leadership
- Own enterprise cybersecurity strategy, target-state architecture, and a funded multi-year roadmap aligned to business risk and growth.
- Serve as the accountable security leader: maintain the security policy set, the enterprise risk register with quantified business impact, and documented risk-acceptance decisions.
- Establish and chair a security governance forum; report posture, risk trend, and remediation progress to executive leadership, the Board, and the private-equity sponsor.
- Lead and coordinate independent security assessments, penetration tests, and sponsor-directed reviews; own the remediation plan and evidence package.
- Own client-facing security due diligence, security questionnaires, contractual security terms, and cyber insurance underwriting responses.
- Build and operate a security awareness, phishing simulation, and role-based training program with measured behavioral outcomes.
- Set the security investment strategy: extract full value from licensed entitlements before adding tooling; justify new spend with quantified risk reduction.
Identity & Access Management
- Own Microsoft Entra ID architecture, hybrid identity, and the M365 tenant identity security model end-to-end.
- Design, govern, and change-control Conditional Access; replace app-by-app policy sprawl with a documented, tenant-wide baseline plus a governed exception register.
- Drive universal multifactor authentication to full coverage and adopt phishing-resistant methods (FIDO2/passkeys, Windows Hello for Business, certificate-based authentication).
- Eliminate legacy authentication protocols enterprise-wide and migrate dependencies to OAuth 2.0 and modern authentication.
- Implement and operate Privileged Identity Management: just-in-time elevation, approval workflow, time-bound roles, session justification, and recurring access reviews.
- Govern trusted network locations and remote-access trust assumptions; ensure privileged access paths are explicitly controlled.
- Own service principal, enterprise application, and OAuth consent governance: least-privilege API permissions, admin-consent workflow, and credential rotation.
- Establish identity lifecycle automation (joiner/mover/leaver), entitlement and access reviews, guest and external-collaboration governance, and elimination of shared/generic accounts.
- Harden credential standards: minimum length, breach-password correlation, rotation policy, and group-managed service accounts for service identities.
Security Operations, Threat Detection & Incident Response
- Own SIEM and security analytics (Microsoft Sentinel): data-source onboarding, retention, detection engineering, tuning, and ingestion cost management.
- Validate detection coverage against MITRE ATT&CK and close gaps across initial access, credential access, persistence, privilege escalation, lateral movement, and exfiltration.
- Own the Microsoft Defender XDR stack with defined triage SLAs by severity and a managed, non-aging alert queue.
- Establish continuous (24×7) monitoring coverage, in-house or through a managed detection and response partner, with defined escalation paths and on-call rotation.
- Author, socialize, and test the incident response plan and playbooks for scenarios including credential exposure, business email compromise, ransomware, insider data theft, and third-party breach.
- Run tabletop and purple-team exercises at least annually; drive after-action findings to closure.
- Lead investigation and containment during live incidents: forensic triage, evidence preservation, and coordination with Legal, HR, Communications, outside counsel, insurers, and law enforcement.
- Own identity threat detection and response, including credential-exposure response, risky-identity remediation, and token-theft defense.
- Own vulnerability and patch management, external attack surface monitoring, secure configuration baselines, and remediation SLAs by severity.
- Own the insider risk and data loss prevention program: data classification, sensitivity labeling, and monitoring/enforcement against removable-media exfiltration, mass download, and sharing to personal accounts.
Cloud & Enterprise Infrastructure
- Direct Azure and hybrid cloud strategy: landing zone and subscription governance, network topology, identity and RBAC model, Key Vault and secrets management, Azure Policy, Defender for Cloud, and Well-Architected reviews.
- Own infrastructure-as-code and configuration management; move change execution from manual console work to automated, peer-reviewed, auditable pipelines.
- Oversee network, firewall, SD-WAN, DNS and email security, and remote access across all offices; modernize VPN architecture toward zero-trust network access and segmentation.
- Own data center, virtualization, storage, and the remaining on-premises footprint, including cloud migration and legacy platform exit plans.
- Own backup, immutable and air-gapped recovery, disaster recovery, and business continuity; define, test, and evidence RTO and RPO for every critical system.
- Own the Microsoft 365 estate—Exchange Online, SharePoint/OneDrive, Teams—and Copilot/AI readiness including data-governance prerequisites.
- Own ITSM discipline: change, incident, and problem management, capacity planning, availability and service-delivery SLAs, and published operational metrics.
Endpoint, Device Trust & Modern Workplace
- Own endpoint management (Intune, Autopilot, and co-managed configuration manager estate); consolidate legacy management paths and retire duplicate tooling.
- Raise device compliance above target and extend compliant-device Conditional Access to all users and workloads.
- Enforce full-disk encryption, EDR coverage, application control, and patch compliance across Windows, macOS, iOS, and Android.
- Own the end-user computing experience, service desk performance, and the quality of onboarding and offboarding execution.
Data Engineering & Analytics Platform
- Lead the data engineering function: pipeline and integration architecture, orchestration, warehouse/lakehouse platform, and business intelligence delivery.
- Establish data governance—ownership, classification, lineage, retention, and quality standards—in partnership with Legal, Compliance, and business lines.
- Secure the data platform: least-privilege and row/column-level access, managed identities and secrets management, encryption in transit and at rest.
- Partner with business leadership to deliver reporting and analytics products that improve client delivery, utilization, and operational decision-making.
- Govern AI and machine learning adoption, including acceptable-use standards, data-protection controls, and review of AI-connected data surfaces.
Compliance, Audit & Risk Governance
- Own the technology compliance program mapped to NIST Cybersecurity Framework and NIST 800.