Senior Director Enterprise IT & Cybersecurity Operations
About the Role
The Senior Director, Corporate IT & Cybersecurity Operations serves as Lynker Corporation's senior-most functional leader for enterprise information technology infrastructure, cybersecurity, and technology governance. This position is integral to the Company's ability to operate as a compliant, resilient, and mission-capable Government contractor across civilian, defense, and national security markets. The incumbent owns the design, implementation, and continuous improvement of IT and cybersecurity programs aligned to CMMC 2.0, CMMI, FAR, and DFARS requirements, and is accountable for the confidentiality, integrity, and availability of Lynker's enterprise systems. Prior experience supporting a Government Contracting Organization or a Government Agency is a plus. Prior Military service is highly desired.
Responsibilities
- IT Infrastructure Management
- Direct the design, deployment, administration, and lifecycle management of Lynker's Cloud-based IT infrastructure, including endpoints, identity and access management, and enterprise collaboration platforms (e.g., Microsoft 365 GCC High).
- Establish infrastructure standards, capacity planning, patch management, and change control processes that support both civil and future defense-sector operational requirements.
- Oversee help desk/service desk operations and ensure service level agreements (SLAs) meet internal customer and contract-driven expectations.
- Maintain the enterprise architecture roadmap, ensuring interoperability across core systems, including ADP Workforce Now, iCIMS, Jira Service Management, and Microsoft Dynamics Business Central.
- Cybersecurity, Governance & Regulatory Compliance
- Own and continuously mature Lynker's cybersecurity program in accordance with CMMC 2.0 (Levels 1-2, with readiness planning toward Level 3 where contractually indicated), NIST SP 800-171, and NIST SP 800-172 control families.
- Serve as (or directly oversee) the Information System Security Officer (ISSO) function, including maintenance of the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting body of evidence for assessments.
- Ensure compliance with applicable FAR and DFARS clauses governing safeguarding of covered defense information, cyber incident reporting, and supply chain risk management.
- Apply CMMI-aligned process discipline to IT service management, change management, and systems governance, in coordination with Quality Assurance.
- Develop, publish, and maintain enterprise IT and cybersecurity policy instruments (e.g., Acceptable Use, Access Control, System & Communications Protection, Equipment Responsibility, Generative AI Acceptable Use).
- Risk Management, Business Continuity & COOP
- Enterprise risk mitigation: Identify, assess, and remediate technology and cybersecurity risk across the enterprise; maintain a risk register and report residual risk to Executive Leadership.
- Continuity of Operations (COOP): Own, test, and maintain COOP and disaster recovery plans, including backup/recovery architecture, tabletop exercises, and after-action reporting, to ensure mission-critical continuity of federal contract performance.
- Incident response: Lead the enterprise cybersecurity incident response program, including detection, containment, remediation, and regulatory/contractual notification obligations (e.g., DFARS 252.204-7012 incident reporting).
- Insider threat: Maintain an insider threat awareness and monitoring capability appropriate to Lynker's contract portfolio and clearance posture.
- Systems Decision Analysis Report (DAR) Ownership & Approval
- Serve as the enterprise owner and final internal approval authority for Decision Analysis Reports (DARs) governing new or replacement internal systems, tools, and platforms.
- Establish and administer a standardized DAR methodology (requirements definition, alternatives analysis, total cost of ownership, security/compliance scoring, and recommendation) for use enterprise-wide.
- Ensure DAR outcomes are documented, retained, and traceable to subsequent procurement, implementation, and audit activity.
- Enterprise Systems Implementation & Lifecycle Management
- Lead end-to-end implementation of enterprise systems (HRIS, ATS, CRM, ERP, ITSM, and related platforms), from requirements gathering and vendor selection through configuration, data migration, testing, cutover, and post-implementation stabilization.
- Establish project governance for major technology initiatives and ensure alignment with budget, schedule, and compliance obligations.
- Manage the full software and systems lifecycle, including periodic evaluation of tools for renewal, replacement, or retirement.
- Mandatory Training Program Administration
- Partner with Lynker’s Facility Security Officer (FSO), deploy, and track completion of mandatory cybersecurity awareness, insider threat, acceptable use, and role-based technical training required by CMMC, DFARS, and Lynker policy.
- Partner with Human Resources to integrate IT and cybersecurity training into new-hire onboarding, annual refresher cycles, and role-change triggers, and to maintain auditable completion records.
- Onboarding & Offboarding IT Artifact Management
- Own the technology components of employee onboarding and offboarding, including provisioning/de-provisioning of accounts, hardware issuance and recovery, access certification, and Company asset accountability.
- Ensure timely and auditable offboarding artifact completion (access revocation, data retention/disposition, equipment return) in coordination with Human Resources and Security, consistent with CMMC access control requirements.
- Cross-Functional Governance Partnership
- Partner with Human Resources on workforce technology needs, policy development, and compliance training administration.
- Partner with Contracts on cybersecurity clause flow-down, technology-related proposal content, and customer data handling requirements.
- Partner with Finance on IT/cybersecurity capital and operating budget planning, cost allocation, and technology-related indirect rate considerations.
- Partner with Quality Assurance to align IT governance with Lynker's CMMI-based process improvement framework.
- Partner with Executive Leadership to translate cybersecurity and technology risk into business terms and to inform strategic decisions regarding DoD and national security market expansion.
- Artificial Intelligence Platform Governance & Oversight
- Platform ownership: Serve as the enterprise owner of all generative AI and machine learning platforms and accounts used by Lynker personnel, including vendor selection, licensing, provisioning, and decommissioning.
- Acceptable use enforcement: Administer and enforce the Generative AI Acceptable Use Policy (POL-IT-AI-001), including data classification boundaries for permissible AI input, prohibited use cases, and CUI/FCI handling restrictions.
- Utilization monitoring: Maintain visibility into organizational AI utilization patterns, account-level access, and third-party data processing terms, and report material AI-related risk.
- Governance framework: Establish an AI governance framework encompassing model/vendor risk assessment, human-in-the-loop review requirements, intellectual property and export-control considerations, and alignment with emerging federal AI acquisition and use guidance.
- Systems Auditing & Periodic Review
- Establish and execute a recurring internal audit cadence for enterprise systems, access controls, configuration baselines, and security control effectiveness, independent of any external CMMC assessment cycle.
- Report audit findings, corrective action status, and residual risk on a defined periodic basis (at minimum quarterly, or as contractually required).
- Maintain audit evidence retention practices sufficient to support external assessments, customer audits, and Defense Contract Audit Agency (DCAA) or Defense Contract Management Agency (DCMA) inquiries as applicable.
- Additional Duties
- Own vendor and contract management for managed service providers (MSP/MSSP), software publishers, and technology resellers, including SLA enforcement and cyber-insurance-related control attestations.
- Develop and manage the annual IT and cybersecurity budget; forecast capital expenditures for infrastructure refresh and compliance-driven investment.
- Maintain data governance standards.
- Serve as a technology subject matter expert during proposal development, customer security assessments, and merger/acquisition or teaming due diligence.
- Liaise with facilities/physical security functions on badge access, visitor control, and physical safeguards supporting logical security requirements.
- Represent Lynker in customer, teammate, and industry cybersecurity forums.
- Perform other duties as assigned consistent with the scope and seniority of the role.
- Supervisory Responsibilities
- Manages the IT Infrastructure and Cybersecurity function, including direct or matrixed oversight of systems engineers/administrators, cybersecurity analysts, service desk personnel, and third-party managed service providers.
- Responsible for staff hiring, performance management, professional development, and succession planning within the function.
Requirements
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field; equivalent experience considered in lieu of degree.
- Minimum of ten (10) to fifteen (15) years of progressive information technology and cybersecurity leadership experience, with substantial tenure managing IT/cybersecurity functions within Government contracting (GovCon) organizations supporting 500 to 1000 staff.
- Demonstrated hands-on experience implementing and maturing CMMC 2.0 Level 2 (or higher) compliance programs, including SSP and POA&M ownership.
- Working mastery of FAR, DFARS cybersecurity clauses, NIST SP 800-171, and NIST SP 800-172.
- Demonstrated experience owning enterprise systems governance, including DAR/decision-analysis processes and IT capital planning.
- Experience developing and executing COOP and disaster recovery plans in a contract-performance-critical environment.
- Experience administering regulated cloud environments (e.g., Microsoft 365 GCC High or equivalent).
- Proven vendor, contract, and budget management experience.
- Strong executive presence and communication skills, with demonstrated success partnering across Human Resources, Contracts, Finance, Quality Assurance, and Executive Leadership.
Preferred Qualifications
- Master's degree in a related discipline or 15-20 years of experience in