Onsite
Full Time IT Management & IT Project Management
Responsibilities
Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response
Own IT governance, risk, and compliance
Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes
Serve as the primary IT liaison to external auditors and readiness advisors
Mature incident response and disclosure governance
Establish data classification, retention, and encryption standards
Partner on the IT/OT security boundary and with product security
Report cybersecurity and compliance posture to leadership and governance bodies
Lead, coach, and develop the cybersecurity and GRC team
Requirements
10+ years in cybersecurity and/or IT GRC
5+ years in leadership (CISO-track)
Deep ITGC experience — control design, operation, and audit
Breadth across the security program: IAM, EDR/MDR, vulnerability management, incident response
Fluency in recognized frameworks (ISO 27001, SOC 2, NIST CSF / 800-53; NIST 800-171 / CMMC a plus)
Experience as an external-audit liaison
Strong people leadership and executive‑grade communication