
Director of Cyber Security
Posted Sep 15

Posted Sep 15
This is a fully remote position, open to applicants in United States.
• Take ownership of RapidFort’s information security framework and enterprise risk management.
• Establish and verify security standards across Cloud Operations, Infrastructure Engineering, and Corporate IT environments.
• Manage the ISO 27001 Information Security Management System (ISMS) and the SOC 2 Type 2 program from start to finish.
• Lead the initiatives for FedRAMP authorization and CMMC Level 2 compliance.
• Integrate all four compliance frameworks into one unified control set, utilizing shared evidence and a single timeline.
• Present current risk assessments to the CIO, executive leadership, and Audit Committee, with the authority to escalate unresolved material risks.
• Develop and manage information security policies, control frameworks, technical standards, risk register, exception processes, and security architecture evaluations.
• Oversee security monitoring, SIEM operations, relationships with managed detection service providers, incident response, post-incident evaluations, and exercises.
• Manage vulnerability assessments, remediation service level agreements (SLAs), penetration testing, red team activities, and security testing gates in the software development lifecycle (SDLC).
• Administer access governance, privileged access protocols, access reviews, and authentication and session policies.
• Coordinate relationships with external auditors, certification bodies, agency sponsors, and estate owners.
• Supervise the compliance specialist responsible for evidence collection, control testing, POA&M tracking, and audit logistics.
• Handle customer security assurance, including questionnaires, audits, trust documentation, contract and Data Processing Agreement (DPA) security terms, and controlled distribution of audit artifacts.
• Conduct vendor and SaaS security assessments, establish security requirements in vendor contracts, and lead awareness initiatives, phishing simulations, and role-specific training programs.
• U.S. citizenship is mandatory.
• Significant experience managing enterprise security, risk, and compliance initiatives.
• Proficiency with ISO 27001 ISMS and SOC 2 Type 2 programs.
• Familiarity with FedRAMP authorization and CMMC Level 2 requirements.
• Knowledge of NIST SP 800-53 and NIST SP 800-171 standards.
• Experience in developing security policies, control frameworks, risk registers, and risk acceptance strategies.
• Background in conducting security architecture reviews and implementing technical security standards.
• Experience in security monitoring, SIEM technologies, managed detection services, and incident response.
• Proficient in vulnerability management, penetration testing, red team engagements, SAST, dependency scanning, secrets detection, and image scanning.
• Knowledge in identity and access governance, privileged access management, multi-factor authentication (MFA), conditional access, and device trust protocols.
• Experience engaging with external auditors, certification bodies, agency sponsors, and ensuring customer security assurance.
• Proficient in vendor and SaaS security assessments and establishing security contract requirements.
• Experience in developing security awareness initiatives, phishing simulation exercises, and role-specific training programs.
• Capability to act as incident commander and direct containment efforts across various environments.
• Willingness to travel occasionally for audits, customer interactions, and leadership meetings.
• Availability to participate in on-call incident commander responsibilities for declared security incidents.
• Performance-based annual bonus.
• Equity opportunities: Stock options in RapidFort.
• Comprehensive medical, dental, and vision insurance.
• 401(k) retirement plan.
• Paid time off and company-recognized holidays.
• Paid sick leave.
• Equipment provided by the company.
• Opportunities for professional development and career growth.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.