Director of Information Security and Compliance

MATRIX
Cleveland, OH, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Compensation
$98,000.0 - $165,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Software System Penetration Testing Cyber Security Information Systems DevOps Information Systems Security Architecture Professional Key Management Security Information and Event Management Software Vulnerability Management Data Processing Information Technology
+3 more
Integration Frameworks RSA Archer Platform Vulnerability Analysis

Job description

We are seeking a dynamic and strategic Director of Information Security and Compliance to lead our organization’s information security structure and ensure adherence to regulatory standards. As a hands-on player-coach, this role involves developing comprehensive security frameworks, managing risk assessments, overseeing compliance programs, and guiding a talented team dedicated to safeguarding our IT infrastructure. The Director owns Matrix’s overall security strategy, regulatory compliance posture, and executive-level risk reporting.

Matrix serves prosecutors, courts, law enforcement, and state agencies in highly regulated environments. The Director is the senior leader accountable for ensuring Matrix continues to meet - and exceed - the security expectations of those clients, the auditors who certify our systems, and the standards (CJIS, NIST 800-53, SOC 2, GovRAMP, FedRAMP, and emerging state and federal requirements) that govern them.

To be successful, you should bring both strategic vision and hands-on technical depth. You should be comfortable presenting risk and roadmap to executive leadership one day and executing a control implementation, audit response, or incident response the next. You should have excellent judgment, strong written and verbal communication, and a willingness to build a function from the ground up.

This position reports to the Chairman and Chief Software Architect. The Director is expected to build and lead a dedicated security team as the function matures.

Responsibilities

  • Develop, own, and execute Matrix’s information security strategy and multi-year roadmap.
  • Lead Matrix’s SOC 2 audit program end-to-end, including scoping, evidence collection, auditor coordination, control testing, and remediation.
  • Manage Matrix’s NIST 800-53 program and maintain ongoing alignment with the applicable baseline and any client-driven control overlays.
  • Maintain Matrix’s CJIS Security Policy compliance and serve as the senior point of contact for state and federal CJI compliance matters.
  • Define, measure, and report security KPIs, risk posture, and program progress to executive leadership on a recurring cadence.
  • Maintain Matrix’s security policy library, including access control, incident response, vulnerability management, vendor risk, change management, and data handling.
  • Lead vulnerability management, penetration testing, threat modeling, and security review for both cloud and on-premise customer deployments.
  • Own incident response planning, tabletop exercises, live response coordination, post-incident review, and required notifications.
  • Define and oversee security tooling strategy (SIEM, EDR, vulnerability scanning, secrets management, identity, DLP) in partnership with Infrastructure and DevOps.
  • Conduct security reviews of architecture, third-party integrations, and procurement to ensure Matrix products and operations are secure by design.
  • Partner with Engineering and DevOps on secure SDLC, code and dependency scanning, secrets handling, and developer security enablement.
  • Own client-facing security artifacts, including security questionnaires, RFP security responses, attestations, and the Matrix trust narrative.
  • Stay current on the evolving threat landscape, emerging compliance requirements, and justice-sector security expectations; translate them into actionable internal change.
  • Recruit, develop, and lead Matrix’s information security team as the function grows.

Requirements

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or equivalent experience.
  • CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or equivalent certification is required.
  • 6+ years of cybersecurity and/or information security experience
  • Hands-on experience implementing and maintaining NIST 800-53 controls; familiarity with the moderate baseline.
  • Demonstrated ownership of SOC 2 (Type II) audits, including audit coordination, evidence management, and remediation.
  • Proven experience in developing system security plans, managing enterprise cybersecurity programs within complex IT environments, and securing AWS cloud environments and Windows-based application stacks.
  • Experience implementing programs using GRC Platforms i.e. Vanta, Drata.
  • Track record of building, maturing, or significantly upgrading a security function
  • Comfortable operating as a player-coach: setting strategy at the executive level while still performing hands-on technical work., * This position requires an FBI background investigation and U.S. citizenship upon hire. Can you meet these requirements?

Education:

  • Bachelor’s (Preferred)

Experience:

  • cybersecurity and/or information security: 6 years (Required)

License/Certification:

  • CISSP, CISM, or equivalent certification (Required)

Work Location: Hybrid remote in Cleveland, OH 44145

Benefits & conditions

Pulled from the full job description

  • Professional development assistance
  • Tuition reimbursement
  • Parental leave
  • 401(k)
  • Health insurance
  • Retirement plan
  • 401(k) matching, * 401(k)
  • 401(k) matching
  • Dental insurance
  • Health insurance
  • Health savings account
  • Paid time off
  • Parental leave
  • Professional development assistance
  • Retirement plan
  • Tuition reimbursement
  • Vision insurance

About the company

Matrix Pointe Software is a rapidly growing entrepreneurial Cleveland-based software company that provides enterprise software tailored for federal, state and local government agencies across the justice system, such as prosecutor’s offices, law enforcement agencies, administrative bodies, and civil law departments. Committed to delivering innovative technology solutions, we focus on connecting justice partners, streamlining workflows, and enhancing outcomes through our robust platforms.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all