> Markdown version of [/jobs/ext/1472266-director-of-information-security-and-compliance](https://www.wearedevelopers.com/jobs/ext/1472266-director-of-information-security-and-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security and Compliance - **Company:** MATRIX - **Location:** Cleveland, OH, United States - **Experience:** Expert - **Salary:** $98,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Cyber Security, Information Systems, DevOps, Information Systems Security Architecture Professional, Key Management, Security Information and Event Management, Software Vulnerability Management, Data Processing, Information Technology, Integration Frameworks, RSA Archer Platform, Vulnerability Analysis - **Published:** July 28, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=dff62af890668a69 ## About the Role * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or equivalent experience. * CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or equivalent certification is required. * 6+ years of cybersecurity and/or information security experience * Hands-on experience implementing and maintaining NIST 800-53 controls; familiarity with the moderate baseline. * Demonstrated ownership of SOC 2 (Type II) audits, including audit coordination, evidence management, and remediation. * Proven experience in developing system security plans, managing enterprise cybersecurity programs within complex IT environments, and securing AWS cloud environments and Windows-based application stacks. * Experience implementing programs using GRC Platforms i.e. Vanta, Drata. * Track record of building, maturing, or significantly upgrading a security function * Comfortable operating as a player-coach: setting strategy at the executive level while still performing hands-on technical work., * This position requires an FBI background investigation and U.S. citizenship upon hire. Can you meet these requirements? Education: * Bachelor's (Preferred) Experience: * cybersecurity and/or information security: 6 years (Required) License/Certification: * CISSP, CISM, or equivalent certification (Required) Work Location: Hybrid remote in Cleveland, OH 44145 ## Description We are seeking a dynamic and strategic Director of Information Security and Compliance to lead our organization's information security structure and ensure adherence to regulatory standards. As a hands-on player-coach, this role involves developing comprehensive security frameworks, managing risk assessments, overseeing compliance programs, and guiding a talented team dedicated to safeguarding our IT infrastructure. The Director owns Matrix's overall security strategy, regulatory compliance posture, and executive-level risk reporting. Matrix serves prosecutors, courts, law enforcement, and state agencies in highly regulated environments. The Director is the senior leader accountable for ensuring Matrix continues to meet - and exceed - the security expectations of those clients, the auditors who certify our systems, and the standards (CJIS, NIST 800-53, SOC 2, GovRAMP, FedRAMP, and emerging state and federal requirements) that govern them. To be successful, you should bring both strategic vision and hands-on technical depth. You should be comfortable presenting risk and roadmap to executive leadership one day and executing a control implementation, audit response, or incident response the next. You should have excellent judgment, strong written and verbal communication, and a willingness to build a function from the ground up. This position reports to the Chairman and Chief Software Architect. The Director is expected to build and lead a dedicated security team as the function matures. Responsibilities * Develop, own, and execute Matrix's information security strategy and multi-year roadmap. * Lead Matrix's SOC 2 audit program end-to-end, including scoping, evidence collection, auditor coordination, control testing, and remediation. * Manage Matrix's NIST 800-53 program and maintain ongoing alignment with the applicable baseline and any client-driven control overlays. * Maintain Matrix's CJIS Security Policy compliance and serve as the senior point of contact for state and federal CJI compliance matters. * Define, measure, and report security KPIs, risk posture, and program progress to executive leadership on a recurring cadence. * Maintain Matrix's security policy library, including access control, incident response, vulnerability management, vendor risk, change management, and data handling. * Lead vulnerability management, penetration testing, threat modeling, and security review for both cloud and on-premise customer deployments. * Own incident response planning, tabletop exercises, live response coordination, post-incident review, and required notifications. * Define and oversee security tooling strategy (SIEM, EDR, vulnerability scanning, secrets management, identity, DLP) in partnership with Infrastructure and DevOps. * Conduct security reviews of architecture, third-party integrations, and procurement to ensure Matrix products and operations are secure by design. * Partner with Engineering and DevOps on secure SDLC, code and dependency scanning, secrets handling, and developer security enablement. * Own client-facing security artifacts, including security questionnaires, RFP security responses, attestations, and the Matrix trust narrative. * Stay current on the evolving threat landscape, emerging compliance requirements, and justice-sector security expectations; translate them into actionable internal change. * Recruit, develop, and lead Matrix's information security team as the function grows. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)