> Markdown version of [/jobs/ext/1486777-director-of-cybersecurity-architecture-and-engineering](https://www.wearedevelopers.com/jobs/ext/1486777-director-of-cybersecurity-architecture-and-engineering). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Cybersecurity, Architecture and Engineering - **Company:** The Center for Toxicology and Environmental Health, L.L.C. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $195,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, E-Business, Identity and Access Management, Information Systems Security Architecture Professional, Network Architecture, Network Segmentation, Security Information and Event Management, Software Vulnerability Management, Firewalls (Computer Science), Information Technology, Vulnerability Analysis - **Published:** July 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fdbf0a972db9ed70 ## About the Role * 10+ years of progressive information security experience, including hands-on tool engineering and team leadership * Bachelor's degree in Computer Science, Information Systems, or a related field * Demonstrated experience managing or technically partnering with a managed security services provider (MSSP) for SOC/NOC functions * Experience supporting CMMC and/or NIST SP 800-171 / 800-53 control implementation in partnership with a GRC or compliance function * Deep technical knowledge across core security tooling categories: next-generation firewalls, EDR, SIEM, WAF, vulnerability management platforms, and security awareness platforms * Strong understanding of network architecture, segmentation, and security concepts in large-scale environments * Demonstrated ability to build, mentor, and retain a small, high-performing technical team * Knowledge of federal cybersecurity and data privacy laws, regulations, and policies applicable to a federal contractor * Strong understanding of the cybersecurity threat lifecycle, attack vectors, and intrusion set tactics, techniques, and procedures (TTPs) * Excellent cross-functional communication skills, with the ability to translate technical risk for executive audiences, * This is a remote role within the U.S. with a willingness to travel as needed * Primarily office/home-office based work; standard business hours with periodic escalation-tier on-call responsibilities outside business hours ## Description Reporting to the CISO, the Director of Cybersecurity Architecture & Engineering leads our security engineering team and is accountable for the design, implementation, and continuous improvement of our core security tooling and architecture. This role partners closely with our managed security services provider (MSSP), which delivers 24/7 SOC/NOC monitoring, and with our GRC team, which owns our compliance frameworks and assessments (including CMMC and NIST SP 800-171). This is a hands-on, player-coach role: the Director is expected to lead and develop a small, high-performing technical team while remaining technically capable of stepping into any tool domain when needed., To thrive in this role, you'll be comfortable taking ownership of the following responsibilities: * Lead, mentor, and develop a team of security engineers responsible for perimeter and endpoint security, detection and monitoring, and vulnerability management engineering * Serve as a hands-on technical backstop across the team's tool domains (firewall, EDR, SIEM, WAF, vulnerability management, and security awareness platforms), able to step in during absences or transitions * Own the strategic relationship with our managed security services provider (MSSP), including SLAs, escalation processes, contract performance, and renewal * Serve as the Tier 2/3 escalation point for security incidents raised by the MSSP, providing decision authority on containment, access, and asset-criticality judgment calls * Serve as the primary technical point of contact between the security engineering team and the GRC team, ensuring technical controls required for CMMC, NIST SP 800-171, and other applicable frameworks are designed, implemented, and maintained * Design and maintain security architecture standards for network segmentation, system hardening baselines, and identity and access boundaries, in partnership with the team that owns IAM * Develop and continuously refine the security engineering roadmap and technical standards in alignment with the evolving threat landscape and business risk tolerance * Define OKRs, metrics, and scorecards for the security engineering function and report on team health and risk posture to executive leadership * Partner with development and infrastructure teams to identify and remediate application- and infrastructure-level vulnerabilities * Own workforce planning for the team, including current team development and future headcount growth * Ensure the team maintains up-to-date documentation of tool ownership, backup coverage, and operational runbooks * Track developments in the digital business and threat environment to ensure they are reflected in security strategy and architecture ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)