Deputy Chief Information and Security Officer (Deputy CIO, CISO)

@orchard Llc
Alexandria, VA, United States
20 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$275,000.0 - $345,000.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Security CompTIA Security+ Cyber Security Disaster Recovery Identity and Access Management IT Management Information Technology Operations Machine Learning Zero Trust Network Access
+7 more
SAP (Applications) Software Vulnerability Management Information Technology Multiaccess Edge Computing Virtual Agents Devsecops Plan of Action and Milestones

Job description

We are seeking a strategic and highly motivated Deputy CIO/CISO to serve as a key technology architect and operational leader. In this pivotal role, you will partner directly with the CIO/CISO and Executive Leadership team to drive enterprise IT, harden their cybersecurity posture, and scale their infrastructure.

You will bridge the gap between high-level business strategy and tactical technical execution. From navigating complex federal risk frameworks (RMF, CMMC, NIST) to building scalable IT operations and supporting edge-computing platforms, you will ensure our client’s technology is secure, innovative, and mission-ready.

Your role will involve regular engagement with customers in government and commercial sectors, as a technology and security leader, tasked with articulating the unique value proposition our client brings to digital infrastructure, sovereign data, and cybersecurity

Key Responsibilities

Strategic IT & Enterprise Architecture

* Drive Scalable Infrastructure: Help define and execute enterprise IT strategy across cloud, on-premises, edge computing, and high-availability hybrid environments. * Build Operational Excellence: Design and implement IT governance, policies, and automated workflows from scratch to support rapid organizational scaling. * Ensure Business Continuity: Lead disaster recovery, data resilience, and multi-path networking strategies to guarantee 99.999% mission readiness.

Cybersecurity Leadership & Zero Trust

* Cybersecurity leadership: Partner with the CIO to develop and maintain the enterprise security program and champion cybersecurity as a critical differentiator when engaging with clients and new customers. * Champion Security Culture: Cultivate a continuous, “security-first” mindset across all engineering, product, and operational business units. Integrate cybersecurity throughout every aspect of the product lifecycle. * Architect Zero Trust: Lead vulnerability management, endpoint security, IAM, and security monitoring initiatives using cutting-edge Zero Trust principles. * Manage Cyber Incident Response: Coordinate response plans, active cyber exercises, and post-incident action reports to continuously harden the operational posture.

Artificial Intelligence as a cornerstone

  • ML/Agentic AI: Integrate Machine Learning and Agentic AI into every aspect of the business by teaming with stakeholders to analyze opportunities for greater AI adoption to drive performance. Evaluate every task to determine where AI can benefit the firm, and tasks that should remain inherently human-owned.

  • AI Engineering: Partner with R&D and Engineering teams to engineer solutions to enhance the customer’s ability to get answers quickly by leveraging agentic AI and NLP to manage queries and develop solutions.

Federal Compliance & Risk Management (RMF)

* Lead RMF & ATO Readiness: Oversee compliance efforts across NIST SP 800-37, 800-53, 800-171, CMMC, and FedRAMP frameworks to secure Authorities to Operate (ATOs). * Manage Documentation & Audits: Oversee Security Assessment Plans (SAP), Security Assessment Reports (SAR), and Plans of Action & Milestones (POA&M). * Partner with External Stakeholders: Collaborate directly with government, DoD, and enterprise customer auditors to accredit systems seamlessly.

Startup Operations & Cross-Functional Growth

* Comfort with ambiguity: Roll up your sleeves to develop operational standards, build out IT capabilities, and solve complex technical challenges on the fly. * Customer & Proposal Support: Assist in technical demonstrations, RFP/proposal development, and high-stakes executive customer briefings. * Customer Engagement: Conduct regular meetings with senior government and commercial leaders to help solve significant digital infrastructure and cybersecurity problems through the deployment of SEMPRE solutions. * Team Building: Mentor technical staff, foster cross-functional collaboration with engineering and sales, and help recruit top-tier technical talent.

Requirements

* Experience: 10+ years of progressive leadership in enterprise IT, cybersecurity, and secure infrastructure. * Education: Bachelor’s degree in Computer Science, IT, Cybersecurity, Engineering, or a related field. * Cybersecurity leadership: Proven experience developing enterprise-level cybersecurity programs, including Zero Trust Architecture, endpoint security, identity management, and security monitoring. * Compliance Expertise: In-depth working knowledge of NIST SP 800-series frameworks, CMMC requirements, and federal RMF/ATO processes. * Technical Breadth: Strong background in enterprise networking, edge computing, secure cloud platforms (AWS, Azure, or GCP), and Zero Trust Architecture. * Startup Agility: Demonstrated success building IT/security programs from scratch in fast-paced, high-growth environments. * Communication: Exceptional ability to communicate complex cybersecurity concepts to executives, engineers, and government clients alike.

Preferred Qualifications

* Advanced Degree: Master’s degree in Cybersecurity, IT, or an MBA. * Active Certifications: CISSP, CISM, CCSP, Security+, PMP, or AWS/Azure Solutions Architect. * Specialized Tech: Familiarity with EMP/RF resilience, edge AI infrastructure, DevSecOps pipelines, or defense/critical infrastructure communications.

Benefits & conditions

Compensation: The anticipated base salary range is$275,000 - $345,000. The full compensation package is determined by experience and qualifications. Our client offers a competitive benefits package to all staff members.

About the company

@Orchard LLC is supporting a rapidly growing client in their search for an experienced individual to work alongside their current CIO, covering both CIO and CISO responsibilities. This is an internal role that also engages frequently with their clients in government and commercial enterprises. Owing to the nature of our client’s customers in government, you must be cleared to a Top-Secret level (TS/SCI strongly preferred).

Our client is redefining critical infrastructure by delivering a secure digital foundation where cloud, trusted AI, advanced cybersecurity, and multi-path networking converge-all deployed over an EMP-hardened, highly resilient 5G platform. Built for ultimate simplicity and uncompromising security, their technology empowers defense, government, and commercial enterprise clients to execute critical operations, anywhere, under any conditions.

If you are a mission-first tech leader who thrives on building resilient systems from the ground up, welcome to your next mission., Established in 2010, @Orchard LLC has an exceptional reputation, providing staffing solutions to time-sensitive, talent-scarcity issues to deliver better talent management ROI. Our specialty lies in the critical area of program talent acquisition and resource management, not in one narrow skillset, but across many areas of technical and functional delivery. To learn more about our other exciting opportunities, visit our Jobs Page at www.atOrchard.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ WWC 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil ¡ LIVE

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah ¡ WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia ¡ LIVE

Videos

See all

Related articles

See all