> Markdown version of [/jobs/ext/184478-director-of-it-information-security](https://www.wearedevelopers.com/jobs/ext/184478-director-of-it-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of IT & Information Security - **Company:** Hidden Level - **Location:** East Syracuse, NY, United States - **Experience:** Expert - **Salary:** $138,000.0 - $179,000.0 - **Contract:** Permanent contract - **Skills:** Business Software, Business Systems, Cyber Security, Digital Forensics, Disaster Recovery, Identity and Access Management, Information Security Management, Information Technology Operations, Security Information and Event Management, Software Vulnerability Management, Data Logging, Cloud Platform System, System Availability, SC Clearance, Information Technology - **Published:** May 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c3385b570e6627b5 ## About the Role Do you have experience in Team leadership?, * Strong leadership presence with the ability tooperatein both strategic and hands-on capacities. * Ability to build scalable processes, accountability, and operational discipline. * Strong prioritization, decision-making, and problem-solving skills. * Cross-functional collaboration across Operations, Engineering, Supply Chain, Program Management, Contracts & Legal, and Executive Leadership. * Commitment to cybersecurity, compliance, continuous improvement, and enterprise service delivery., * 15+ years of progressive experience across IT operations, cybersecurity, infrastructure, and compliance leadership with at least 8 years in a regulated environment. * Proven experience managing enterprise IT infrastructure, cloud environments, applications, and security operations. * Hands-on experience with NIST SP 800-171 and/or CMMC compliance. * Experience in a regulated environment such as DoD, aerospace, defense contracting, or similar. * Experienced people leader withdemonstratedexperience across both operational IT and cybersecurity functions. * Active U.S. Secret clearance preferred; ability to obtain andmaintaina clearancerequired. * Strong communicationskills with the ability to translate technical and security risks into business impact., * CISSP, CISM, or equivalent cybersecurity certification and/or experience. * Experience with ERP systems and enterprise business applications. * Familiarity with ISO9001, vulnerability management, and secure infrastructure practices. * Experience working in classified or air-gapped environments. ## Description The Director of IT & Information Security is responsible for leading Hidden Level's Information Technology (IT) function and information security program. This role ensures that enterprise systems, infrastructure, applications, and support services are reliable, secure, scalable, and aligned with business priorities. This position oversees IT operations, cybersecurity, incident management, change management, security response, and compliance with applicable U.S. Department of Defense (DoD) cybersecurity requirements, including National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Defense Federal Acquisition Regulation Supplement (DFARS), and Cybersecurity Maturity Model Certification (CMMC). This is a hands-on leadership role requiring both operational execution and strategic direction to support a growing enterprise organization. This role is critical to ensuring Hidden Level's operational continuity, cybersecurity posture, compliance readiness, and enterprise technology maturity as the company supports national security missions., Onsite, Syracuse, NY - This role requires frequent travel to multiple locations in the Syracuse area and may include occasional travel to Washington, DC. Organizational Scope & Reporting: * The Director of IT & Information Security is responsible for leading Hidden Level's Information Technology (IT) function and information security program. This role ensures that enterprise systems, infrastructure, applications, and support services are reliable, secure, scalable, and aligned with business priorities. * This position oversees IT operations, cybersecurity, incident management, change management, security response, and compliance with applicable U.S. Department of Defense (DoD) cybersecurity requirements, including National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, Defense Federal Acquisition Regulation Supplement (DFARS), and Cybersecurity Maturity Model Certification (CMMC). * This is a hands-on leadership role requiring both operational execution and strategic direction to support a growing enterprise organization. Responsibilities: IT Operations & Infrastructure * Lead enterprise IT operations, including infrastructure, applications, support services, cloud systems, and business systems. * Own Incident Management, Change Management, and Security Response processes, providing both strategic oversight and hands-on leadership during operationally significant or high-impact events. * Ensure system availability, reliability, scalability, and operational resilience. * Develop and manage IT budgets, vendor relationships, infrastructure planning, and technology roadmaps. * Lead and develop IT personnel and/or managed service providers. * Support facility expansion, business transformation initiatives, and enterprise growth. Information Security & Cybersecurity * Develop, implement, and maintain the company's information security program. * Lead cybersecurity operations including vulnerability management, monitoring, incident response, audit readiness, and risk management. * Oversee implementation of security controls, system hardening, access management, logging, Security Information and Event Management (SIEM), and endpoint protection. * Provide cybersecurity leadership and guidance to the Information Systems Security Manager (ISSM) and broader IT organization. * Assess and communicate cybersecurity risks to leadership and stakeholders. * Support enterprise resilience and security operations, including disaster recovery, digital forensics, insider threat, and compliance-related activities. CMMC, Compliance & Governance * Accountable for overall CMMC readiness and certification efforts, with execution led in partnership with the ISSM and supported through established governance, audit oversight, and separation of duties controls. * Ensure compliance with NIST SP 800-171, DFARS, and applicable contractual or regulatory requirements. * Oversee maintenance of System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), security policies, and audit documentation. * Coordinate internal and external audits, assessments, remediation activities, and customer security reviews. * Support the Cybersecurity Governance Committee and provide executive-level reporting on cybersecurity posture, risks, incidents, and remediation progress. * Oversee third-party and supplier security risk management. * Maintainappropriate governance, risk visibility, and separation of duties across IT and cybersecurity functions. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)