> Markdown version of [/jobs/ext/2034502-information-security-program-lead](https://www.wearedevelopers.com/jobs/ext/2034502-information-security-program-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Program Lead - **Company:** MSA - **Location:** Cranberry Township, PA, United States - **Experience:** Expert - **Salary:** $112,326.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cyber Security, Information Security Management, Microsoft Office, Software Engineering, Information Security Management System, Information Technology, ISO/IEC 27002 - **Published:** August 12, 2026 - **Apply:** https://www.disabledperson.com/jobs/74203331-information-security-program-lead ## About the Role * Deep understanding of ISO 27001:2022 and associated standards (e.g., ISO 27002), including practical ISMS management experience * Solid grasp of GRC methodologies, control frameworks, and structured risk assessment practices * Working knowledge of SOC 2 (Trust Services Criteria) and readiness or audit support experience * Working knowledge of CMMC 2.0 and/or NIST SP 800-171, including their application to CUI environments and U.S. federal compliance obligations * Familiarity with GDPR or equivalent data protection regulations as they apply to global enterprise operations * Experience with cross-framework control mapping across two or more of the above frameworks * Excellent written and verbal communication skills - ability to translate complex compliance topics for both technical and non-technical audiences across different cultural and organizational contexts * Proven ability to work independently and drive compliance initiatives with minimal supervision in a globally distributed team environment Preferred Skills * Hands-on experience with SOC 2 Type II audit support and evidence collection * Direct involvement in CMMC readiness activities or C3PAO-facilitated assessments * Knowledge of cloud security controls, particularly in AWS and Office 365 environments * Familiarity with AI-enhanced GRC tooling and compliance automation approaches * Understanding of TPRM frameworks, vendor risk methodologies, and associated tooling * Familiarity with SSDLC principles and their integration with compliance requirements * Experience working across multiple time zones and jurisdictions in a multinational organization, * Bachelor's degree in Computer Science, Information Security, or a relevant field * Demonstrated experience leading or supporting ISO 27001 certification or re-certification audits * Experience developing and implementing security policies and controls across multiple frameworks * Experience conducting structured risk assessments and managing risk treatment plans in complex, multi-jurisdictional environments, * ISO 27001 Lead Auditor or Lead Implementer certification (e.g., PECB, BSI, or equivalent) * Master's degree in Computer Science, Information Security, or a relevant field * Additional certifications such as CISM, CISA, CISSP, or ISO 27005 Risk Manager * Certifications or formal training in CMMC, NIST, or SOC 2 methodologies * Experience working in or supporting regulated industries subject to U.S. government compliance requirements #LI-KH2 ## Description ISMS Ownership & ISO 27001 * Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO 27001:2022 requirements and organizational objectives * Lead and coordinate internal and external ISO 27001:2022 audits, including audit planning, execution, and follow-up * Conduct gap analyses, risk assessments, and risk treatment planning in line with ISO 27001 Annex A controls * Develop, review, and maintain information security policies, standards, and procedures, * Drive and coordinate compliance activities across SOC 2 Type II, including control documentation, evidence collection, and readiness reviews in preparation for external assessments * Support CMMC 2.0 Level 2 readiness and compliance, including control implementation guidance aligned with NIST SP 800-171 and coordination for third-party assessment organization (C3PAO) engagements * Maintain working knowledge of NIST SP 800-171 requirements and their relationship to CMMC, supporting Controlled Unclassified Information (CUI) scoping and handling requirements * Ensure compliance activities reflect applicable regional data protection obligations, including GDPR and other jurisdiction-specific requirements relevant to global operations * Maintain a cross-framework control mapping to identify overlaps, reduce duplication of effort, and ensure consistent control coverage across ISO 27001, SOC 2, CMMC, and NIST Global Governance & Stakeholder Engagement * Serve as a key point of contact for external certification bodies, auditors, and regulatory inquiries * Report on the state of the ISMS, compliance posture, and key risk indicators to senior management across global business units * Contribute to security awareness programs and training initiatives, adapting content for regional and cultural relevance where needed * Collaborate with cross-functional and geographically distributed stakeholders to embed security and compliance requirements into business processes Third-Party & Engineering Collaboration * Support and collaborate with the Third-Party Risk Management (TPRM) function, providing GRC expertise on vendor risk assessments and due diligence processes * Work closely with the software development function to integrate compliance requirements into the Secure Software Development Lifecycle (SSDLC) ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)