Director of Information Security & Compliance

Resources, Inc
Doylestown, PA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$90,000.0 - $120,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Firewall Cloud Computing Cloud Computing Security Cyber Security Network Security Security Information and Event Management Software Vulnerability Management Information Technology

Job description

We are seeking an experienced Director of Information Security & Compliance to lead and strengthen our cybersecurity, risk management, and regulatory compliance programs. This role will be responsible for developing security strategy, ensuring compliance with federal and industry standards, and protecting enterprise systems, networks, and cloud infrastructure., * Develop and execute the organization’s information security strategy.

  • Lead cybersecurity, risk management, incident response, and business continuity initiatives.
  • Manage compliance programs including SOC 2, FedRAMP, NIST, and related security frameworks.
  • Oversee cloud security architecture and governance within Gov Cloud
  • Direct firewall strategy, network security controls, and vulnerability management programs.
  • Conduct security risk assessments and implement remediation plans.
  • Collaborate with executive leadership on security posture, compliance requirements, and risk mitigation.
  • Manage third-party security assessments and vendor risk programs.
  • Develop and maintain security policies, procedures, and training programs.
  • Lead internal and external audits and support regulatory compliance initiatives.

Requirements

Do you have experience in Stakeholder management?, Do you have a Bachelor’s degree?, The ideal candidate will have extensive experience with SOC 2, FedRAMP, firewall administration, Gov Cloud , and security governance frameworks. Experience with CMMC (Cybersecurity Maturity Model Certification) is highly desirable., * Bachelor’s degree in Information Security, Computer Science, Information Technology, or related field.

  • 8+ years of progressive information security experience, including leadership responsibilities.
  • Demonstrated experience leading or supporting FedRAMP compliance initiatives.
  • Strong experience with SOC 2 (Service Organization Control) audits and compliance programs.
  • Extensive knowledge of firewall technologies, network security, and cybersecurity best practices.
  • Hands-on experience with Gov Cloud security and administration.
  • Strong understanding of NIST 800-53, risk management frameworks, and security governance.
  • Excellent leadership, communication, and stakeholder management skills.

Preferred Qualifications

  • Experience with CMMC (Cybersecurity Maturity Model Certification) programs.
  • Professional certifications such as CISSP, CISM, CISA, CCSP, or similar.
  • Experience supporting government contractors or highly regulated industries.
  • Familiarity with vulnerability management, SIEM platforms, and cloud security tools.

Benefits & conditions

  • Competitive salary and bonus opportunity.
  • Comprehensive benefits package.
  • Flexible work environment.
  • Opportunity to build and lead enterprise security programs.
  • High visibility with executive leadership and strategic initiatives.

Pay: $90,000.00 - $120,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

1:16 min

Securing internal pod communication with network security policies

Marc Nimmerrichter · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all