> Markdown version of [/jobs/ext/565687-director-of-information-security-compliance](https://www.wearedevelopers.com/jobs/ext/565687-director-of-information-security-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security & Compliance - **Company:** Resources, Inc - **Location:** Doylestown, PA, United States - **Experience:** Expert - **Salary:** $90,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Application Firewall, Cloud Computing, Cloud Computing Security, Cyber Security, Network Security, Security Information and Event Management, Software Vulnerability Management, Information Technology - **Published:** June 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2667ec268dba417d ## About the Role Do you have experience in Stakeholder management?, Do you have a Bachelor's degree?, The ideal candidate will have extensive experience with SOC 2, FedRAMP, firewall administration, Gov Cloud , and security governance frameworks. Experience with CMMC (Cybersecurity Maturity Model Certification) is highly desirable., * Bachelor's degree in Information Security, Computer Science, Information Technology, or related field. * 8+ years of progressive information security experience, including leadership responsibilities. * Demonstrated experience leading or supporting FedRAMP compliance initiatives. * Strong experience with SOC 2 (Service Organization Control) audits and compliance programs. * Extensive knowledge of firewall technologies, network security, and cybersecurity best practices. * Hands-on experience with Gov Cloud security and administration. * Strong understanding of NIST 800-53, risk management frameworks, and security governance. * Excellent leadership, communication, and stakeholder management skills. Preferred Qualifications * Experience with CMMC (Cybersecurity Maturity Model Certification) programs. * Professional certifications such as CISSP, CISM, CISA, CCSP, or similar. * Experience supporting government contractors or highly regulated industries. * Familiarity with vulnerability management, SIEM platforms, and cloud security tools. ## Description We are seeking an experienced Director of Information Security & Compliance to lead and strengthen our cybersecurity, risk management, and regulatory compliance programs. This role will be responsible for developing security strategy, ensuring compliance with federal and industry standards, and protecting enterprise systems, networks, and cloud infrastructure., * Develop and execute the organization's information security strategy. * Lead cybersecurity, risk management, incident response, and business continuity initiatives. * Manage compliance programs including SOC 2, FedRAMP, NIST, and related security frameworks. * Oversee cloud security architecture and governance within Gov Cloud * Direct firewall strategy, network security controls, and vulnerability management programs. * Conduct security risk assessments and implement remediation plans. * Collaborate with executive leadership on security posture, compliance requirements, and risk mitigation. * Manage third-party security assessments and vendor risk programs. * Develop and maintain security policies, procedures, and training programs. * Lead internal and external audits and support regulatory compliance initiatives. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)