Director, Information Security & Compliance
Role details
Job location
Tech stack
Job description
Lead CMMC Level 2 and NIST SP 800-171 compliance, cybersecurity, IT governance, and physical security for a growing 250+ person electrical contractor.
Reports To: President/CFO
???????????????????? ???????????? ????????????????
Citadel Electric Group performs commercial, industrial, and federal construction work. This newly created, hands-on leadership role will own our security and compliance program, protect our Controlled Unclassified Information environment, oversee Microsoft 365 security and configurations, supervise internal IT, manage our MSP, and maintain audit-ready evidence.
You will also own company-wide physical-security standards for facilities, controlled areas, the yard, warehouse, fleet, equipment, and active jobsites. This is not an advisory-only role. We need an accountable internal owner who will make decisions, verify execution, lead incidents, and hold internal and external resources accountable.
???????????????? ???????????? ???????????????? ????????????
???????????????????????????? ???????????????????????????????????????? ???????????? ????????????????
- Own NIST SP 800-171 compliance, SPRS assessments, CMMC Level 2 readiness, and preparation for applicable self-assessments, government assessments, and third-party assessments.
- Maintain the SSP, POA&M, CUI boundary, SPRS score, control narratives, assessment results, affirmations, and supporting evidence.
- Coordinate with federal customers, assessors, counsel, the MSP, and internal stakeholders.
- Support Citadel's obligations under DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021, as applicable.
???????????????????????????????????????????????????? ???????????? ???????????????????????????????????? ????????????
- Build and operate the cybersecurity program, including policies, risk management, incident response, security awareness, access governance, asset inventory, vendor risk, and recurring control reviews.
- Review and validate Entra ID, Conditional Access, MFA, Intune, Defender, Purview, logging, administrative roles, endpoint security, and data-protection controls.
- Identify weaknesses, direct remediation, and challenge the MSP when configurations, documentation, responsiveness, or recommendations do not meet Citadel's requirements.
???????????????????????????????? ????????????????????????????????
- Own access control and badging, visitor management, surveillance and CCTV, intrusion detection, alarms, monitoring, controlled-area requirements, and physical protection of sensitive information and IT assets.
- Establish physical-security standards for the yard, warehouse, equipment storage, fleet, vehicles, and active jobsites.
- Coordinate implementation and incident response with Operations, Safety, project leadership, and outside vendors.
???????? ???????????????????????????????????????? ???????????? ???????????????????????????????? ????????????????????????????????
- Create and maintain an annual IT and cybersecurity roadmap and help prioritize budget, lifecycle, backup and recovery, logging, endpoint, identity, network, and infrastructure decisions.
- Ensure material technology changes are reviewed, approved, tested, documented, and tied to business risk.
- Lead cybersecurity incidents and significant IT-risk events through triage, containment, investigation, recovery, root-cause analysis, corrective action, executive communication, and required reporting.
????????????????????????????????, ????????????????????, ???????????? ????????????????????????????
- Own the compliance evidence repository and documentation standards for internal IT, the MSP, vendors, and control owners.
- Directly supervise Citadel's IT team
- Own the MSP relationship as a security and engineering partnership and hold vendors accountable for outcomes, responsiveness, documentation, and secure execution., Travel is primarily local and during the business day, with occasional out-of-area or overnight travel for project sites, federal-customer engagements, vendor meetings, training, and CMMC assessment activities.
Requirements
- Eight or more years of progressive experience in cybersecurity, information security, IT infrastructure, compliance, or risk management, including at least three years in a senior, lead, supervisory, or management capacity.
- Direct experience leading or materially supporting CMMC Level 2, NIST SP 800-171, DFARS cybersecurity requirements, SPRS assessments, DIBCAC reviews, C3PAO assessments, or comparable federal-contractor readiness work.
- Working knowledge of NIST SP 800-171 and familiarity with NIST SP 800-53 and the NIST Cybersecurity Framework.
- Practical experience with Microsoft 365, Entra ID, Intune, Defender, Purview, Conditional Access, MFA, logging, and administrative security.
- Experience implementing or overseeing access control, badging, visitor management, surveillance, alarms, intrusion detection, and protection of sensitive assets.
- Experience supervising internal IT personnel, managing an MSP, or leading technical vendors through accountable delivery.
- Experience leading cybersecurity incidents or significant IT-risk events and producing defensible documentation.
- Strong plain-English communication with owners, executives, field supervisors, project teams, tradespeople, vendors, federal customers, counsel, and assessors.
- Ability to successfully complete required background screening and satisfy applicable federal-customer access requirements.
- This position may involve access to export-controlled technical data and other restricted information. The selected candidate must be able to satisfy all access requirements imposed by applicable law, regulation, executive order, or government contract.
???????????????????????????????????? ????????????????????????????????????????????????????????
- Successful CMMC Level 2 assessment experience or prior engagement with a C3PAO, DIBCAC, federal customer, or government cybersecurity assessor.
- In-house experience with a federal contractor, defense supplier, construction company, manufacturer, or engineering-services firm.
- GCC, GCC High, ITAR, or EAR experience.
- Experience building practical security programs for mid-sized operating businesses or distributed operations.
- Relevant credentials such as CISSP, CISM, CRISC, CMMC CCP, CMMC CCA, ASIS PSP, ASIS CPP, or comparable demonstrated expertise.
???????????????? ???????????????? ???????????????? ???????? ????????????
This is not a pure CIO, passive compliance, or help-desk management position. You will review configurations, validate controls, walk facilities and jobsites, lead incidents, produce evidence, make decisions, and ensure remediation is completed.
Benefits & conditions
- Competitive base salary commensurate with experience, discussed with finalists.
- Performance bonus opportunity.
- Health and dental insurance for you and your dependents, with premiums paid by Citadel.
- 401(k) with a 3% company contribution.
- Additional discretionary profit-sharing contribution that has historically been 14% of eligible compensation, subject to plan terms, eligibility requirements, company performance, and annual approval.
- Paid time off.
- Company-provided cell phone.