**Worker Type**
Regular
**Job Description**
**Company Overview**
AV is a leading defense technology company delivering mission-critical solutions to government and commercial customers. We are seeking an experienced Director of Information Security to lead our cybersecurity program and ensure the protection of sensitive national security information.
**Summary**
The Director of Information Security will lead the organization's information security program, ensuring compliance with defense industry regulations, managing information security, and supervising a team of ~5 professionals. This role requires deep expertise in defense contractor security requirements and the ability to balance rigorous security controls with operational efficiency.
**Position Responsibilities**
**Leadership & Management**
+ Lead and mentor a team of information security professionals including compliance specialists, compliance managers, and/or analysts
+ Develop and execute the information security strategy aligned with business objectives and threat landscape
+ Collaborate with executive leadership on security risk management, investment priorities, and incident response
+ Lead and write procedures on approving security exceptions,foreign travel,and deviations following established risk management frameworks
**Compliance & Risk Management**
+ Build compliance approaches for NIST SP 800-171, CMMC, DFARS, ITAR, EAR, and other defense industry information security requirements
+ Develop and maintain security policies, procedures, and standards
+ Conduct information security risk assessments and manage risk treatment plans
+ Oversee security audits, assessments, and government inspections
+ Maintain relationships with government and third party representatives
**Program Management**
+ Review and advise on continuous monitoring, compliance practices, and security automation priorities
+ Develop security metrics and reporting for leadership and government customers
+ Manage security budget and resource allocation
**Business Partnership**
+ Serve as trusted advisor to business units on security requirements
+ Facilitate security discussions with customers and partners
+ Balance security requirements with mission effectiveness and operational efficiency
+ Promote security awareness culture throughout the organization
**Basic Qualifications (Required Skills & Experience)**
**Education**
+ Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
+ Master's degree preferred
**Experience**
+ Minimum 10 years of progressive information security experience
+ Minimum 5 years in leadership role managing security teams
+ Minimum 5 years working in defense contractor or government environment
+ Experience managing security programs supporting classified systems and information
+ Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance
**Technical Knowledge**
+ Expert knowledge of NIST SP 800-171, CMMC 2.0, and DFARS cybersecurity requirements
+ Working knowledge of NIST Cybersecurity Framework, ISO 27001/27002, and CIS Controls
+ Understanding of cloud security principles and FedRAMP requirements
+ Familiarity with network security, endpoint protection, SIEM, and security operations technologies
+ Knowledge of export control regulations (ITAR/EAR) and related IT security implications
**Compliance Frameworks**
+ NIST SP 800-171 (Protecting CUI in Nonfederal Systems)
+ CMMC (Cybersecurity Maturity Model Certification) 2.0
+ DFARS 252.204-7012, 7019, 7020, 7021, and related clauses
**Skills**
+ Strong leadership and people management capabilities
+ Excellent written and verbal communication skills, including ability to present to executive audiences
+ Risk management and decision-making under uncertainty
+ Project and program management
+ Budget management and financial planning
+ Vendor management and contract oversight
+ Ability to translate complex technical security concepts for non-technical stakeholders
**Other Qualifications & Desired Competencies**
**Certifications (Preferred)**
+ CISSP (Certified Information Systems Security Professional)
+ CISA (Certified Information Systems Auditor)
+ CCP (CMMC Certified Professional)
+ CCA (CMMC Certified Assessor)
+ CAP (Certified Authorization Professional)
+ Security+ or equivalent DoD 8570 IAT Level II certification
**Additional Experience**
+ Experience in aerospace, intelligence, or weapons systems environment
+ FedRAMP (Federal Risk and Authorization Management Program)
+ FIPS 140-2/140-3 cryptographic module validation
+ DoD Cloud Computing SRG
+ NIST SP 800-37 (RMF Application) and SP 800-53
+ ISO 27001 certification experience
+ Security architecture design
+ Software security and secure development lifecycle
+ Supply chain risk management
+ Export control and OPSEC experience
+ Government liaison and relationship management
+ Change management and organ