An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Pride Veteran Staffing Inc. in Whippany, NJ seeks an Information Security Lead to build, operate, and continuously improve the company’s internal security program.
The role covers security operations, identity management, endpoint and network defense, vulnerability management, vendor risk, incident response, and business continuity. Working with IT, engineering, operations, and business teams, you’ll protect regulated information while supporting efficient business operations.
Duration: 6-12 Month Contract to Hire
Address: 110 Algonquin Pkwy, Whippany, NJ 07981
Company background: They manufacture aerospace/defense actuation systems and serve commercial and military applications. They have a small local IT team supporting the one-site environment.
Position Summary
The Information Security Lead is a dedicated, hands-on cybersecurity professional responsible for helping build, operate, and continuously improve the company’s internal security program.
The role works across security operations, identity and access management, endpoint and network defense, vulnerability management, vendor risk, compliance, incident response, business continuity, and user enablement. Working closely with Information Technology, engineering, operations, and business teams, the Information Security Lead protects company systems and regulated information while supporting efficient business operations.
This role is intended for a professional with broad information technology and security experience who can operate independently, coordinate across teams, and grow into a senior internal security role.
Responsibilities
Support day-to-day security operations, including alert triage in SIEM and EDR platforms, log review, threat monitoring, investigation, containment, escalation, and incident-response activities.
Administer identity and access management controls, including SSO, MFA, Active Directory and Microsoft Entra ID, privileged access, and joiner, mover, and leaver processes; conduct periodic access reviews and remove stale accounts and unnecessary entitlements.
Maintain and improve endpoint security across the company’s technology environment, including EDR health, patch management, configuration baselines, software control, disk encryption, and remediation of exceptions.
Perform and coordinate network security activities, including firewall and access-control-list reviews, VPN administration, segmentation, secure configuration, wireless security, and monitoring for misconfigurations and unauthorized activity.
Operate the vulnerability management program by performing or coordinating scans, prioritizing vulnerabilities based on business risk and exposure, assigning remediation to system owners, validating closure, and reporting trends and metrics.
Support cybersecurity incident response, disaster recovery, and business continuity planning, including exercises and testing designed to restore critical business systems within established recovery objectives.
Support compliance with applicable customer, contractual, and regulatory requirements, including CMMC, DFARS, ITAR and other U.S. export controls, and, where applicable, NIS2, Cyber Essentials, Cyber Essentials Plus, CMS, DCPP, ISO/IEC 27001, GDPR, and customer-specific information-security requirements.
Collect and maintain audit evidence; develop and maintain policies, procedures, system security plans, plans of action and milestones, risk registers, data-flow diagrams, network diagrams, control documentation, and recurring compliance records; support customer questionnaires and internal and external audits.
Support third-party and supplier risk management by reviewing security documentation, assessing risks, tracking remediation and risk acceptances, and monitoring relevant service-provider controls.
Develop and deliver security awareness and role-based training, phishing simulations, onboarding content, and practical guidance on reporting suspicious activity, protecting CUI and FCI, and responding to security events.
Serve as a knowledgeable point of contact for employee security questions, suspicious emails, lost devices, access requests, and other security concerns.
Research, recommend, implement, and document security technologies, standards, configuration baselines, processes, and runbooks so the security program scales with the company.
Coordinate effectively with internal teams, external service providers, assessors, and other stakeholders, and participate in an on‑call rotation when needed.
Perform other tasks as assigned.
Required Education and Experience
Preferred Qualifications
Physical Requirements