Director, Cybersecurity, GRC

Jobtailor

California (MO)

On-site

USD 170,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor seeks a seasoned Chief Information Security and GRC leader to own the security program, including EDR/MDR, IAM, vulnerability management, incident response, and external-audit readiness.

Design a control framework aligned with ISO 27001, SOC 2, NIST CSF/800-53, and NIST 800-171/CMMC, mature governance, and lead a growing cybersecurity team while reporting posture to leadership. You will partner across IT and product security to ensure risk-based priorities and compliant operations.

Qualifications

  • 10+ years in cybersecurity and/or IT GRC.
  • 5+ years in leadership (CISO-track).
  • Deep ITGC experience — control design, operation, and audit.
  • Breadth across the security program: IAM, EDR/MDR, vulnerability management, incident response.
  • Fluency in recognized frameworks (ISO 27001, SOC 2, NIST CSF / 800-53; NIST 800-171 / CMMC a plus).
  • Experience as an external-audit liaison.
  • Strong people leadership and executive‑grade communication.

Responsibilities

  • Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response.
  • Own IT governance, risk, and compliance.
  • Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes.
  • Serve as the primary IT liaison to external auditors and readiness advisors.
  • Mature incident response and disclosure governance.
  • Establish data classification, retention, and encryption standards.
  • Partner on the IT/OT security boundary and with product security.
  • Report cybersecurity and compliance posture to leadership and governance bodies.
  • Lead, coach, and develop the cybersecurity and GRC team.

Skills

Executive leadership
People leadership
Executive communication

Tools

EDR/MDR
IAM
Vulnerability Management
Incident Response
ISO 27001
SOC 2
NIST CSF/800-53
NIST 800-171 / CMMC

Job description

Responsibilities
  • Lead the cybersecurity program: endpoint detection and response / managed detection and response, email and web security, identity and access management, vulnerability management, threat detection, and incident response
  • Own IT governance, risk, and compliance
  • Design a control framework synergistic across ITGC, SOC 2, ISO 27001, and NIST 800-171 / CMMC scopes
  • Serve as the primary IT liaison to external auditors and readiness advisors
  • Mature incident response and disclosure governance
  • Establish data classification, retention, and encryption standards
  • Partner on the IT/OT security boundary and with product security
  • Report cybersecurity and compliance posture to leadership and governance bodies
  • Lead, coach, and develop the cybersecurity and GRC team
Requirements
  • 10+ years in cybersecurity and/or IT GRC
  • 5+ years in leadership (CISO-track)
  • Deep ITGC experience — control design, operation, and audit
  • Breadth across the security program: IAM, EDR/MDR, vulnerability management, incident response
  • Fluency in recognized frameworks (ISO 27001, SOC 2, NIST CSF / 800-53; NIST 800-171 / CMMC a plus)
  • Experience as an external-audit liaison
  • Strong people leadership and executive‑grade communication
Hard Skills
  • Endpoint Detection And Response
  • Managed Detection And Response
  • Identity And Access Management
  • Vulnerability Management
  • Threat Detection
  • Incident Response
  • Control Design
  • ISO 27001
  • NIST 800-171
  • SOC 2
Soft Skills
  • People Leadership
  • Executive-Grade Communication
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, GRC, IT Controls, Cyber Culture
Senior Director, GRC, IT Controls, Cyber Culture

Jobtailor • Town of Florida (NY)

On-site
USD 180,000 - 240,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior Cybersecurity GRC Director - Strategy & Compliance
Senior Cybersecurity GRC Director - Strategy & Compliance

Jobtailor • California (MO)

On-site
USD 170,000 - 210,000
Senior Director, Information Security (Relocation eligible)
Senior Director, Information Security (Relocation eligible)

Solving IT • Nashville (TN)

On-site
USD 180,000 - 260,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
Director, Cyber Risk
Director, Cyber Risk

Jobtailor • Sterling (VA)

On-site
USD 180,000 - 280,000
Director, Governance, Risk, Compliance
Director, Governance, Risk, Compliance

Jobtailor • Illinois

On-site
USD 120,000 - 180,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus