Director of Enterprise Security Design

Kids for the Future

Columbia (MD)

On-site

USD 170,000 - 190,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Bonus potential up to 15%

Job summary

CRISP Shared Services, Inc. in Maryland is seeking a Director of Enterprise Security Design to define and advance the enterprise security architecture strategy. You will act as a trusted advisor to executives, embedding security into business and technology initiatives across the organization.

You will lead risk assessments, maturity initiatives, and cross-functional programs while shaping standards, guardrails, and security investments to strengthen the company's security posture and resilience.

Qualifications

  • 10+ years of progressive cybersecurity experience.
  • 5+ years leading enterprise security architecture, security engineering, or cybersecurity programs.
  • Experience securing hybrid environments across cloud, on-premises, and SaaS ecosystems.
  • Experience developing enterprise security strategies and roadmaps.
  • Experience influencing executive stakeholders and presenting risk-based recommendations.
  • Experience leading cross-functional initiatives without direct authority.
  • Experience overseeing penetration testing and remediation programs.
  • Experience supporting compliance frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, PCI-DSS, or similar.

Responsibilities

  • Develop and maintain the enterprise security architecture roadmap aligned with business objectives.
  • Establish and drive the organization's security-by-design framework across infrastructure, cloud, applications, and data.
  • Influence technology strategy and ensure security requirements are embedded in enterprise architecture decisions.
  • Lead long-term cybersecurity maturity initiatives and continuous improvement programs.
  • Present security risks, recommendations, and investment priorities to executive leadership.
  • Translate business objectives into security capabilities and controls.
  • Define security standards, reference architectures, and engineering guardrails.
  • Provide strategic leadership for enterprise security transformation initiatives.
  • Serve as the primary security advisor to technology and business leaders.
  • Lead security risk reviews for strategic initiatives, acquisitions, and major technology implementations.
  • Develop security metrics, KPIs, and risk dashboards for internal and external reporting.
  • Participate in enterprise governance committees and technology review boards.
  • Drive remediation priorities based on business risk and organizational objectives.
  • Analyze outputs from security tools and coordinate remediation across teams.
  • Perform security risk assessments for change requests and new initiatives.
  • Lead a risk-based vulnerability management program including results from vulnerability scanners, secure code scan, and from security advisories.
  • Identify risks and develop incident response procedures.
  • Support and enhance security technologies (e.g. SIEM, EDR, NDR, IDPS, vulnerability scanner, security lake).
  • Investigate security incidents and produce reports with root cause and corrective actions.
  • Track emerging threats and recommend security improvements.

Education

CISSP
Azure Security Engineer (AZ-500)
Certified Incident Handler (GCIH)

Job description

  • Base Pay $170,000.00 - $190,000.00 / Year
  • Other Compensation up to 15% bonus potential
  • Employee Type FT Exempt
Description
Company Description

CRISP Shared Services (CSS) serves as the technology partner for health information exchange (HIE) partners in Maryland, DC, West Virginia, Connecticut, Alaska, Virginia, Kentucky, Florida, and other jurisdictions. CSS facilitates the electronic transfer of clinical information between disparate information systems in order to positively impact the healthcare system through improved patient care and outcomes, reduced costs, and data-driven understanding of regional public health concerns.

Job Summary

The Director of Enterprise Security Design, i s responsible for defining and advancing the organization's enterprise security architecture strategy, ensuring security is embedded into business and technology initiatives across the enterprise. This role serves as a trusted advisor to executive leadership, drives security-by-design principles, establishes architectural standards, and leads to cross-functional efforts to identify, assess, and mitigate cybersecurity risks. The Director, Enterprise Security Design, maintains a forward-looking view of emerging threats, evolving technologies, and business objectives to strengthen the organization's overall security posture and resilience.

Requirements
Key Responsibilities

Include the following. Other duties may be assigned.

  • Develop and maintain the enterprise security architecture roadmap aligned with business objectives
  • Establish and drive the organization's security-by-design framework across infrastructure, cloud, applications, and data
  • Influence technology strategy and ensure security requirements are embedded in enterprise architecture decisions
  • Lead long-term cybersecurity maturity initiatives and continuous improvement programs
  • Present security risks, recommendations, and investment priorities to executive leadership
  • Translate business objectives into security capabilities and controls
  • Define security standards, reference architectures, and engineering guardrails
  • Provide strategic leadership for enterprise security transformation initiatives
  • Serve as the primary security advisor to technology and business leaders
  • Lead security risk reviews for strategic initiatives, acquisitions, and major technology implementations
  • Develop security metrics, KPIs, and risk dashboards for internal and external reporting
  • Participate in enterprise governance committees and technology review boards
  • Drive remediation priorities based on business risk and organizational objectives
  • Analyze outputs from security tools and coordinate remediation across teams
  • Perform security risk assessments for change requests and new initiatives
  • Lead a risk-based vulnerability management program including results from vulnerability scanners, secure code scan, and from security advisories.
  • Identify risks and develop incident response procedures
  • Support and enhance security technologies (e.g. SIEM, EDR, NDR, IDPS, vulnerability scanner, security lake)
  • Investigate security incidents and produce reports with root cause and corrective actions
  • Track emerging threats and recommend security improvements
Qualifications

To perform this job successfully, the incumbent must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

Required Experience
  • 10+ years of progressive cybersecurity experience
  • 5+ years leading enterprise security architecture, security engineering, or cybersecurity programs
  • Experience securing hybrid environments across cloud, on-premises, and SaaS ecosystems
  • Experience developing enterprise security strategies and roadmaps
  • Experience influencing executive stakeholders and presenting risk-based recommendations
  • Experience leading cross-functional initiatives without direct authority
  • Experience overseeing penetration testing and remediation programs
  • Experience supporting compliance frameworks such as SOC 2, ISO 27001, NIST CSF, HIPAA, PCI-DSS, or similar
Education and Certifications Requirements
Required Experience
  • CISSP
  • Azure Security Engineer (AZ-500)
  • Certified Incident Handler (GCIH)
Preferred Experience
  • CCSP
  • SABSA
  • TOGAF
  • AWS Security Specialty
  • GIAC certifications (GSEC, GCIH, GCIA)
  • GIAC Reverse Engineering Malware (GREM)
Summary
Compensation and Benefits Package
  • Targeted base salary: $170k - $190k per year, based on experience and qualifications, plus benefits and bonuses.
  • Benefits include the following but are not limited to health, dental, vision, life and disability insurance. CSS also has a 403(b) plan with discretionary employer match and contributions. You will be eligible for 20 days of Paid Time Off per year (accrued in accordance with CSS' policies). PTO is in addition to 8 company designated holidays. If you are not PTO eligible, you may be eligible for applicable state and/or local sick and safe leave in accordance with the provisions of any applicable state and/or local sick and safe leave laws.

CRISP Shared Services, Inc. is an equal opportunity employer. This means that CRISP Shared Services Inc. is dedicated to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, age, marital status, genetic information, disability, military or veteran status, or any other status protected by federal, state, or local law. We celebrate diversity and are committed to creating an inclusive environment for all team members.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director Enterprise Security Design
Director Enterprise Security Design

Dynamed Solutions, LLC • Columbia (MD)

Hybrid
USD 170,000 - 190,000
Director Enterprise Security Design
Director Enterprise Security Design

Dynamed Solutions • Columbia (MD)

Hybrid
USD 170,000 - 190,000
Business Analyst
Business Analyst

Kids for the Future • Columbia (MD)

Hybrid
USD 90,000 - 105,000
Health, dental, vision, life and disa­
Senior Security & Technology Solutions Engineer
Senior Security & Technology Solutions Engineer

CRDF Global • Arlington (VA)

On-site
USD 160,000 - 185,000
Medical, dental, and vision insurance
403b retirement savings plan
Unlimited paid time off
+1
Principal Solutions Architect
Principal Solutions Architect

CIS Secure • Ashburn (VA)

Hybrid
USD 150,000 - 190,000
401(k) with company matching
Medical insurance
Dental insurance
+2
Senior Director, IT Security
Senior Director, IT Security

Global Lending Services • Greenville (SC)

On-site
USD 120,000 - 170,000
Competitive base pay
Medical, dental, vision insurance
401K with employer match
+2
Principal Solutions Architect
Principal Solutions Architect

CIS Secure • Virginia (MN)

Hybrid
USD 140,000 - 190,000
401(k) with company matching
Medical insurance
Dental insurance
+5
Job Posting Title Principal Solutions Architect
Job Posting Title Principal Solutions Architect

CIS Secure • Ashburn (VA)

Hybrid
USD 180,000 - 240,000
401(k) with company matching
Dental insurance
Medical insurance
+7
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Senior Security and Technology Solutions Engineer
Senior Security and Technology Solutions Engineer

CRDF Global • Arlington (VA)

On-site
USD 160,000 - 185,000
Medical insurance
Dental insurance
Vision insurance
+3