Information Security Officer

RPM xConstruction

McKinney (TX)

On-site

USD 180,000 - 240,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

RPM xConstruction seeks an experienced Information Security Officer to build and mature our security program across projects and offices. You will own compliance with CMMC 2.0 and NIST SP 800-171, manage risk, and work with executives to align security with business goals.

The role includes incident response, security governance, and architecture oversight across corporate IT and field operations, with travel to project sites as needed.

Qualifications

  • 7+ years in information security, risk management, or IT compliance.
  • Leadership experience in security programs.
  • Experience supporting CMMC/NIST 800-171 compliance.

Responsibilities

  • Develop and maintain RPM's information security strategy and policies.
  • Lead governance, risk assessment, and incident response.
  • Ensure compliance with federal contracting cybersecurity requirements.
  • Oversee security architecture and vendor risk management.
  • Coordinate with Legal, Procurement, and IT stakeholders.

Skills

Security governance
Risk management
Cybersecurity strategy
Executive communication
Incident response

Education

Bachelor's degree in Information Security/CS/IT
Master's degree preferred

Tools

CMMC 2.0
NIST SP 800-171
ISO 27001 / SOC 2

Job description

RPM xConstruction is seeking an experienced Information Security Officer (ISO) to build, lead, and continuously mature the company's information security program. This is a senior, high-visibility role responsible for protecting RPM's project data, financial systems, and client and partner information across all business units and job sites, while ensuring the company meets the cybersecurity requirements tied to its federal and government-adjacent construction contracts, including CMMC 2.0 and NIST SP 800-171. The ISO serves as the company's principal authority on cybersecurity risk, policy, and compliance, and works directly with executive leadership to align security strategy with business and contractual obligations.

Key Responsibilities

Security Strategy & Governance

  • Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
  • Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
  • Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
  • Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.

Regulatory & Federal Contract Compliance

  • Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
  • Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
  • Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.
  • Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
  • Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
  • Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
  • Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
  • Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.

Incident Response & Operations

  • Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
  • Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
  • Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
  • Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.

Security Architecture & Technical Oversight

  • Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
  • Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
  • Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.

Training & Culture

  • Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
  • Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.

Reporting & Documentation

  • Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
  • Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.

Qualifications

Education

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.

Experience

  • 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
  • Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
  • Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.

Certifications (one or more preferred)

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA)
  • CRISC (Certified in Risk and Information Systems Control)
  • CCSP or equivalent cloud security certification

Skills & Attributes

  • Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
  • Ability to translate technical risk into business terms for executive and ownership audiences.
  • Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
  • Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
  • Sound judgment under pressure, particularly during incident response.

Working Conditions

  • Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
  • Availability for occasional after-hours response in the event of a security incident.
  • This position is located in McKinney, Texas. We do not compensate for relocation.

Equal Opportunity Employer

This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

INFORMATION SECURITY OFFICER
INFORMATION SECURITY OFFICER

RPM xConstruction, LLC • McKinney (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Senior Information Security Officer — CMMC/NIST Expert
Senior Information Security Officer — CMMC/NIST Expert

RPM xConstruction • McKinney (TX)

On-site
USD 180,000 - 240,000
Enterprise Information Security Leader
Enterprise Information Security Leader

RPM xConstruction, LLC • McKinney (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Contractor Program Security Officer (CPSO)
Contractor Program Security Officer (CPSO)

Radix Metasystemsorporated • Englewood (CO)

On-site
USD 115,000 - 132,000
Small Company Culture
Relaxed Flexible Work Environment
Competitive Wages
+7
Information Systems Security Manager (ISSM)
Information Systems Security Manager (ISSM)

Cypress HCM • San Diego (CA)

On-site
USD 150,000 - 175,000
Principal Information Security Engineer
Principal Information Security Engineer

Clarityinnovates • Fort Meade (MD)

On-site
USD 117,000 - 292,000
Manager of Information Technology
Manager of Information Technology

Confidential • Pittsburgh

Hybrid
USD 150,000 - 190,000
Senior Information System Security Officer (ISSO)
Senior Information System Security Officer (ISSO)

ERP International, LLC • Laurel (MD)

On-site
USD 145,000 - 185,000
IT Cybersecurity Specialist - Remote
IT Cybersecurity Specialist - Remote

OPSPro • Huntsville (AL)

On-site
USD 85,000 - 125,000
IT Cybersecurity Specialist - Remote
IT Cybersecurity Specialist - Remote

OPSPro • Baltimore (MD)

On-site
USD 90,000 - 130,000