INFORMATION SECURITY OFFICER

RPM xConstruction, LLC

McKinney, Northern (TX, KY)

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

RPM xConstruction, LLC is seeking a senior information security leader to develop and govern the company’s information security program across corporate IT, field offices, and project sites. You will align strategy with NIST CSF, NIST SP 800-171, and CMMC 2.0, driving risk-informed decisions for bids and operations.

You will own the SSP/POA&M, coordinate audits, and oversee security controls across cloud, on-premise, and field systems, while leading incident response and security training

Qualifications

  • 7+ years in information security, risk management, or IT compliance with leadership experience.
  • Experience supporting CMMC, NIST SP 800-171, or similar federal/defense requirements preferred.
  • Construction/real estate or project-based industries experience is a plus.

Responsibilities

  • Develop, implement, and update RPM's enterprise information security strategy, policies, and standards.
  • Own compliance with cybersecurity requirements for DoD/government contracts and monitor CMMC rollout.
  • Maintain SSP/POA&M and support audits, assessments, and vendor risk management.
  • Lead incident response, security monitoring, and reporting to executive leadership.
  • Ensure secure architecture, IAM, and secure deployment of project management and field systems.

Skills

Leadership
Risk management
Cross-functional collaboration
Executive communication
Incident response

Education

Bachelor's degree in Information Security, Computer Science, IT, or related field
Master's degree preferred

Job description

  • Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
  • Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
  • Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
  • Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.
Regulatory & Federal Contract Compliance
  • Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
  • Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
  • Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.
  • Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
  • Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
  • Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
  • Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
  • Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.
Incident Response & Operations
  • Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
  • Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
  • Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
  • Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.
Security Architecture & Technical Oversight
  • Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
  • Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
  • Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.
Training & Culture
  • Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
  • Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.
Reporting & Documentation
  • Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
  • Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.
Qualifications
Education
  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.
Experience
  • 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
  • Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
  • Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.
Certifications (one or more preferred)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA)
  • CRISC (Certified in Risk and Information Systems Control)
  • CCSP or equivalent cloud security certification
Skills & Attributes
  • Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
  • Ability to translate technical risk into business terms for executive and ownership audiences.
  • Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
  • Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
  • Sound judgment under pressure, particularly during incident response.
Working Conditions
  • Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
  • Availability for occasional after-hours response in the event of a security incident.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Compliance Specialist
Senior Security Compliance Specialist

FORTEM TECHNOLOGIES INC • Lindon (UT)

On-site
USD 110,000 - 160,000
Security Analyst 1
Security Analyst 1

Construction Partners, Inc. • Dothan (AL)

On-site
USD 52,000 - 76,000
Medical, Dental, Vision coverage
401(k) with employer match
Paid vacation and holidays
+3
Construction Site Security Manager
Construction Site Security Manager

Orbitalpm • Washington

On-site
USD 120,000 - 170,000
Competitive compensation based on 경험
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Manager, IT Risk & Compliance 2
Manager, IT Risk & Compliance 2

Celestica • United States

On-site
USD 107,000 - 147,000
Enterprise Information Security Leader
Enterprise Information Security Leader

RPM xConstruction, LLC • McKinney (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
SR INFRASTRUCTURE SECURITY ENGINEER
SR INFRASTRUCTURE SECURITY ENGINEER

NOW Foods • Bloomingdale (IL), Northern (KY)

Hybrid
USD 122,000 - 152,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Warehouse-Specialists,-LLC-2 • Appleton (WI)

On-site
USD 120,000 - 165,000
Medical, Dental, Vision
401(k) Plan
Paid Time Off
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Warehouse Specialists, Inc. • Appleton (WI)

Hybrid
USD 120,000 - 180,000
Medical, Dental, Vision
401(k) with employer match
Paid time off
+1
Manager of Information Technology
Manager of Information Technology

Confidential • Pittsburgh

Hybrid
USD 150,000 - 190,000