DIRECTOR IT SECURITY

NORDAM Group LLC

• $130K — $160K *
Tulsa, OK 74133In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity leadership roles
  • Proven knowledge of regulatory frameworks like CMMC, NIST SP 800-171, and NIST Cybersecurity Framework
  • Experience in risk management and security operations
  • Strong understanding of incident response and monitoring best practices
  • Ability to drive compliance and governance in complex environments
  • Familiarity with security technologies such as SIEM and endpoint protection
  • Excellent leadership skills with experience in team development and collaboration

Responsibilities

  • Lead development and execution of the enterprise cybersecurity strategy
  • Oversee compliance with regulatory requirements and maintain necessary artifacts
  • Conduct enterprise IT risk assessments and remediation planning
  • Manage the lifecycle of security technologies and oversee secure configurations
  • Direct identity and access management practices across systems
  • Ensure protection of sensitive data through various security measures
  • Direct incident response planning and maintain operational readiness
  • Evaluate cybersecurity posture of third-party vendors and partners
  • Create and enforce cybersecurity policies and provide training for all teams
  • Identify and implement continuous improvements for security operations

Benefits

  • Comprehensive training and professional development opportunities
  • Flexible working options including hybrid work environments
  • Engagement with advanced security technologies and frameworks
  • Collaboration with cross-functional teams across the organization
  • Opportunities to lead and develop multi-disciplinary teams
  • Access to cutting-edge cybersecurity tools and resources
  • Participation in strategic decision-making processes
Full Job Description
Job Summary

Responsible for establishing, executing, and continuously improving the enterprise cybersecurity strategy across all systems, data, IT and OT environments - on-premise, hybrid, or cloud-based - and all operational environments. Ensures compliance with global, aerospace, and industry-specific regulatory requirements, including CMMC, NIST SP 800-171, NIST SP 800-53, NIST Cybersecurity Framework, and OEM/customer cybersecurity standards, and other global operating standards e.g. Data Privacy Framework (DPF). Oversees risk management, security operations, incident response, governance, and training across the global organization.Essential Functions & Key Responsibilities
  • Cybersecurity Leadership & Strategy - Lead development, communication, and execution of the enterprise cybersecurity strategy; govern security posture across on-premise, hybrid, OT, and Cloud environments; liaise with IT management to align existing technical solutions and skills with future architectural requirements; align security programs with organizational objectives, global operations, and regulatory obligations.
  • Governance, Compliance & Regulatory Requirements - Oversee compliance with CMMC Level 2, NIST SP 800-171, NIST SP 800-53, DoD, aerospace OEM, and other mandated standards; maintain all required artifacts such as SSPs, POA&Ms, policies and evidence packages to support formal assessments, surveys, questionnaires and audits; drive governance practices consistent with enterprise policies, including permission governance and secure SharePoint/OneDrive data management; monitor changes in regulatory frameworks and update controls, procedures and technologies accordingly.
  • Risk Management - Lead enterprise IT risk management, including risk assessments, remediation planning and reporting; ensure global consistency in risk treatment across business units, engineering, operations and supply chain.
  • Security Architecture & Technology Management - Oversee design, deployment and lifecycle management of security technologies such as endpoint protection, firewalls, IDS/IPS, SIEM, identity platforms and cloud security controls; implement secure configuration baselines and vulnerability management programs.
  • Identity, Access & Privileged Governance - Direct IAM practices including role-based access, privileged access controls and lifecycle management; govern permissions and inheritance models across collaboration systems (SharePoint/OneDrive).
  • Data Protection & Information Security - Ensure protection of sensitive data including Controlled Unclassified Information (CUI) - using classification, encryption, retention, auditing and DLP enforcement; oversee secure design of shared repositories, collaboration sites and business data environments, e.g. M365, SharePoint/OneDrive, Teams, .NET, etc.; manage security issues and incidents to protect company assets, including intellectual property and regulated data; participate in problem and change management forums.
  • Incident Response, Monitoring & Resilience - Direct enterprise incident response plans, threat detection, monitoring and forensics capability; conduct regular exercises and ensure all facilities maintain mature response readiness; govern disaster recovery, back-up strategies and business-continuity planning; provide strategic leadership and governance across Security Operations Center overseeing enterprise-wide incident detections, response remediation and threat investigations, directing development and continuous improvement of SOC/IR playbooks and automation and defining KRAs/KPIs that ensure measurable operational performance, risk reduction and alignment with organization security objectives.
  • Vendor, Supplier & Partner Security - Evaluate and manage cybersecurity posture of vendors, suppliers and joint-venture partners, e.g. third-party cyber risk management; enforce contractual and regulatory security requirements across the supply chain.
  • Policies, Procedures & Training - Create, maintain and enforce cybersecurity policies, standards and procedures across the organization; deliver enterprise training and awareness programs tailored to IT, operations, engineering and shop-floor teams; responsible to provide robust training to end-users on security processes, procedures, risk and importance of proper usage; promotes training and individual role accountability with other departments.
  • Continuous Improvement - Identify and implement ongoing enhancements to security operations, tooling and governance; drive maturity improvements tied to audit findings, risk assessments and evolving strategic goals.
  • Leadership & Team Development - Lead and develop multi-disciplinary security teams including cloud security, identity governance, compliance, vulnerability management and operations; foster collaboration with IT, engineering, quality, operations, legal and supply chain to embed security into daily workflows; perform typical responsibilities of management including evaluation, organization, integration, coaching and personnel actions.

Performs other duties as required. These duties may include assignments in job classifications and departments other than the primary assignment.

Similar Jobs

More Jobs at NORDAM Group LLC

More Information Technology Jobs

Find similar DIRECTOR IT SECURITY jobs: