Montrose Environmental Group, Inc.

Director of Cybersecurity, Architecture and Engineering

US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of progressive information security experience, especially in tool engineering and team leadership.
  • Bachelor's degree in Computer Science, Information Systems, or related field.
  • Experience managing or collaborating with a managed security services provider (MSSP) for SOC/NOC functions.
  • Supported CMMC and/or NIST standards implementation in partnership with GRC teams.
  • Deep technical knowledge across security tools: firewalls, EDR, SIEM, and vulnerability platforms.
  • Strong understanding of network security concepts in large-scale environments.
  • Proven ability to build and mentor a high-performing technical team.

Responsibilities

  • Lead and develop a team of security engineers focused on various security domains.
  • Act as a hands-on technical backstop, engaging in tool domains as needed.
  • Manage the relationship with the MSSP, ensuring compliance with SLAs and effective performance.
  • Serve as the escalation point for serious security incidents, making decisive containment calls.
  • Coordinate with the GRC team to implement essential technical controls for compliance frameworks.
  • Design and maintain security architecture standards across the organization.
  • Develop and refine the security engineering roadmap in response to threats and business risks.
  • Define and track metrics and OKRs for the security engineering function, reporting to leadership.

Benefits

  • Remote work opportunity within the U.S. with travel flexibility.
  • Standard business hours with occasional on-call responsibilities.
  • Opportunity for professional growth within a high-performing team.
Full Job Description
A Day in the Life

Reporting to the CISO, the Director of Cybersecurity Architecture & Engineering leads our security engineering team and is accountable for the design, implementation, and continuous improvement of our core security tooling and architecture. This role partners closely with our managed security services provider (MSSP), which delivers 24/7 SOC/NOC monitoring, and with our GRC team, which owns our compliance frameworks and assessments (including CMMC and NIST SP 800-171). This is a hands-on, player-coach role: the Director is expected to lead and develop a small, high-performing technical team while remaining technically capable of stepping into any tool domain when needed.

The compensation range for this role is $195,000 to $230,000 USD, in addition to an annual bonus (15%), commensurate with experience, skills, and geographic location.

To thrive in this role, you'll be comfortable taking ownership of the following responsibilities:
  • Lead, mentor, and develop a team of security engineers responsible for perimeter and endpoint security, detection and monitoring, and vulnerability management engineering
  • Serve as a hands-on technical backstop across the team's tool domains (firewall, EDR, SIEM, WAF, vulnerability management, and security awareness platforms), able to step in during absences or transitions
  • Own the strategic relationship with our managed security services provider (MSSP), including SLAs, escalation processes, contract performance, and renewal
  • Serve as the Tier 2/3 escalation point for security incidents raised by the MSSP, providing decision authority on containment, access, and asset-criticality judgment calls
  • Serve as the primary technical point of contact between the security engineering team and the GRC team, ensuring technical controls required for CMMC, NIST SP 800-171, and other applicable frameworks are designed, implemented, and maintained
  • Design and maintain security architecture standards for network segmentation, system hardening baselines, and identity and access boundaries, in partnership with the team that owns IAM
  • Develop and continuously refine the security engineering roadmap and technical standards in alignment with the evolving threat landscape and business risk tolerance
  • Define OKRs, metrics, and scorecards for the security engineering function and report on team health and risk posture to executive leadership
  • Partner with development and infrastructure teams to identify and remediate application- and infrastructure-level vulnerabilities
  • Own workforce planning for the team, including current team development and future headcount growth
  • Ensure the team maintains up-to-date documentation of tool ownership, backup coverage, and operational runbooks
  • Track developments in the digital business and threat environment to ensure they are reflected in security strategy and architecture


Your Expertise and Skills

These requirements reflect the knowledge, skills and abilities that help you do your best work here.
  • 10+ years of progressive information security experience, including hands-on tool engineering and team leadership
  • Bachelor's degree in Computer Science, Information Systems, or a related field
  • Demonstrated experience managing or technically partnering with a managed security services provider (MSSP) for SOC/NOC functions
  • Experience supporting CMMC and/or NIST SP 800-171 / 800-53 control implementation in partnership with a GRC or compliance function
  • Deep technical knowledge across core security tooling categories: next-generation firewalls, EDR, SIEM, WAF, vulnerability management platforms, and security awareness platforms
  • Strong understanding of network architecture, segmentation, and security concepts in large-scale environments
  • Demonstrated ability to build, mentor, and retain a small, high-performing technical team
  • Knowledge of federal cybersecurity and data privacy laws, regulations, and policies applicable to a federal contractor
  • Strong understanding of the cybersecurity threat lifecycle, attack vectors, and intrusion set tactics, techniques, and procedures (TTPs)
  • Excellent cross-functional communication skills, with the ability to translate technical risk for executive audiences


Work Environment
  • This is a remote role within the U.S. with a willingness to travel as needed
  • Primarily office/home-office based work; standard business hours with periodic escalation-tier on-call responsibilities outside business hours


About Montrose Environmental Group, Inc.

Montrose Environmental Group, Inc. is a leading environmental services company focused on supporting government and commercial organizations as they deal with the challenges of today, and prepare for what's coming tomorrow. With more than 1,700 employees across over 70 locations around the world, Montrose combines deep local knowledge with an integrated approach to design, engineering, and operations, enabling them to respond effectively and efficiently to the unique requirements of each project. Montrose is committed to protecting the environment, supporting communities, and strengthening the economy.
Learn more about Montrose Environmental Group, Inc.
Size
1,500 employees
Market Cap
$1.2 billion
Industry
5 Year Trend
+36.6%
NASDAQ

Similar Jobs

More Jobs at Montrose Environmental Group, Inc.

More Information Technology Jobs

Find similar Director of Cybersecurity, Architecture and Engineering jobs: