10+ years of experience in U.S. regulatory compliance frameworks (ITAR, CUI, EAR).
Extensive background with Cybersecurity Maturity Model Certification (CMMC).
Track record in creating and managing security compliance programs in regulated environments.
Familiarity with IT service management and project management tools (ServiceNow, Jira).
Ability to translate regulatory requirements into actionable security policies.
Strong analytical and problem-solving skills for compliance risk mitigation.
Excellent communication skills for engagement with all organizational levels.
Responsibilities
Lead, mentor, and foster a culture of excellence and growth within the team.
Develop and enforce security policies to ensure compliance with U.S. regulations.
Oversee the enhancement of secure system environments to meet industry standards.
Conduct compliance audits and manage risk assessments and remediation programs.
Serve as a contact point for stakeholders on security compliance matters and provide expert guidance.
Stay updated on CMMC and other cybersecurity frameworks, integrating necessary changes into security posture.
Collaborate with cross-functional teams to ensure security requirements are met in system development.
Benefits
401(k) with matching contributions
Comprehensive dental insurance
Flexible spending accounts for health-related expenses
Health insurance options available
Life insurance coverage
Paid time off for vacations and personal days
Vision insurance options available
Full Job Description
Key Responsibilities:
Team Leadership & Development: Lead, mentor, and fostering a culture of excellence, continuous improvement, and professional growth.
Strategic Compliance Oversight: Develop, implement, and enforce security policies, standards, and procedures to ensure comprehensive compliance with U.S. regulations (ITAR, CUI, EAR) and cybersecurity frameworks (CMMC Level 2).
Program Management: Oversee the deployment, maintenance, and continuous enhancement of secure system environments, ensuring they meet or exceed industry security standards.
Audit & Risk Management: Lead compliance audits, conduct comprehensive risk assessments, and manage vulnerability remediation programs. Develop and track robust remediation plans to address identified gaps and ensure perpetual audit readiness.
Stakeholder Engagement: Act as a primary point of contact for internal stakeholders regarding security compliance matters, providing expert guidance and ensuring strategic alignment across various departments.
Continuous Improvement & Threat Intelligence: Ensure the team stays abreast of the latest developments in CMMC, and other relevant cybersecurity frameworks, proactively integrating necessary changes and enhancements into our security posture.
Cross-Functional Collaboration: Partner effectively with cross-functional teams (e.g., IT, Sales, Quality) to integrate security and compliance requirements into all stages of system development and operation.
Qualifications:
Minimum 10+ years' experience in U.S. regulatory compliance frameworks, including ITAR, CUI, and EAR.
Extensive experience with the Cybersecurity Maturity Model Certification (CMMC) framework, including leading audit preparation and remediation efforts.
Proven track record of developing, implementing, and managing security compliance programs in complex, highly regulated environments.
Familiarity with IT service management platforms (e.g., ServiceNow) and project management tools (e.g., Jira) for tracking compliance initiatives.
Strategic thinker with the ability to translate complex regulatory requirements into action able security policies and procedures.
Strong analytical and problem-solving abilities, with a proactive approach to identifying and mitigating compliance risks.
Outstanding communication and interpersonal skills, capable of engaging effectively with all levels of the organization, including executive leadership and external auditors.
Experience working in a global organization and navigating diverse compliance landscapes is a significant plus.
This position will be subject to U.S. export control requirements under the International Traffic in Arms Regulations (ITAR) and/or Export Administration Regulations (EAR). Employment is contingent on either verifying the U.S. Person status or obtaining any necessary export license.