INFORMATION SECURITY OFFICER

RPM xConstruction

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, IT, or related field; Master's preferred.
  • 7+ years in information security, risk management, or IT compliance; 3 years in leadership role.
  • Experience with CMMC, NIST SP 800-171, or similar federal cybersecurity requirements strongly preferred.
  • Experience in project-based industries like construction is a plus but not required.
  • Certifications such as CISSP, CISM, CCP, or equivalent are preferred.
  • Strong knowledge of security frameworks including ISO 27001 and SOC 2.
  • Ability to translate technical risks for executive audiences.

Responsibilities

  • Develop and implement enterprise information security strategies aligned with business objectives and industry standards.
  • Present risk posture and incident trends to executive leadership regularly.
  • Manage the company's information security governance structure and policy review processes.
  • Create a multi-year security roadmap addressing regulatory needs and operational realities.
  • Oversee compliance with federal cybersecurity requirements for construction contracts.
  • Act as point of contact for compliance audits and security assessments.
  • Lead incident response efforts and maintain the incident response plan.

Benefits

  • Company-wide security awareness training opportunities.
  • Support for continual professional development and certification.
  • Collaborative working environment with cross-functional teams.
  • Potential for travel to diverse project sites and offices.
  • Flexible working conditions with an office-based majority.
Full Job Description
Key Responsibilities
Security Strategy & Governance
  • Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
  • Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
  • Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
  • Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.
Regulatory & Federal Contract Compliance
  • Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
  • Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
  • Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS [redacted]/7019/7020 flow-down requirements.
  • Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
  • Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
Risk Management
  • Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
  • Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
  • Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.
Incident Response & Operations
  • Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
  • Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
  • Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
  • Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.
Security Architecture & Technical Oversight
  • Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
  • Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
  • Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.
Training & Culture
  • Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
  • Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.
Reporting & Documentation
  • Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
  • Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.
Qualifications
Education
  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.
Experience
  • 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
  • Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
  • Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.
Certifications (one or more preferred)
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA)
  • CRISC (Certified in Risk and Information Systems Control)
  • CCSP or equivalent cloud security certification
Skills & Attributes
  • Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
  • Ability to translate technical risk into business terms for executive and ownership audiences.
  • Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
  • Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
  • Sound judgment under pressure, particularly during incident response.
Working Conditions
  • Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
  • Availability for occasional after-hours response in the event of a security incident.


Similar Jobs

More Jobs at RPM xConstruction

More Information Technology Jobs

Find similar INFORMATION SECURITY OFFICER jobs: