RapidFort, Inc. logo

Director of Cyber Security

RapidFort, Inc.
Posted 10 hours ago
United StatesRemote$200K–$245KEngineering & Development
Is this job info correct?

DIRECTOR OF CYBER SECURITY Location: United States — Remote: West Coast preferred Department: Information Technology — Security, Risk & Compliance Eligibility: U.S. citizenship required ABOUT RAPIDFORT RapidFort is a cybersecurity company focused on helping organizations secure and optimize their software supply chain and containerized environments. Our platform helps teams reduce software vulnerabilities and attack surface while improving the security and efficiency of modern cloud-native applications. We work with commercial enterprises and public-sector organizations operating in highly regulated and security-sensitive environments. Title: Director of Cyber Security Department: Information Technology — Security, Risk & Compliance Reports To: Chief Information Officer, with a standing reporting line to the Audit Committee Direct Reports: Security operations, security engineering, and governance/risk/compliance, including a dedicated compliance specialist Location: REMOTE Employment Type: Full-time Travel: Periodic travel for audits, customer engagements, and leadership meetings On-Call: Incident commander for declared security incidents ABOUT THE ROLE RapidFort Inc. is looking for a Director of Cyber Security to own our security posture and the risk position behind it — what our controls are, whether they work, what remains exposed, and who has accepted that exposure. This is a horizontal role by design. Cloud Operations, Infrastructure Engineering, and Corporate IT each own an estate and run it. You own the standard those estates are held to, the evidence that the standard is met, and the response when it is not. You set the requirement and verify the outcome; the estate owner executes the remediation. That separation is deliberate — it is what makes the assurance worth anything. You will own the ISO 27001 ISMS and the SOC 2 Type 2 program end to end, command security incidents with authority to direct containment across any estate, and give executive leadership and the Audit Committee an honest, current view of where our risk actually sits. You will also own two program we need closed: FedRAMP authorization and CMMC Level 2. Both are live commitments rather than aspirations, and between them they will reshape how we scope, evidence, and monitor controls. You will have a dedicated compliance specialist to run the evidence machinery across all four frameworks — your job is to sequence them against one control set rather than four, and to carry the scoping and risk decisions that a specialist cannot. Security is also part of our commercial proposition. You will be the person customers’ security teams talk to — questionnaires, customer audits, and the security terms in our contracts — and the person who decides what we will not agree to. This role reports to the CIO but carries a standing reporting line to the Audit Committee, including the explicit right to escalate unresolved material risk without CIO clearance. We would rather write that down than leave it to goodwill. WHAT YOU’LL DO Policy, standards, and risk • Own the information security policy set and the control framework, mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, and our customer and regulatory obligations. • Own the technical standards the estate owners implement — hardening baselines, encryption, logging and retention, authentication, segmentation, and secure configuration. • Own the risk framework and the risk register: current, evidenced, reviewed on cadence, with named owners. • Own the exception process and approve risk acceptances below the material threshold; prepare and escalate anything above it. • Own security architecture review for significant changes and new technology, before commitment. • Report the risk position to the CIO, executive leadership, and the Audit Committee. Detection and incident response • Own security monitoring across endpoints, cloud, on-premises, corporate applications, and identity — coverage, detection content, and tuning. • Own the SIEM estate and any managed detection provider relationship. • Act as incident commander for declared security incidents, with authority to direct containment in any estate. • Own post-incident review and drive remediation into the owning function’s backlog, tracked to closure. • Run tabletop and live exercises across technical teams and executive leadership. Vulnerability and threat management • Own the vulnerability management program: scanning coverage, severity model, and remediation SLAs. • Own the prioritization model — excitability, exposure, business impact — so remediation effort is directed rather than alphabetical. • Track SLA attainment by estate owner, report it, and escalate breaches. • Own penetration testing and red team engagements: scope, vendors, cadence, and finding closure. • Own security testing requirements in the SDLC — SAST, dependency scanning, secrets detection, image scanning — and the gating thresholds. Identity and access governance • Own the access governance model: least privilege, segregation of duties, and the evidence each control must produce. • Own privileged access policy — vaulting, just-in-time elevation, session recording, and break-glass. • Own the design, scope, and cadence of access reviews, and certify their completion. • Own authentication and session policy: MFA requirements, phishing-resistant factors, conditional access, and device trust. Compliance and customer assurance • Own the ISO 27001 ISMS: scope, Statement of Applicability, internal audit program, management review, and certification maintenance. • Own the SOC 2 Type 2 program: control narrative, evidence calendar, and the audit period itself. • Close out FedRAMP authorization: authorization path and agency sponsorship, system boundary, the NIST SP 800-53 baseline, System Security Plan, 3PAO assessment, POA&M, and the monthly continuous monitoring that follows. • Close out CMMC Level 2: CUI scoping and enclave boundary, NIST SP 800-171 implementation, SSP and POA&M, SPRS submission, C3PAO assessment, and annual affirmation. • Sequence all four frameworks against one control set — shared evidence, one calendar, and a single answer to a control tested under more than one regime. • Own the external auditor and certification body relationship, plus the agency sponsor relationship where one is required, and coordinate evidence from each estate owner. • Build continuous control monitoring so compliance is a measured state, not an annual scramble. • Direct the compliance specialist, who runs evidence collection, control testing, POA&M tracking, and audit logistics. You keep framework scope, control interpretation, assessor and sponsor relationships, and the risk decisions behind them. • Own customer security assurance — questionnaires, customer audits, trust documentation, and security terms in contracts and DPAs. • Own the customer assurance pipeline: questionnaire intake, a library of pre-approved answers, and a turnaround commitment to Sales. The specialist drafts; you approve anything that commits us to a control, a date, or a contractual term. • Own controlled distribution of audit artifacts under NDA — SOC 2 report, penetration test summaries, certifications, authorization packages — and decide what is not released. Third-party risk and security culture • Own vendor and SaaS security assessment: tier, assessment depth, sign-off before contract, and reassessment cadence. • Own security requirements in vendor contracts — control obligations, right to audit, and incident notification terms. • Own the awareness program, phishing simulation, and role-specific training for developers, privileged operators, and executives. COMPENSATION & BENEFITS RapidFort offers a competitive total rewards package that includes: • Base Salary: $200,000–$245,000 USD annually, depending on experience, qualifications, and location • Annual performance-based bonus • Equity: Stock options in RapidFort • Medical, dental, and vision insurance • 401(k) retirement plan • Paid time off and company holidays • Paid sick leave • Company-provided equipment • Professional development and growth opportunities RapidFort is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

Similar jobs