Director, National Security-Cybersecurity Governance
$130k - $175kAlvarez & Marsal
Description
About Alvarez & Marsal Alvarez & Marsal is a premier independent global professional services firm specializing in providing turnaround management, restructuring, performance improvement and corporate advisory services. Our talent drives our success, resulting in our growing Disputes and Investigations practice becoming one of the most respected in the industry. From the boardroom to the courtroom, the firm delivers a wide array of solutions to contentious situations by drawing on the deep skills, diverse disciplines and experiences of its professionals. We are recognized by Global Arbitration Review as one of the leading firms of independent experts for arbitration and considered a top three firm by Who's Who Legal based on the number of experts across the globe. Our clients include major banks, leading law firms, private equity firms and well-known corporations and upper-mid-sized companies. The Team At A&M you will have the opportunity to work with a diverse team of supportive and motivated professionals that love to share their knowledge and depth of industry experience with others. A&M's Disputes and Investigations practice comprises professionals from a wide range of backgrounds, who bring and share their deep expertise in conducting investigations and delivering expert witness reports. We have an inclusive developmental environment where everyone has the opportunity to learn and grow. Our culture is characterized by openness and entrepreneurial thinking, with a foundation of mutual respect and high-quality standards for our work. We strive to remove bureaucracy in favor of recognizing effort and results through advancement opportunities and a motivating performance-based reward structure. How you will contribute With the rapidly changing geopolitical environment, competition for sensitive technologies, and risks associated with potential exploitation of sensitive personal and business data, demand for national security-focused risk analysis and mitigation is growing significantly. Our team supports organizations, investors and counsel in identifying, assessing, and reducing national security-related risk through modern security architectures and enterprise-grade solutions. We focus on implementing Zero Trust security frameworks, establishing robust Identity and Access Management (IAM) controls, and embedding regulatory requirements into business systems and processes. Our approach facilitates transparency between companies and regulators by leveraging data analytics, automated compliance monitoring, and advanced security tooling. The team serves as fiduciary to U.S. government agencies as either third-party monitor or third-party auditor, ensuring adherence to federal security standards and frameworks. Responsibilities: • Lead cross-functional project teams in executing advisory, oversight, and audit projects related to Foreign Direct Investment (FDI) national security reviews, export and technology controls, and Cybersecurity Maturity Model Certification (CMMC). Develop comprehensive project plans, establish key milestones, and manage resource allocation using enterprise project management methodologies and tools. • Design and implement Zero Trust architecture frameworks and IAM solutions, including privileged access management (PAM), role-based access control (RBAC), and continuous authentication mechanisms. Collaborate with client security personnel to define and document security controls for distributed, big data systems with emphasis on least-privilege access principles. • Conduct enterprise-wide security assessments to verify the efficacy of administrative, technical, and physical safeguards, with particular focus on identity governance, access management, and Zero Trust implementation. Evaluate security control maturity against industry frameworks such as NIST 800-53, ISO 27001, and CMMC. • Direct comprehensive security assessments of applications and software, including: (i) reviewing architecture diagrams with emphasis on identity and access flows; (ii) interviewing personnel across DevSecOps teams; (iii) evaluating IAM integration points and Zero Trust implementation; (iv) overseeing static and dynamic code analysis; (v) managing network penetration testing; and (vi) preparing detailed technical reports for senior counsel, executives, and national security officials. • Analyze and interpret penetration test results, focusing on identity-related vulnerabilities, access control weaknesses, and deviations from Zero Trust principles. Develop remediation roadmaps aligned with enterprise architecture standards. • Implement and integrate security technologies including Security Information and Event Management (SIEM), Identity Governance and Administration (IGA), and Privileged Access Management (PAM) solutions to enable automated compliance monitoring and security oversight. • Create and maintain project management artifacts including work breakdown structures, risk registers, and resource allocation plans. Establish project governance frameworks and reporting mechanisms to ensure alignment with organizational objectives and regulatory requirements. • Availability for up to 20% travel required to client sites and security assessment locations. Qualifications: • 8+ years of experience with Technology Companies that deliver controlled technology nationally and internationally • Experience with NIST CSF, NIST SP 800-53, NIST SP 800-171, NIST SP 800-218, NIST SP 800-161, and/or ISO 27001 • Experience working in cybersecurity governance (i.e., experience working with NIST CSF; NIST 800-171 and -53; CIS-18 IG1 and ISO 27001) • Proficiency in at least one programming language (e.g., Python, Java, etc.) • Background in network and cloud-based platforms (e.g., GCP, AWS, Kubernetes, etc.) • Familiarity with containerization technologies and deployments • Experience with Big Data platforms (on premise and cloud) • Ability to obtain a USG security clearance • One or more relevant industry certification: CompTIA Security+, CompTIA CySA+, CompTIA CASP+, CISSP, CISM, CISA, ISO 27001, or comparable certifications Your journey at A&M We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person's unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals. Full-time Positions and Part-time Positions Over 30 hours Regular employees working 30 or more hours per week are also entitled to participate in Alvarez & Marsal Holdings' fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined from time to time as well as a 401(k) retirement plan. Provided the eligibility requirements are met, employees will also receive a discretionary contribution to their 401(k) from Alvarez & Marsal. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type. Click here for more information regarding A&M's benefits programs. The salary range is $130,000 - $175,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, A&M offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details. Alvarez & Marsal recruits on an ongoing basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) that they are qualified for and that are of interest to them. A&M does not require or administer lie detector tests as a condition of employment or continued employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-NM1
About Alvarez & Marsal Alvarez & Marsal is a premier independent global professional services firm specializing in providing turnaround management, restructuring, performance improvement and corporate advisory services. Our talent drives our success, resulting in our growing Disputes and Investigations practice becoming one of the most respected in the industry. From the boardroom to the courtroom, the firm delivers a wide array of solutions to contentious situations by drawing on the deep skills, diverse disciplines and experiences of its professionals. We are recognized by Global Arbitration Review as one of the leading firms of independent experts for arbitration and considered a top three firm by Who's Who Legal based on the number of experts across the globe. Our clients include major banks, leading law firms, private equity firms and well-known corporations and upper-mid-sized companies. The Team At A&M you will have the opportunity to work with a diverse team of supportive and motivated professionals that love to share their knowledge and depth of industry experience with others. A&M's Disputes and Investigations practice comprises professionals from a wide range of backgrounds, who bring and share their deep expertise in conducting investigations and delivering expert witness reports. We have an inclusive developmental environment where everyone has the opportunity to learn and grow. Our culture is characterized by openness and entrepreneurial thinking, with a foundation of mutual respect and high-quality standards for our work. We strive to remove bureaucracy in favor of recognizing effort and results through advancement opportunities and a motivating performance-based reward structure. How you will contribute With the rapidly changing geopolitical environment, competition for sensitive technologies, and risks associated with potential exploitation of sensitive personal and business data, demand for national security-focused risk analysis and mitigation is growing significantly. Our team supports organizations, investors and counsel in identifying, assessing, and reducing national security-related risk through modern security architectures and enterprise-grade solutions. We focus on implementing Zero Trust security frameworks, establishing robust Identity and Access Management (IAM) controls, and embedding regulatory requirements into business systems and processes. Our approach facilitates transparency between companies and regulators by leveraging data analytics, automated compliance monitoring, and advanced security tooling. The team serves as fiduciary to U.S. government agencies as either third-party monitor or third-party auditor, ensuring adherence to federal security standards and frameworks. Responsibilities: • Lead cross-functional project teams in executing advisory, oversight, and audit projects related to Foreign Direct Investment (FDI) national security reviews, export and technology controls, and Cybersecurity Maturity Model Certification (CMMC). Develop comprehensive project plans, establish key milestones, and manage resource allocation using enterprise project management methodologies and tools. • Design and implement Zero Trust architecture frameworks and IAM solutions, including privileged access management (PAM), role-based access control (RBAC), and continuous authentication mechanisms. Collaborate with client security personnel to define and document security controls for distributed, big data systems with emphasis on least-privilege access principles. • Conduct enterprise-wide security assessments to verify the efficacy of administrative, technical, and physical safeguards, with particular focus on identity governance, access management, and Zero Trust implementation. Evaluate security control maturity against industry frameworks such as NIST 800-53, ISO 27001, and CMMC. • Direct comprehensive security assessments of applications and software, including: (i) reviewing architecture diagrams with emphasis on identity and access flows; (ii) interviewing personnel across DevSecOps teams; (iii) evaluating IAM integration points and Zero Trust implementation; (iv) overseeing static and dynamic code analysis; (v) managing network penetration testing; and (vi) preparing detailed technical reports for senior counsel, executives, and national security officials. • Analyze and interpret penetration test results, focusing on identity-related vulnerabilities, access control weaknesses, and deviations from Zero Trust principles. Develop remediation roadmaps aligned with enterprise architecture standards. • Implement and integrate security technologies including Security Information and Event Management (SIEM), Identity Governance and Administration (IGA), and Privileged Access Management (PAM) solutions to enable automated compliance monitoring and security oversight. • Create and maintain project management artifacts including work breakdown structures, risk registers, and resource allocation plans. Establish project governance frameworks and reporting mechanisms to ensure alignment with organizational objectives and regulatory requirements. • Availability for up to 20% travel required to client sites and security assessment locations. Qualifications: • 8+ years of experience with Technology Companies that deliver controlled technology nationally and internationally • Experience with NIST CSF, NIST SP 800-53, NIST SP 800-171, NIST SP 800-218, NIST SP 800-161, and/or ISO 27001 • Experience working in cybersecurity governance (i.e., experience working with NIST CSF; NIST 800-171 and -53; CIS-18 IG1 and ISO 27001) • Proficiency in at least one programming language (e.g., Python, Java, etc.) • Background in network and cloud-based platforms (e.g., GCP, AWS, Kubernetes, etc.) • Familiarity with containerization technologies and deployments • Experience with Big Data platforms (on premise and cloud) • Ability to obtain a USG security clearance • One or more relevant industry certification: CompTIA Security+, CompTIA CySA+, CompTIA CASP+, CISSP, CISM, CISA, ISO 27001, or comparable certifications Your journey at A&M We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person's unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals. Full-time Positions and Part-time Positions Over 30 hours Regular employees working 30 or more hours per week are also entitled to participate in Alvarez & Marsal Holdings' fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined from time to time as well as a 401(k) retirement plan. Provided the eligibility requirements are met, employees will also receive a discretionary contribution to their 401(k) from Alvarez & Marsal. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type. Click here for more information regarding A&M's benefits programs. The salary range is $130,000 - $175,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, A&M offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details. Alvarez & Marsal recruits on an ongoing basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) that they are qualified for and that are of interest to them. A&M does not require or administer lie detector tests as a condition of employment or continued employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-NM1
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Director, National Security-Cybersecurity Governance in San Francisco, CA vacancy
$125.9k - $150k
Impact As a Program Manager, Privacy, Cybersecurity and AI Governance located in San Francisco, CA or... ...functionally with Product, Engineering, Security, and Data stakeholders to embed... ...discriminate on the basis of race, color, national origin, ethnicity, religion or...SuggestedFull timeWork at officeWork from home$244k - $390.58k
...our products. Docusign's security program is vital to that trust... ...our success. The Senior Director, Security Governance, Risk, and Compliance (GRC... ..., machine learning, cybersecurity, risk management, or a related... ...color, age, sex, religion, national origin, ancestry, pregnancy...SuggestedContract workWork experience placementWork at officeLocal areaRemote workShift work2 days per week$260k - $346k
...Your Impact at LILA Cloud Security & Compliance Lead is... ...for the end-to-end security, governance, risk management, and regulatory... ...science, Information Security, Cybersecurity, Engineering, or related... ...color, ancestry, religion, sex, national origin, sexual orientation,...SuggestedFull timeContract workWork at officeLocal areaFlexible hours$195k - $263k
...Director of Security & IT Operations San Francisco, CA The Role Pilot is looking for... ...security—including application security, cybersecurity detection and response, corporate IT... ..., color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship...SuggestedFull timeTemporary workPart timeFlexible hours- ...Salesforce, Inc. is seeking a Director of Product Management to lead the Partner Security, Governance, and Guardrails Platform in San Francisco. The role involves defining the strategy for ensuring partner-deployed technology remains secure and compliant. You will manage...Suggested
$148.7k - $240.53k
...place. Who We Are In order to be the cybersecurity partner of choice, we must trailblaze... ...to define and advance our Device Security solution - an AI-first solution that discovers... ..., marital status, medical condition, national origin, physical or mental disability,...Full timeWork at officeRemote workVisa sponsorshipWork visa$148.7k - $240.53k
...We Are In order to be the cybersecurity partner of choice, we must... ...executing both the product security and lifecycle strategy for PAN... ...Product Security Strategy & Governance Own the Platform Security... ...status, medical condition, national origin, physical or mental disability...Full timeWork at officeShift work$300k - $360k
...compounding interest. The Chief Information Security Officer (CISO) will serve as a key... ...leading Bank’s information security and cybersecurity programs. As the Bank prepares to... ...the development of information security governance, technical controls, and third-party risk...Work at officeRemote workFlexible hours- ...critical infrastructure cybersecurity, delivers an end-to-... ...complex networks, secure their devices, and ensure... ...1,700 organizations, governments, and institutions... ...talented and experienced Director of Products to... ...religion, age, sex, national origin, disability status...Local areaFlexible hours
$275k - $375k
...seeking an experienced Head of Security Engineering to define, lead,... ...detection & response, IAM governance, and secure development... ...degree in Computer Science, Cybersecurity, or a related field 10+ years... ...color, ancestry, religion, sex, national origin, sexual orientation,...Full timeWork at officeLocal area$168.3k - $296.7k
...information, such as your social security number. What to know:... ...to reduce risks, improve governance, and do more with data. The... ...Expertise: At least 5 years in the Cybersecurity or Data Protection space,... ..., ancestry, religion, sex, national origin, sexual orientation,...Remote workShift work$140.4k - $372.3k
...by Copilot to build, scale, and deliver secure software. Over 180 million developers, including... ...their software. The way enterprises govern code on that infrastructure, who can... ...sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy...Ongoing contractRemote work- ...Sales Manager (RSM), Cloud Security Introduction We are a specialized... ...provider within a global cybersecurity leader, focused on Security... .... Reporting : Director of North American Sales... ...grounds of race, religion, color, national origin, gender, sexual...Temporary workWork at officeLocal areaRemote workWorldwideFlexible hours
- ...enterprise spends millions of dollars on Governance, Risk, and Compliance (GRC). It's one of... ...the best. Our team includes AI and security leaders from Airbnb, Microsoft, Deloitte... ...orientation, gender identity/expression, national origin, disability, age, genetic information...Work at officeVisa sponsorshipFlexible hours
- DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of experience in security leadership, focusing on innovative risk management strategies. The ideal candidate will...
$220k - $290k
...Role Summary We’re hiring a Director of IT to lead our Corporate IT... ...responsible for the reliability, security, and scalability of our... ...experience, balancing the need for governance with the need to move quickly... ...of race, color, religion, national origin, gender, sexual...Work at officeLocal areaRemote workHome officeFlexible hours$200k - $350k
...------------------------------------------- THE ROLE: Our Directors are responsible for owning client relationships and delivering... ...medical conditions), gender, gender identity, gender expression, national origin, ancestry, age, physical or mental disability, medical...Work at officeLocal area2 days per week3 days per week$164k - $261.5k
...Role This role is part of the Salesforce Security organization, where we protect one of... ...subject matter experts (SMEs) across the Cybersecurity Operations Center (CSOC), Product... ...without regard to race, religion, color, national origin, sex, sexual orientation, gender...- ...Anywhere Real Estate is seeking a Director of Escrow Support to lead the national strategy and performance across multiple operational functions. This role involves overseeing escrow support, vendor management, and a learning & development team. The ideal candidate will...
$180k - $210k
...more, go to About the Role We're looking for a Director of Application Security to architect and lead an AI-native, agent-driven Application... ..., religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis...Shift work$217k - $300k
...seeking an Associate General Counsel in San Francisco to lead the Privacy & Security team. This role involves managing the privacy program in compliance with laws and advising on AI governance. The individual will work cross-functionally with various teams to ensure privacy...$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice – the best... ...your career in information security! The opportunity The... ...designing, implementing, and governing secure network architectures... ..., genetic information, national origin, protected veteran status...Summer holidayRemote workFlexible hours- ...Director Of Customer Security Salesforce is the #1 AI CRM, where humans with agents drive customer success together. Here, ambition meets action... ...– without regard to race, religion, color, national origin, sex, sexual orientation, gender expression or identity...
$157k - $235k
...role responsible for building the planning, launch, reporting, governance, and operating systems that help SPECS Marketing scale with... ...employment opportunities regardless of race, religious creed, color, national origin, ancestry, physical disability, mental disability,...Live inWork at officeLocal areaImmediate start$190k - $220k
...seeking a highly strategic and operationally driven Director, Supply Chain Operations & Governance to build and lead a centralized supply chain operations... ...regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status...Full timeContract workWork at officeLocal areaRemote workFlexible hours$300k - $360k
...there are multiple listed for the job. The Work As the Senior Director of Security Engineering, you will be responsible for building and... ...religion, gender identity, sex, sexual identity, pregnancy, national origin, ancestry, citizenship, age, marital status, physical...Full timeLocal area- ...to lead and scale our corporate IT function. You will ensure a secure and efficient technology experience for employees while... ...IT experience, focusing on leadership in corporate operations, cybersecurity, and SaaS environments. Pano AI offers stock options, comprehensive...
$200k - $300k
...testing, deployments, application security, reliability, compliance, and... ...maintaining security and governance throughout the entire... ...scale the organization. The Director, Revenue Operations role is responsible... ..., color, religion, sex or national origin. Note on Fraudulent Recruiting...Immediate startWorldwideShift work$250k - $300k
...Director, Security & Compliance San Francisco, CA At Instabase, we're passionate about democratizing... ...managing out our Security and GRC (Governance, Risk, IT and Compliance) program,... ..., gender perception or identity, national origin, age, marital status, protected...Work at officeFlexible hours$184k - $230k
...searching for a highly motivated and strategic Manager, Enterprise Security to lead and mentor a team of Security Engineers in securing... ...Threat prevention, Endpoint Security, Identity and Access Governance, Security Awareness Training, Configuration management and Infrastructure...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, National Security-Cybersecurity Governance. Be the first to apply!
Related searches
- security systems manager San Francisco, CA
- senior security manager San Francisco, CA
- security manager San Francisco, CA
- security engineering manager San Francisco, CA
- product security manager San Francisco, CA
- director information security San Francisco, CA
- corporate security manager San Francisco, CA
- security operations manager San Francisco, CA
- director global security San Francisco, CA
- senior director information security San Francisco, CA

