Director of IT Security
$137.5k - $229.5kETAP
ETAP empowers customers to make informed decisions throughout the life cycle of their projects with innovative software solutions for electrical systems. By applying ETAP solutions, customers experience continuous intelligence during design and engineering and into operations and maintenance using a unified electrical digital twin platform. ETAP supports customers in their digital transformation and sustainable energy transitions for a green and smart future, helping them to prioritize safety, maximize reliability, and stay resilient.Our employees' passion for excellence, innovation, and customer satisfaction is our most-prized resource. If you share that passion — and want to be part of a company that leads the energy transition towards a cleaner and more resilient world for future generations — we invite you to join us!ETAP is committed to creating a diverse work environment and is proud to be an Equal Opportunity Employer.Title: Director Of IT SecurityLocation: Irvine, CAJob type: Full-time / HybridDirector of IT SecurityReports to the CIO. Works closely with leaders across IT, Engineering/R&D, QA/Quality, Legal, HR, Finance, and Operations.Collaborates with parent and sister company Security teams to align standards, share risk and incident intelligence, and coordinate audits and assurance activities while maintaining clear ownership and compliance boundariesBased in Irvine, CA. International and domestic travel required for audits, certifications, federal/customer compliance activities, and collaboration with global teams.Position SummaryThe Director of IT Security serves as the company’s security hub and “quarterback”—aligning IT, Engineering/R&D, Quality, Legal, and business leadership around a clear security strategy, and coordinates end-to-end delivery across teams that may not sit within a dedicated security organization.This role drives prioritization, establishes clear ownership, and coordinates end-to-end security operations, keeps execution moving (risk management, incidents, audits, vendor/security reviews, and training), and provides timely visibility to leadership on posture, gaps, and remediation progress.In addition, this position owns and coordinates security obligations tied to the National Security Agreement (NSA) and related federal/customer requirements, including audit readiness, documentation, and evidence management - ensuring the organization can demonstrate compliance while maintaining operational efficiency.Success depends on the ability to influence without authority, create clarity, and prioritize, partnering closely with Engineering/R&D, Quality, Legal, HR, Finance, Operations, and business leaders to embed security into day-to-day operations and product development.Key OutcomesA practical security program that scales with clear priorities, minimal bureaucracy, and measurable risk reduction.Audit- and customer-ready security posture (evidence organized, controls operating, owners assigned).Cross-functional security ownership: security responsibilities embedded across IT, Engineering, and business teams rather than centralized in a large security staff.Reliable incident response, monitoring, and reporting pathways that work with limited tools and people.Sustained compliance with NSA obligations and related security plans (e.g., FOCI mitigation artifacts) with predictable cadence and governance.Key Responsibilities1) Security Leadership and GovernanceEstablish and maintain the company’s security strategy, annual roadmap, and control framework aligned to business priorities and resource constraints.Lead a lightweight security governance cadence (e.g., monthly risk review, quarterly executive updates) to drive decisions, remove blockers, and maintain accountability.Define security standards, patterns, and guardrails that teams can follow without heavy security staffing.Own security policies, exceptions, and compensating controls; ensure policies are practical, adopted, and periodically reviewed.2) Risk ManagementMaintain an enterprise risk register, including IT, product/engineering, vendor, and compliance risks; drive mitigation plans with clear owners and deadlines.Provide security architecture direction for cloud/services, endpoints, identity, networks, and corporate applications - focusing on standardization and simplification.Partner with R&D to implement scalable controls (e.g., MFA, least privilege, secure configurations, patching SLAs, logging baselines).3) Cross-Functional PartnershipCollaborate with Engineering/R&D to implement secure development practices appropriate for the organization (secure SDLC expectations, code and dependency risk management, environment protections).Partner with QA/Quality and Legal to maintain certifications, manage findings, and ensure contractual/regulatory obligations are met.Partner with Legal on interpretation of regulatory, NSA, customer, and contractual security obligations, translating requirements into operational controls.· Influence leaders to build security responsibilities into roles, objectives, and operating routines.Partner with parent company and sister company Security teams to align security strategy, standards, and risk posture; share risk and incident intelligence; coordinate on shared controls, incidents, audits, and assurance activities; and ensure efficient information sharing while respecting organizational boundaries, regulatory obligations, and data segregation requirements.4) Compliance, Audit Readiness & Evidence ManagementLead planning and coordination for internal, customer, third-party, parent-company, and government-related audits/reviews.Support review and operationalization of customer and partner security obligations in coordination with Legal, ensuring commitments are implementable and evidence backed.Maintain an evidence program: control narratives, procedures, test results, access reviews, training completion, incident records, and corrective actions.Support ISO 27001 and other applicable certifications/attestations; ensure alignment and minimize duplicate work across frameworks.5) National Security Agreement (NSA) & Federal/Controlled Data ResponsibilitiesServe as the primary Security authority accountable for defining sustainable security controls required by the NSA and government-approved security plans.Protect classified, controlled unclassified information (CUI), export-controlled, and NSA-governed data through appropriate technical and procedural safeguards.Maintain alignment with relevant frameworks and requirements (as applicable), such as NIST, ISO, and GDPR and related customer/government security expectations.Support FOCI mitigation requirements by maintaining and operationalizing Technology Control Plans, Electronic Communications Plans, Access Control Plans, and related procedures.Ensure monitoring, logging, and escalation processes meet NSA-driven requirements, including reporting timelines and documentation.6) Incident Response, Monitoring & Business ContinuityOwn and run incident response planning and execution: triage, containment, investigation, eradication, recovery, and post-incident improvements.Coordinate NSA/customer-required notifications and reporting when protected data or environments are implicated.Ensure pragmatic monitoring and logging coverage with available tooling; define alert thresholds and an escalation model that works with limited staff.Partner with business functions on business continuity and disaster recovery planning, tabletop exercises, and periodic restoration testing.7) Third-Party/Vendor SecurityPartner with business functions on a right-sized vendor risk management program: tier vendors, assess risk, review contracts/security addenda, and track remediation.Ensure critical vendors meet baseline security requirements (e.g., MFA, breach notification, data handling, subcontractor controls).8) Security Awareness & TrainingDeliver practical, role-based security training (general workforce + privileged access users + NSA-specific training where required).Build a culture of “secure-by-default” behaviors through concise guidance, easy-to-follow playbooks, and recurring communications.This is a hands-on leadership role. Sets direction and drives key deliverables (policies, audit evidence, incident leadership, stakeholder alignment), leveraging a combination of internal resources and external partners/MSSPs as needed.QualificationsRequiredBachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent experience.10+ years in information security/IT risk roles with at least 5 years leading security programs or teams.Demonstrated experience leading audits and compliance readiness (internal/external/customer), including documentation and evidence management.Strong ability to translate security requirements into practical controls in an environment with limited dedicated resources.Proven executive communication skills: clear risk narratives and recommendations.Strongly PreferredExperience with NSA environments, FOCI mitigation, or government-regulated security programs.Familiarity with NIST Cybersecurity Framework 2.0, RMF concepts and secure controlled environment practices.Experience supporting product development/engineering environments and CI/CD ecosystems.Preferred CertificationsCISSP, CISM, CISA, CRISC, or similar.Core CompetenciesRisk-based prioritization in resource-constrained environmentsCross-functional governance and stakeholder managementAudit readiness and evidence-driven complianceIncident leadership and decision-making under pressureClear writing: policies, procedures, control narratives, and plansIntegrity, discretion, and national security awarenessSalary Range: $137,500 - $229,500 AnnualThis pay range represents the minimum and maximum compensation that the position offers, and final compensation can vary within the range depending on work location, job experience, skills, and relevant educational attainment and/or training.ETAP requires all successful applicants to undergo and pass a comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third party personal data may involve additional background check criteria.ETAP is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business.Come and join ETAP to create the transformative technology that enables our customers to engineer a better world.SummaryLocation: Irvine, California, United States of AmericaType: Full time
$113k - $149k
...software. Well versed in a combination of Information Technology, Security and government accreditation processes, ISSOs are able to... ...from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.Via Agency Partner:...SuggestedFull timeWork experience placementImmediate start- ...Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models & auto brands Industry Market Research Type Privately Held, Private Equity-backed Founded 1968 Employees...Suggested
$200k - $250k
About Codazen Codazen is a technology consultancy that helps organizations move faster without losing control. We design and engineer the platforms, data systems, and digital products that enable leaders to make better decisions and turn strategic intent into measurable...SuggestedFull timeTemporary workLocal areaRemote work$265k - $300k
...Chief Information Officer Department: IT Employment Type: Full Time... ...build a high-performing team, and provide a secure, scalable foundation that enables leaders... ...advise executive leadership and the Board of Directors on technology strategy, enterprise and cybersecurity...SuggestedFull timeWork at officeMonday to FridayFlexible hours$82.6k - $162.8k
Position Summary As a Consultant - Cyber Defense and Resilience, you will support the design and deployment of security operations solutions that help clients improve monitoring, detection, response, and automation capabilities. In this client-facing role, you will...SuggestedLocal areaVisa sponsorship$105.4k - $207.8k
...Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security operations across monitoring, detection, response, and automation. In this client-facing role, you will work...Local areaVisa sponsorship$82.6k - $162.8k
...the scale, complexity, and growth environment to build your career. In this role, you will support organizations as they modernize security operations through advanced analytics, cyber data engineering, and AI-enabled capabilities. You will work with leading...Local areaVisa sponsorship$97.61k - $188.38k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll doAs... ...of business processes, internal control risk management, IT controls and related standardsResponsible to install, integrate,...Local areaVisa sponsorship$144.9k - $265.8k
...consolidations and hybrid identity programs. ~ Translating business, security and regulatory needs into practical identity architecture,... ...or other adjacent identity, governance, privileged access or IT service management platforms. ~ Microsoft identity, cloud,...Full timeSummer holidayFlexible hours- ...knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In...Local area
$134.5k - $265.1k
...organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you’ll work with leading organizations to strengthen security, enable innovation, and reduce threat exposure. Join Deloitte’s Cyber Defense & Resilience Continuous Threat Exposure Management (...Local area- ...that accelerate decarbonization and strengthen domestic energy security. POSITION OVERVIEW The Chief Technology Officer (CTO – Nuclear... ...leadership experience at the level of CTO, VP of Engineering, Director of Nuclear, or equivalent. Hands-on experience with SMR,...Local areaRelocation package
- ...Team Leadership & Development: Build and lead a high-performing IT team; foster collaboration, innovation, and continuous... ...integrations, and advanced analytics to drive decisions and outcomes Security & Infrastructure: Ensure strong cybersecurity, data privacy,...
- ..., with a proven track record of executive influence, and the ability to build AI-enabled teams. A minimum of 10 years of progressive IT leadership experience, particularly in direct-to-consumer industry and eCommerce, is essential. The role demands a candidate with a strong...
$146k - $194k
...infrastructures to support global operations. Information Systems Security Managers are in charge of directly supporting business lines... ...Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.Conduct security risk assessments,...Full timeContract workWork experience placementImmediate start$155.6k - $306.8k
...live data and systems• Ensuring deployed AI systems meet production bars for evaluation, guardrails, observability, reliability, security, and cost/performance management• Building automated controls and response workflows that support disaster recovery orchestration...Local areaRemote work$110.7k - $218.3k
...across environments, and track progress against risk-reduction goals.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer II on the Cyber Defense & Resilience Continuous Threat Exposure Management (CTEM) team, you will be responsible for…...Local area$134.5k - $265.1k
Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology...Local areaVisa sponsorship$144.2k - $265.6k
...solutions that not only address regulatory requirements, but also enable secure growth, strengthen trust, and improve operational effectiveness.... ...across organizational silos, including multifunctional teams of IT professionals, legal/compliance teams, and business...Work experience placementLocal area- Chief Growth Officer (CGO) About the Company Charitable organization focused on bringing resources to developing countries Industry International Trade and Development Type Privately Held, VC-backed Founded 2012 Employees 501...
$189.2k - $372.9k
...data and systems• Setting and owning standards for AI production practices — evaluation, guardrails, observability, reliability, security, and cost/performance management — across multiple solutions or engagements• Leading, mentoring, and managing the performance and...Local areaRemote work$134.5k - $265.1k
...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Manager, Strategy, Growth, and Transformation on the Cyber...Local area$102.17k
...sector clients across the country. Job Description Join the Trinnex Security Team as a Senior Cyber Security Analyst, where you will operate... ...scenarios across infrastructure and applications. Partner with IT and software development teams to remediate vulnerabilities and...H1b$80k - $92.5k
...the ability to obtain a Public Trust LTS is seeking a Cyber Security Analyst to support the Department of Veterans Affairs (VA) Health Portfolio. The Health PMO support contract provides IT program management, project management, technical management, financial...Permanent employmentContract workWork at officeRemote work$170k - $230k
Job ID: 42654Reference: 300015904945092Location: Los Angeles, CA, United States | Irvine, CA, United States | San Diego, CA, United StatesDepartment: Water EngineeringBusiness Unit: ANA United StatesWork Type: HybridDate Posted: 2026-07-20Arcadis is the world's leading ...Full timePart timeLocal area- ...Bachelor’s degree in a related field preferred but not required. 5+ years of experience in a SOC or similar security environment. Expertise with SIEM, EDR, CSPM tools; strong skills in SQL/KQL/Cypher for data analysis. Proven ability to lead complex investigations and...Contract work
- ...results and rapidly improving models through real-field applications. Learn more at About the Job We're hiring a Director of IT, Infrastructure & Security to own Field AI's IT operations, corporate and cloud security, and compliance program end-to-end. You'll inherit a...Remote work
$129k - $171k
...strategically overseeing M&A integrations.ABOUT THE ROLEAs a technical IT Operations Manager for Acquisitions, you will architect and... ...execution for consolidating disparate infrastructures into a unified, secure, and scalable operating model that enables Anduril's long-term...Full timeWork experience placementImmediate start$85.56 - $152.95 per hour
...patient-centered care are paramount, we invite you to explore this exceptional leadership opportunity. The Role The Executive Director, Imaging Services, serves as the division's key administrative leader, overseeing imaging services and integrating acute and...Minimum wageFull timeWork at officeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of IT Security. Be the first to apply!



