INFORMATION SECURITY OFFICER
RPM xConstruction
Key Responsibilities
Security Strategy & Governance
Education
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Security Strategy & Governance
- Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
- Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
- Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
- Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.
- Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
- Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
- Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.
- Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
- Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
- Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
- Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
- Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.
- Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
- Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
- Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
- Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.
- Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
- Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
- Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.
- Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
- Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.
- Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
- Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.
Education
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.
- 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
- Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
- Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CMMC Certified Professional (CCP) or Certified Assessor (CCA)
- CRISC (Certified in Risk and Information Systems Control)
- CCSP or equivalent cloud security certification
- Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
- Ability to translate technical risk into business terms for executive and ownership audiences.
- Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
- Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
- Sound judgment under pressure, particularly during incident response.
- Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
- Availability for occasional after-hours response in the event of a security incident.
- This position is located in McKinney, Texas. We do not compensate for relocation.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the INFORMATION SECURITY OFFICER in Mckinney, TX vacancy
- ...evolution of our SaaS platform while ensuring the stability, security, scalability, and performance of our solutions. The ideal candidate... ...awareness. Develop and enforce data protection and information security policies. Monitor technology performance, uptime...SuggestedLocal areaFlexible hours
- ...strategic guidance to help clients achieve robust, sustainable security across complex architectures. The ideal candidate will... ...level Mid-Senior level Employment type Contract Job function Information Technology Industries IT Services and IT Consulting IsExpired...SuggestedContract workWork from home
- ...Analyst (511) work role at an intermediate proficiency level and serves as the primary escalation point for confirmed or suspected security incidents across federal and Defense Industrial Base (DIB) client environments hosted in government-authorized cloud platforms....SuggestedShift workNight shiftRotating shift
- The SOC Analyst I is an entry-to-early-career security operations role responsible for front-line monitoring, triage, and initial response... ...SP 800-171 handling requirements for Controlled Unclassified Information (CUI) Required Qualifications 0-2 years of experience in a...SuggestedInternshipShift workNight shiftRotating shift
- ...Cybersecurity And Technology Controls Organization Drive the security of critical banking applications and platforms through hands-on offensive testing. As an Assessments & Exercises Vice President in the Cybersecurity and Technology Controls organization, you will...Suggested
- ...thinking organization, apply now.We are currently seeking a Information Security Manager- to join our team in Plano, Texas (US-TX), United States... ...year in R&D.Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and...Contract workWork at officeRemote workFlexible hours
- ...Assisting with the 5 L's of operations: Leadership: Recruit and onboard program staff and volunteers Location: Research, secure and prepare facility and transportation Logistics: Coordinate details and maintain positive communications with the school Loot...Local area
- ...resident care • Prepare and submit accurate and timely financial reports as requested by State regulatory bodies as well as the Home Office • Knowledgeable of state regulations • Ensure all state reportable incidents are reported, investigation completed and...Home officeFlexible hoursNight shiftAfternoon shift
- Globe Life in McKinney, Texas is seeking a Sr. IT Audit Manager to join our team. This hybrid role provides assurance and consulting services across Globe Life Inc. and subsidiaries, leading audits, evaluating controls, and guiding risk management. You will manage staff...
$105.1k
Orabase Solutions in McKinney, TX, is seeking a Consultant (Network Engineer) to engage in network administration and engineering. The role requires working with Cisco devices, configuring routers and switches, and monitoring network traffic. A Bachelor’s degree in a relevant...Relocation$426.79 per month
...Job Description attached Daily rate starting at $426.79, commensurate with experience Attachment(s): ~2026-2027 Calendar - 226 Admin, HS_MS Prin, HS AP_Adm Asst_PEIMS, Ath Dir, Tech, Band Dir, Dir Security.pdf ~ Job Description - Sr Dir of Tech 2026.pdf...Daily paidImmediate start- ...that Toyota's technology and IT operations are well controlled, secure, and aligned with business and audit requirements. What you... ...audits over key risk areas such as SDLC, Change Management, Information Security, Infrastructure and Networks, Third-Parties, Access Management...Work experience placementH1bRelocation package
- ...Juvenile Supervision Officer Collin County is seeking degreed candidates who are passionate about helping kids. If you want to meet residents of the Collin County Juvenile Detention Center where they are in their life journey, provide them with a safe environment, and...Shift workNight shiftDay shiftAfternoon shift3 days per week
- ...of Georgia. SonSoft Inc is growing at a steady pace specializing in the fields of Software Development, Software Consultancy and Information Technology Enabled Services.Job DescriptionAt least 8 years of experience in Cellular Carrier with emphasis on wireless technologies...Permanent employmentFull timeH1b
- ...Cheil USA / Corporate Services / Information Technology IT Director Plano, Texas... ...take ownership of the "Business of IT", securing the network, optimizing the budget, and... ...and cloud infrastructure for a 200-person office, managing a hybrid environment (50% Mac...Agency workFor contractorsWork at officeLocal areaImmediate startWorldwide
- ...teachers. They must be adept at leveraging data, managing financial information, and communicating effectively to inspire and motivate others.... ...Hiring Manager Title Chief Regional Impact and Operations Officer Functions CEO/President Non-Profit Management...Local area
$65.9 - $73.9 per hour
...interacting directly with stakeholders across security, compliance, engineering, and... ...Bachelor's degree in computer science, information systems, cybersecurity, engineering, or... ...hygiene platforms, Microsoft Defender for Office 365, or Microsoft Purview ~ Ability to...Hourly payContract workWork at office$122.65k - $204.41k
...capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and... ...Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can... ...recruiters will never ask for payment or banking information and will only use @nttdata.com, @...Temporary workWork at officeRemote workFlexible hours- A prominent technology firm is seeking a results-driven Business Development Manager to join their team in Plano, TX. The ideal candidate will have extensive experience in identifying growth opportunities and driving revenue in the software sector. Responsibilities include...Full time
- ...Chief Technology Officer (CTO) About the Company Pioneering media company focused on news & educational information about financial technology & cryptocurrency Industry Newspapers... ...team, and ensuring the platform is secure, compliant, and ready for enterprise-...
- ...position is anticipated to require the use of one or more High Security Access (HSA) systems. Users of these systems are subject to... ...environments using internal and external tools to detect personal information and data exposure related to executivesIdentify and remediate...
- Who we are: Chief of Staff Veterinarian (DVM) Fairview, Texas Stacy Road Pet Hospital Lead a Team. Practice Great Medicine. Shape the Future of a Growing Hospital. Stacy Road Pet Hospital is seeking an experienced Doctor of Veterinary Medicine (DVM) to join our team as...
- Collin County is seeking candidates for the position of Court Officer- District Court. Reporting to the District Judge. A Court Officer is responsible for, but not limited to, providing safety and security for the judge, courtroom personnel and others in the courtroom....Temporary workWork at office
- ...Responsibilities: Adheres to Integer’s Values and all safety, environmental, security and quality requirements including, but not limited to: Quality... ...and resiliency requirementsUse ARB outcomes to inform platform roadmaps and technical investment recommendationsEscalate...Full timeWork experience placementImmediate start
- Sage Integration Holdings LLC is seeking a CAD Engineer to create, revise, and maintain electronic drawings for integrated security systems, infrastructure, and electrical layouts. You will translate field notes into CAD files and ensure drawings meet internal standards...
- SRS Distribution Inc. is seeking a Senior Vice President, Supplier Relations in McKinney, TX, a hybrid role with up to 30% travel. You will lead the supplier ecosystem, negotiate major terms, and drive end-to-end inventory strategies to improve margins and service levels...
- ...International is looking to add an IT Cyber Security Analyst to our Security team located in... ...that the risk to the organization’s information posed by a variety of threats is minimized... .... Demonstrated knowledge of current MS Office products (especially Excel, Word & PowerPoint...
- ...Design and Implementation: Design, implement, and maintain highly secure cloud network architectures within Google Cloud Platform (GCP)... .... Minimum Education Bachelor's degree in computer science, information systems, or related degree, and/or equivalent formal training...Work experience placement
- ...Compliance OfficerThe job description below is for Code Compliance Officer, however, based on experience and qualifications, candidates... ...prepares cases for judicial process. Acts as a public information resource. Performs related work as required.General Expectations...Start working todayLocal areaWeekend workAfternoon shift
- A leading technology solutions provider in Plano, Texas, is seeking a Qualys Threat and Vulnerability Management Cyber Security Advisor. This pivotal role involves managing cyber security vulnerabilities and coordinating remediation efforts across teams. Candidates should...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to INFORMATION SECURITY OFFICER. Be the first to apply!
Related searches
- data center security officer Mckinney, TX
- information security lead Mckinney, TX
- information security Mckinney, TX
- chief information security officer ciso
- ciso
- information security officer
- business information security officer
- information systems security officer sso
- remote ciso
- information systems security officer


