Director, National Security-Cybersecurity Governance
$130k - $175kAlvarez & Marsal
Description
About Alvarez & Marsal Alvarez & Marsal is a premier independent global professional services firm specializing in providing turnaround management, restructuring, performance improvement and corporate advisory services. Our talent drives our success, resulting in our growing Disputes and Investigations practice becoming one of the most respected in the industry. From the boardroom to the courtroom, the firm delivers a wide array of solutions to contentious situations by drawing on the deep skills, diverse disciplines and experiences of its professionals. We are recognized by Global Arbitration Review as one of the leading firms of independent experts for arbitration and considered a top three firm by Who's Who Legal based on the number of experts across the globe. Our clients include major banks, leading law firms, private equity firms and well-known corporations and upper-mid-sized companies. The Team At A&M you will have the opportunity to work with a diverse team of supportive and motivated professionals that love to share their knowledge and depth of industry experience with others. A&M's Disputes and Investigations practice comprises professionals from a wide range of backgrounds, who bring and share their deep expertise in conducting investigations and delivering expert witness reports. We have an inclusive developmental environment where everyone has the opportunity to learn and grow. Our culture is characterized by openness and entrepreneurial thinking, with a foundation of mutual respect and high-quality standards for our work. We strive to remove bureaucracy in favor of recognizing effort and results through advancement opportunities and a motivating performance-based reward structure. How you will contribute With the rapidly changing geopolitical environment, competition for sensitive technologies, and risks associated with potential exploitation of sensitive personal and business data, demand for national security-focused risk analysis and mitigation is growing significantly. Our team supports organizations, investors and counsel in identifying, assessing, and reducing national security-related risk through modern security architectures and enterprise-grade solutions. We focus on implementing Zero Trust security frameworks, establishing robust Identity and Access Management (IAM) controls, and embedding regulatory requirements into business systems and processes. Our approach facilitates transparency between companies and regulators by leveraging data analytics, automated compliance monitoring, and advanced security tooling. The team serves as fiduciary to U.S. government agencies as either third-party monitor or third-party auditor, ensuring adherence to federal security standards and frameworks. Responsibilities: • Lead cross-functional project teams in executing advisory, oversight, and audit projects related to Foreign Direct Investment (FDI) national security reviews, export and technology controls, and Cybersecurity Maturity Model Certification (CMMC). Develop comprehensive project plans, establish key milestones, and manage resource allocation using enterprise project management methodologies and tools. • Design and implement Zero Trust architecture frameworks and IAM solutions, including privileged access management (PAM), role-based access control (RBAC), and continuous authentication mechanisms. Collaborate with client security personnel to define and document security controls for distributed, big data systems with emphasis on least-privilege access principles. • Conduct enterprise-wide security assessments to verify the efficacy of administrative, technical, and physical safeguards, with particular focus on identity governance, access management, and Zero Trust implementation. Evaluate security control maturity against industry frameworks such as NIST 800-53, ISO 27001, and CMMC. • Direct comprehensive security assessments of applications and software, including: (i) reviewing architecture diagrams with emphasis on identity and access flows; (ii) interviewing personnel across DevSecOps teams; (iii) evaluating IAM integration points and Zero Trust implementation; (iv) overseeing static and dynamic code analysis; (v) managing network penetration testing; and (vi) preparing detailed technical reports for senior counsel, executives, and national security officials. • Analyze and interpret penetration test results, focusing on identity-related vulnerabilities, access control weaknesses, and deviations from Zero Trust principles. Develop remediation roadmaps aligned with enterprise architecture standards. • Implement and integrate security technologies including Security Information and Event Management (SIEM), Identity Governance and Administration (IGA), and Privileged Access Management (PAM) solutions to enable automated compliance monitoring and security oversight. • Create and maintain project management artifacts including work breakdown structures, risk registers, and resource allocation plans. Establish project governance frameworks and reporting mechanisms to ensure alignment with organizational objectives and regulatory requirements. • Availability for up to 20% travel required to client sites and security assessment locations. Qualifications: • 8+ years of experience with Technology Companies that deliver controlled technology nationally and internationally • Experience with NIST CSF, NIST SP 800-53, NIST SP 800-171, NIST SP 800-218, NIST SP 800-161, and/or ISO 27001 • Experience working in cybersecurity governance (i.e., experience working with NIST CSF; NIST 800-171 and -53; CIS-18 IG1 and ISO 27001) • Proficiency in at least one programming language (e.g., Python, Java, etc.) • Background in network and cloud-based platforms (e.g., GCP, AWS, Kubernetes, etc.) • Familiarity with containerization technologies and deployments • Experience with Big Data platforms (on premise and cloud) • Ability to obtain a USG security clearance • One or more relevant industry certification: CompTIA Security+, CompTIA CySA+, CompTIA CASP+, CISSP, CISM, CISA, ISO 27001, or comparable certifications Your journey at A&M We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person's unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals. Full-time Positions and Part-time Positions Over 30 hours Regular employees working 30 or more hours per week are also entitled to participate in Alvarez & Marsal Holdings' fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined from time to time as well as a 401(k) retirement plan. Provided the eligibility requirements are met, employees will also receive a discretionary contribution to their 401(k) from Alvarez & Marsal. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type. Click here for more information regarding A&M's benefits programs. The salary range is $130,000 - $175,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, A&M offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details. Alvarez & Marsal recruits on an ongoing basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) that they are qualified for and that are of interest to them. A&M does not require or administer lie detector tests as a condition of employment or continued employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-NM1
About Alvarez & Marsal Alvarez & Marsal is a premier independent global professional services firm specializing in providing turnaround management, restructuring, performance improvement and corporate advisory services. Our talent drives our success, resulting in our growing Disputes and Investigations practice becoming one of the most respected in the industry. From the boardroom to the courtroom, the firm delivers a wide array of solutions to contentious situations by drawing on the deep skills, diverse disciplines and experiences of its professionals. We are recognized by Global Arbitration Review as one of the leading firms of independent experts for arbitration and considered a top three firm by Who's Who Legal based on the number of experts across the globe. Our clients include major banks, leading law firms, private equity firms and well-known corporations and upper-mid-sized companies. The Team At A&M you will have the opportunity to work with a diverse team of supportive and motivated professionals that love to share their knowledge and depth of industry experience with others. A&M's Disputes and Investigations practice comprises professionals from a wide range of backgrounds, who bring and share their deep expertise in conducting investigations and delivering expert witness reports. We have an inclusive developmental environment where everyone has the opportunity to learn and grow. Our culture is characterized by openness and entrepreneurial thinking, with a foundation of mutual respect and high-quality standards for our work. We strive to remove bureaucracy in favor of recognizing effort and results through advancement opportunities and a motivating performance-based reward structure. How you will contribute With the rapidly changing geopolitical environment, competition for sensitive technologies, and risks associated with potential exploitation of sensitive personal and business data, demand for national security-focused risk analysis and mitigation is growing significantly. Our team supports organizations, investors and counsel in identifying, assessing, and reducing national security-related risk through modern security architectures and enterprise-grade solutions. We focus on implementing Zero Trust security frameworks, establishing robust Identity and Access Management (IAM) controls, and embedding regulatory requirements into business systems and processes. Our approach facilitates transparency between companies and regulators by leveraging data analytics, automated compliance monitoring, and advanced security tooling. The team serves as fiduciary to U.S. government agencies as either third-party monitor or third-party auditor, ensuring adherence to federal security standards and frameworks. Responsibilities: • Lead cross-functional project teams in executing advisory, oversight, and audit projects related to Foreign Direct Investment (FDI) national security reviews, export and technology controls, and Cybersecurity Maturity Model Certification (CMMC). Develop comprehensive project plans, establish key milestones, and manage resource allocation using enterprise project management methodologies and tools. • Design and implement Zero Trust architecture frameworks and IAM solutions, including privileged access management (PAM), role-based access control (RBAC), and continuous authentication mechanisms. Collaborate with client security personnel to define and document security controls for distributed, big data systems with emphasis on least-privilege access principles. • Conduct enterprise-wide security assessments to verify the efficacy of administrative, technical, and physical safeguards, with particular focus on identity governance, access management, and Zero Trust implementation. Evaluate security control maturity against industry frameworks such as NIST 800-53, ISO 27001, and CMMC. • Direct comprehensive security assessments of applications and software, including: (i) reviewing architecture diagrams with emphasis on identity and access flows; (ii) interviewing personnel across DevSecOps teams; (iii) evaluating IAM integration points and Zero Trust implementation; (iv) overseeing static and dynamic code analysis; (v) managing network penetration testing; and (vi) preparing detailed technical reports for senior counsel, executives, and national security officials. • Analyze and interpret penetration test results, focusing on identity-related vulnerabilities, access control weaknesses, and deviations from Zero Trust principles. Develop remediation roadmaps aligned with enterprise architecture standards. • Implement and integrate security technologies including Security Information and Event Management (SIEM), Identity Governance and Administration (IGA), and Privileged Access Management (PAM) solutions to enable automated compliance monitoring and security oversight. • Create and maintain project management artifacts including work breakdown structures, risk registers, and resource allocation plans. Establish project governance frameworks and reporting mechanisms to ensure alignment with organizational objectives and regulatory requirements. • Availability for up to 20% travel required to client sites and security assessment locations. Qualifications: • 8+ years of experience with Technology Companies that deliver controlled technology nationally and internationally • Experience with NIST CSF, NIST SP 800-53, NIST SP 800-171, NIST SP 800-218, NIST SP 800-161, and/or ISO 27001 • Experience working in cybersecurity governance (i.e., experience working with NIST CSF; NIST 800-171 and -53; CIS-18 IG1 and ISO 27001) • Proficiency in at least one programming language (e.g., Python, Java, etc.) • Background in network and cloud-based platforms (e.g., GCP, AWS, Kubernetes, etc.) • Familiarity with containerization technologies and deployments • Experience with Big Data platforms (on premise and cloud) • Ability to obtain a USG security clearance • One or more relevant industry certification: CompTIA Security+, CompTIA CySA+, CompTIA CASP+, CISSP, CISM, CISA, ISO 27001, or comparable certifications Your journey at A&M We recognize that our people are the driving force behind our success, which is why we prioritize an employee experience that fosters each person's unique professional and personal development. Our robust performance development process promotes continuous learning, rewards your contributions, and fosters a culture of meritocracy. With top-notch training and on-the-job learning opportunities, you can acquire new skills and advance your career. We prioritize your well-being, providing benefits and resources to support you on your personal journey. Our people consistently highlight the growth opportunities, our unique, entrepreneurial culture, and the fun we have together as their favorite aspects of working at A&M. The possibilities are endless for high-performing and passionate professionals. Full-time Positions and Part-time Positions Over 30 hours Regular employees working 30 or more hours per week are also entitled to participate in Alvarez & Marsal Holdings' fringe benefits consisting of healthcare plans, flexible spending and savings accounts, life, AD&D, and disability coverages at rates determined from time to time as well as a 401(k) retirement plan. Provided the eligibility requirements are met, employees will also receive a discretionary contribution to their 401(k) from Alvarez & Marsal. Additionally, employees are eligible for paid time off including vacation, personal days, seventy-two (72) hours of sick time (prorated for part time employees), ten federal holidays, one floating holiday, and parental leave. The amount of vacation and personal days available varies based on tenure and role type. Click here for more information regarding A&M's benefits programs. The salary range is $130,000 - $175,000 annually, dependent on several variables including but not limited to education, experience, skills, and geography. In addition, A&M offers a discretionary bonus program which is based on a number of factors, including individual and firm performance. Please ask your recruiter for details. Alvarez & Marsal recruits on an ongoing basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) that they are qualified for and that are of interest to them. A&M does not require or administer lie detector tests as a condition of employment or continued employment. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
#LI-NM1
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Director, National Security-Cybersecurity Governance in Boston, MA vacancy
- A leading IT security firm in New Hampshire seeks an experienced Director of Information Security to enhance data protection measures. You... ...have over 10 years of experience in cybersecurity and a strong background in data governance. This role offers competitive compensation...Suggested
$100k
...Description The Organization: MassChallenge The Role: Sr. Director, Industry Alliances – National Security & Resiliency with focus on Defense, Dual-Use, and... ...: sourcing, developing, and closing corporate and government partnerships within the national security and energy...Suggested- ...technical leader to join our Global Cybersecurity organization. As the Sr. Director, Platform Security & Architecture, you will be at... ...and continuous monitoring. Governance & Operations: Establish a... ...in these positions across the national market and provides an...SuggestedLocal area
$76.34k - $107.82k
...University seeks an Associate Director, Security Technology to provide... ...for the design, deployment, governance, and continuous improvement... ..., and integrations. Ensure cybersecurity, data privacy, and regulatory... ...to race, religion, color, national origin, age, sex, sexual orientation...SuggestedContract workWorldwide$108.88k - $163.32k
...commerce, Technology and more. Overview The Security Engineering Manager plays a critical... ...environment by monitoring and governing security policies in close coordination... ...capabilities or skills. Strong understanding of cybersecurity principles, threat vectors, and...SuggestedFull timeWork at officeRemote workFlexible hoursWeekend work$260k - $346k
...Senior Director, Cloud Security, Compliance Lead San Francisco, CA USA... ...the end-to-end security, governance, risk management, and regulatory... ..., Information Security, Cybersecurity, Engineering, or related field... ...ancestry, religion, sex, national origin, sexual orientation...Full timeContract workWork at officeLocal areaFlexible hours$130k - $140k
...Description Role: Manager, Security Operations... ..., NC) Department: Cybersecurity - Security Operations... ...Reports to: Senior Director, Security Operations... ...operational delivery, governance, and assurance of cybersecurity... ...expression, age, national origin, protected...Full time$160k - $174.8k
...Join Brandeis University as Director of Information Security Brandeis University... ...Security to lead our cybersecurity program and safeguard the... ...implement, and manage policies, governance, and risk management... ...identity and expression, national or ethnic origin, sex,...Work experience placement- Draper is seeking a Program Manager 1 to deliver innovative technical solutions for National Security missions in Cambridge, MA. You will oversee program execution, manage customer relationships, and lead multi-functional teams while ensuring project delivery within budget...
$100k - $150k
...An exciting opportunity within the Security Strategy and Governance (SSG) team whose mission is to ensure... ...Systems Control, CompTIA Cybersecurity Analyst or Certified Fraud Examiner... ...basis of race, ethnicity, citizenship, national origin, color, religion or religious...Flexible hours$150k - $220k
Senior Director, Cloud Security & AI Security Salary Range: $150,000.00 To $220,000.00 Annually... ...business impact. As a core member of our cybersecurity leadership team reporting directly... ...AI security ecosystems—establishing governance, controls, and compliance across our...Temporary workFlexible hours$234k - $322k
...goals. This role demands transformation in process discipline, governance, strategic influence, and automation. You will architect the... ...expression, sexual orientation, marital status, race, color, national origin, ancestry, ethnicity, religion, age, veteran status, disability...Temporary workLocal areaShift work$91.4k - $187k
...Federal Consulting team seeks a Director of Delivery & Operations to... ...risk early through gateway, governance, adoption, and readiness KPIs... ...issue resolution across IT, security, finance, deal desk, and delivery... ...race, color, religion, sex, national origin, sexual orientation,...Temporary workWork experience placementWork at officeFlexible hours$150k - $220k
...HATHAWAY SPECIALTY INSURANCE is looking for a Senior Director of Cloud Security & AI Security to lead the cloud security strategy in... .... The successful candidate will have 5-10+ years in cybersecurity, drive governance and operational security, and enhance incident...Work at office- ...Your role As the National Operations Manager , you are responsible for leading, optimizing, and executing all in house and field... ...Collaborate with procurement, logistics, and engineering teams to secure required service resources. • Manage the operations budget,...
$124.23k - $198.63k
...Platform Team is looking for a Security Technical Account Manager... ...reports directly to the Global Director, Red Hat Services Cross... ...Security +, (ISC)² Certified in Cybersecurity (CC), Certified Ethical... ...orientation, gender identity, national origin, ancestry, citizenship...Permanent employmentFull timeContract workWork experience placementWork at officeRemote workFlexible hours$95k - $245k
...company is seeking a Program Manager 1 in Cambridge, MA. This role will involve delivering innovative technical solutions for national security missions, managing programs, and building customer relationships. Qualified candidates will have a degree in a technical field...$150k - $175k
...services nationwide. About ECG ECG is a national consulting firm that is redefining... ...Your Opportunity with ECG: Associate Director of Cybersecurity, Physical Security, and Artificial Intelligence (AI) Governance Reporting to the IT director, the associate...Permanent employmentFull timeWork at officeRemote work- ...programs. This role focuses on driving operational excellence, governance, and improving the employee experience across a growing global... ...with industry regulations. Join us in shaping the future of sports entertainment technology. #J-18808-Ljbffr National Geographic
$170.6k - $390k
...working world. Join EY’s Cybersecurity consulting practice – the best... ...your career in information security! The opportunity The... ...designing, implementing, and governing secure network architectures... ..., genetic information, national origin, protected veteran status...Summer holidayRemote workFlexible hours- Director, Information Security 1 General Overview Functional Area: Information Technology... ...of Data Security and Governance to lead our comprehensive... ...0 years of experience in cybersecurity and data governance, with... ..., gender identity, national origin, disability or status...Work at office
$255k - $424.9k
...Regeneron is seeking an Executive Director, Worldwide Operations Office to join our PV... ...and countries by defining the scope and governance of regional PV Hubs, establishes clear... ...pregnancy or parental status, age, disability, nationality, citizenship status, ethnic or national...Work at officeLocal areaWorldwide$125.2k - $187.8k
A major grocery retailer is seeking a Security Engineering Manager to oversee security policies and manage incident response for technology environments. This role requires over ten years of relevant experience and a bachelor's degree in a related field. Key responsibilities...Flexible hours$99k - $232k
...Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type... ...to identify vulnerabilities, develop secure systems, and provide proactive solutions... ...without regard to race; color; religion; national origin; sex (including pregnancy, sexual...Full timeH1b- A prominent food retailer is seeking a Security Engineering Manager to monitor security policies and manage incident response. This... ...experience, a bachelor's degree, and a strong understanding of cybersecurity principles. The position offers a hybrid work environment and...
$70 - $88.5 per hour
...seeking a Systems Engineer in Dedham, MA, for a long-term W2 contract position. The ideal candidate will develop mission-critical Cybersecurity Manager Applications as part of a cross-functional team. Required qualifications include U.S. Citizenship, Secret Clearance at...Hourly payLong term contract- ...Description & Requirements The Senior Director, Global Information Security and Risk is the senior-most leader... ...and investment decision-making. Govern strategic security tooling, vendor... ...employment without regard to race, national origin, religion, age, color, sex,...Work at officeLocal areaFlexible hours3 days per week
$171.78k - $190.34k
...controls, and change management practices to maintain a stable and secure technology ecosystem during a critical growth phase as we... ...compromising data security or integrity. Proficiency with common cybersecurity frameworks and best practices. Compensation The...- ...Description: Job Summary We are seeking a visionary Senior Director of Cybersecurity Operations to lead and elevate enterprise cyber defense... ..., vulnerability management, disaster recovery, and security operations, shaping how the organization anticipates, detects...
- ...Description Manage accounting of revenue and costs and ensure governance in financial processes Own, manage, and maintain project,... ...orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director, National Security-Cybersecurity Governance. Be the first to apply!
Related searches
- security systems manager Boston, MA
- senior security manager Boston, MA
- security manager Boston, MA
- security engineering manager Boston, MA
- product security manager Boston, MA
- director information security Boston, MA
- corporate security manager Boston, MA
- security operations manager Boston, MA
- director global security Boston, MA
- senior director information security Boston, MA


