Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Director of IT Security

$137.5k - $229.5k

Dormont Manufacturing Co

Director Of IT Security

Location: Irvine, CA

Job type: Full-time / Hybrid

Reports to: CIO. Works closely with leaders across IT, Engineering/R&D, QA/Quality, Legal, HR, Finance, and Operations.

Collaborates with parent and sister company Security teams to align standards, share risk and incident intelligence, and coordinate audits and assurance activities while maintaining clear ownership and compliance boundaries.

Based in Irvine, CA. International and domestic travel required for audits, certifications, federal/customer compliance activities, and collaboration with global teams.

Position Summary

The Director of IT Security serves as the company’s security hub and “quarterback”—aligning IT, Engineering/R&D, Quality, Legal, and business leadership around a clear security strategy, and coordinates end-to-end delivery across teams that may not sit within a dedicated security organization.

This role drives prioritization, establishes clear ownership, and coordinates end-to-end security operations, keeps execution moving (risk management, incidents, audits, vendor/security reviews, and training), and provides timely visibility to leadership on posture, gaps, and remediation progress.

In addition, this position owns and coordinates security obligations tied to the National Security Agreement (NSA) and related federal/customer requirements, including audit readiness, documentation, and evidence management—ensuring the organization can demonstrate compliance while maintaining operational efficiency.

Success depends on the ability to influence without authority, create clarity, and prioritize, partnering closely with Engineering/R&D, Quality, Legal, HR, Finance, Operations, and business leaders to embed security into day-to-day operations and product development.

Key Outcomes

  • A practical security program that scales with clear priorities, minimal bureaucracy, and measurable risk reduction.
  • Audit- and customer-ready security posture (evidence organized, controls operating, owners assigned).
  • Cross-functional security ownership: security responsibilities embedded across IT, Engineering, and business teams rather than centralized in a large security staff.
  • Reliable incident response, monitoring, and reporting pathways that work with limited tools and people.
  • Sustained compliance with NSA obligations and related security plans (e.g., FOCI mitigation artifacts) with predictable cadence and governance.

Key Responsibilities

1) Security Leadership and Governance

  • Establish and maintain the company’s security strategy, annual roadmap, and control framework aligned to business priorities and resource constraints.
  • Lead a lightweight security governance cadence (e.g., monthly risk review, quarterly executive updates) to drive decisions, remove blockers, and maintain accountability.
  • Define security standards, patterns, and guardrails that teams can follow without heavy security staffing.
  • Own security policies, exceptions, and compensating controls; ensure policies are practical, adopted, and periodically reviewed.

2) Risk Management

  • Maintain an enterprise risk register, including IT, product/engineering, vendor, and compliance risks; drive mitigation plans with clear owners and deadlines.
  • Provide security architecture direction for cloud/services, endpoints, identity, networks, and corporate applications—focusing on standardization and simplification.
  • Partner with R&D to implement scalable controls (e.g., MFA, least privilege, secure configurations, patching SLAs, logging baselines).

3) Cross-Functional Partnership

  • Collaborate with Engineering/R&D to implement secure development practices appropriate for the organization (secure SDLC expectations, code and dependency risk management, environment protections).
  • Partner with QA/Quality and Legal to maintain certifications, manage findings, and ensure contractual/regulatory obligations are met.
  • Partner with Legal on interpretation of regulatory, NSA, customer, and contractual security obligations, translating requirements into operational controls.
  • Influence leaders to build security responsibilities into roles, objectives, and operating routines.
  • Partner with parent company and sister company Security teams to align security strategy, standards, and risk posture; share risk and incident intelligence; coordinate on shared controls, incidents, audits, and assurance activities; and ensure efficient information sharing while respecting organizational boundaries, regulatory obligations, and data segregation requirements.

4) Compliance, Audit Readiness & Evidence Management

  • Lead planning and coordination for internal, customer, third‑party, parent‑company, and government-related audits/reviews.
  • Support review and operationalization of customer and partner security obligations in coordination with Legal, ensuring commitments are implementable and evidence backed.
  • Maintain an evidence program: control narratives, procedures, test results, access reviews, training completion, incident records, and corrective actions.
  • Support ISO 27001 and other applicable certifications/attestations; ensure alignment and minimize duplicate work across frameworks.

5) National Security Agreement (NSA) & Federal/Controlled Data Responsibilities

  • Serve as the primary Security authority accountable for defining sustainable security controls required by the NSA and government‑approved security plans.
  • Protect classified, controlled unclassified information (CUI), export‑controlled, and NSA‑governed data through appropriate technical and procedural safeguards.
  • Maintain alignment with relevant frameworks and requirements (as applicable), such as NIST, ISO, and GDPR and related customer/government security expectations.
  • Support FOCI mitigation requirements by maintaining and operationalizing Technology Control Plans, Electronic Communications Plans, Access Control Plans, and related procedures.
  • Ensure monitoring, logging, and escalation processes meet NSA‑driven requirements, including reporting timelines and documentation.

6) Incident Response, Monitoring & Business Continuity

  • Own and run incident response planning and execution: triage, containment, investigation, eradication, recovery, and post‑incident improvements.
  • Coordinate NSA/customer‑required notifications and reporting when protected data or environments are implicated.
  • Ensure pragmatic monitoring and logging coverage with available tooling; define alert thresholds and an escalation model that works with limited staff.
  • Partner with business functions on business continuity and disaster recovery planning, tabletop exercises, and periodic restoration testing.

7) Third‑Party/Vendor Security

  • Partner with business functions on a right‑sized vendor risk management program: tier vendors, assess risk, review contracts/security addenda, and track remediation.
  • Ensure critical vendors meet baseline security requirements (e.g., MFA, breach notification, data handling, subcontractor controls).

8) Security Awareness & Training

  • Deliver practical, role‑based security training (general workforce + privileged access users + NSA‑specific training where required).
  • Build a culture of “secure‑by‑default” behaviors through concise guidance, easy‑to‑follow playbooks, and recurring communications.

This is a hands‑on leadership role. Sets direction and drives key deliverables (policies, audit evidence, incident leadership, stakeholder alignment), leveraging a combination of internal resources and external partners/MSSPs as needed.

Qualifications

Required

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or equivalent experience.
  • 10+ years in information security/IT risk roles with at least 5 years leading security programs or teams.
  • Demonstrated experience leading audits and compliance readiness (internal/external/customer), including documentation and evidence management.
  • Strong ability to translate security requirements into practical controls in an environment with limited dedicated resources.
  • Proven executive communication skills: clear risk narratives and recommendations.

Strongly Preferred

  • Experience with NSA environments, FOCI mitigation, or government‑regulated security programs.
  • Familiarity with NIST Cybersecurity Framework 2.0, RMF concepts and secure controlled environment practices.
  • Experience supporting product development/engineering environments and CI/CD ecosystems.

Preferred Certifications

  • CISSP, CISM, CISA, CRISC, or similar.

Core Competencies

  • Risk‑based prioritization in resource‑constrained environments
  • Cross‑functional governance and stakeholder management
  • Audit readiness and evidence‑driven compliance
  • Incident leadership and decision‑making under pressure
  • Clear writing: policies, procedures, control narratives, and plans
  • Integrity, discretion, and national security awareness

Salary Range : $137,500 - $229,500 Annual

This pay range represents the minimum and maximum compensation that the position offers, and final compensation can vary within the range depending on work location, job experience, skills, and relevant educational attainment and/or training.

ETAP requires all successful applicants to undergo and pass a comprehensive background check before they start employment. Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification, credit check. Certain positions dealing with sensitive and/or third‑party personal data may involve additional background check criteria.

ETAP is an Equal Opportunity Employer. We are committed to being an exemplary employer with an inclusive culture, developing a workplace environment where all our employees are treated with dignity and respect. We value diversity and the expertise that people from different backgrounds bring to our business.

#J-18808-Ljbffr
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Director of IT Security in Irvine, CA vacancy
  • $137.5k - $229.5k

     ...environment and is proud to be an Equal Opportunity Employer.Title: Director Of IT SecurityLocation: Irvine, CAJob type: Full-time /...  ..., and Operations.Collaborates with parent and sister company Security teams to align standards, share risk and incident intelligence... 
    Suggested
    Full time
    For subcontractor
    Local area

    ETAP

    Irvine, CA
    4 days ago
  • $137.5k - $229.5k

     ...prioritize safety, maximize reliability, and stay resilient. ETAP is an Equal Opportunity Employer. Position Summary The Director of IT Security serves as the company’s security hub and “quarterback”—aligning IT, Engineering/R&D, Quality, Legal, and business... 
    Suggested
    Local area

    AVEVA Denmark

    Irvine, CA
    12 hours ago
  • $113k - $149k

     ...software. Well versed in a combination of Information Technology, Security and government accreditation processes, ISSOs are able to...  ...from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.Via Agency Partner:... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Costa Mesa, CA
    3 days ago
  •  ...results and rapidly improving models through real-field applications. Learn more at About the Job We're hiring a Director of IT, Infrastructure & Security to own Field AI's IT operations, corporate and cloud security, and compliance program end-to-end. You'll inherit a... 
    Suggested
    Remote work

    FieldAI

    Irvine, CA
    more than 2 months ago
  •  ...About the Job We're hiring a Director of IT, Infrastructure & Security to own Field AI’s IT operations, corporate and cloud security, and compliance program end‑to‑end. You'll inherit a working program, SOC 2 Type II is in place, CMMC is being run in partnership with... 
    Suggested

    Field AI

    Irvine, CA
    12 hours ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014... 

    Confidential

    Costa Mesa, CA
    5 days ago
  • $105.4k - $207.8k

    Position Summary As a Senior Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security operations across monitoring, detection, response, and automation. In this client-facing role, you will work... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    4 days ago
  • $105.4k - $207.8k

     ...Cyber practice as a Cyber SecOps Senior Consultant and help clients navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support high-visibility engagements focused on Google SecOps, threat... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    7 hours ago
  • $97.61k - $188.38k

     ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll doAs...  ...of business processes, internal control risk management, IT controls and related standardsResponsible to install, integrate,... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    7 hours ago
  •  ...executive leadership and regional teams to position technology as a trusted business partner, build a high-performing team, and provide a secure, scalable foundation that enables leaders to focus on winning work, executing projects, and developing people. The Chief... 

    W.E. O'Neil

    Irvine, CA
    3 days ago
  • $134.5k - $265.1k

     ...organizations reduce cyber risk and improve resilience? At Deloitte & Touche LLP, you’ll work with leading organizations to strengthen security, enable innovation, and reduce threat exposure. Join Deloitte’s Cyber Defense & Resilience Continuous Threat Exposure Management (... 
    Local area

    Deloitte

    Costa Mesa, CA
    7 hours ago
  • $134.5k - $265.1k

     ...knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    7 hours ago
  •  ...LBPM+Fairgrove is now hiring for Full-time IT Director in Irvine, CA. As a hands‑on IT Director you will own day‑to‑day technology operations...  ...services to the employees are responsive, cost‑effective and secure. Key Responsibilities Partner with the CAO CSO to develop and... 
    Full time
    Contract work
    Immediate start
    Remote work

    LBPM

    Irvine, CA
    1 day ago
  • $105.4k - $207.8k

     ...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Recruiting for this role ends on 12/31/2026. Work you'll do As a Senior Consultant, Sentinel on the Deloitte Cyber team,... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    3 days ago
  • $80k - $92.5k

     ...the ability to obtain a Public Trust   LTS is seeking a Cyber Security Analyst to support the Department of Veterans Affairs (VA) Health Portfolio. The Health PMO support contract provides IT program management, project management, technical management, financial... 
    Permanent employment
    Contract work
    Work at office
    Remote work

    GrabJobs

    Irvine, CA
    7 hours ago
  • $155.6k - $306.8k

     ...live data and systems• Ensuring deployed AI systems meet production bars for evaluation, guardrails, observability, reliability, security, and cost/performance management• Building automated controls and response workflows that support disaster recovery orchestration... 
    Local area
    Remote work

    Deloitte

    Costa Mesa, CA
    7 hours ago
  •  ...FieldAI in Irvine, California, is seeking a Director of IT, Infrastructure & Security to oversee IT operations and ensure robust security and compliance programs. This role entails leading a team, managing MSP relationships, and working closely with key stakeholders to... 

    FieldAI

    Irvine, CA
    12 hours ago
  • $146k - $194k

     ...infrastructures to support global operations. Information Systems Security Managers are in charge of directly supporting business lines...  ...Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.Conduct security risk assessments,... 
    Full time
    Contract work
    Work experience placement
    Immediate start

    Anduril Industries

    Costa Mesa, CA
    2 days ago
  •  ...that accelerate decarbonization and strengthen domestic energy security. POSITION OVERVIEW The Chief Technology Officer (CTO – Nuclear...  ...leadership experience at the level of CTO, VP of Engineering, Director of Nuclear, or equivalent. Hands-on experience with SMR,... 
    Full time
    Local area
    Relocation package

    BaRupOn LLC

    Irvine, CA
    more than 2 months ago
  • $134.5k - $265.1k

     ...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Manager, Strategy, Growth, and Transformation on the Cyber... 
    Local area

    Deloitte

    Costa Mesa, CA
    4 days ago
  • $134.5k - $265.1k

    Position Summary Deloitte’s Cyber Services help our clients to be secure, vigilant, and resilient in the face of an ever-increasing array of cyber threats and vulnerabilities. Our Cyber Risk practice helps organizations with the management of information and technology... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    1 day ago
  • $134.5k - $265.1k

     ...technology landscape against their recovery requirementsBA/BS in Computer Engineering, Computer Science, Information Systems, Cyber Security, or equivalent demonstrated technical backgroundAbility to travel up to 50%, on average, based on the work you do and the clients... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    2 days ago
  • $265k - $300k

     ...Chief Information Officer Department: IT Employment Type: Full Time...  ...build a high-performing team, and provide a secure, scalable foundation that enables leaders...  ...advise executive leadership and the Board of Directors on technology strategy, enterprise and cybersecurity... 
    Full time
    Work at office
    Monday to Friday
    Flexible hours

    Jobleads-US

    Irvine, CA
    3 days ago
  • $170k - $230k

    Job ID: 42654Reference: 300015904945092Location: Los Angeles, CA, United States | Irvine, CA, United States | San Diego, CA, United StatesDepartment: Water EngineeringBusiness Unit: ANA United StatesWork Type: HybridDate Posted: 2026-07-20Arcadis is the world's leading ...
    Full time
    Part time
    Local area

    Arcadis

    Irvine, CA
    1 day ago
  • Chief Academic Officer (CAO) About the Company Dynamic private university Industry Education Management Type Educational Institution Founded 1993 Employees 1001-5000 Categories ~ Education Specialties business degree tesol programs...

    Confidential

    Irvine, CA
    5 days ago
  • Chief Growth Officer (CGO) About the Company Charitable organization focused on bringing resources to developing countries Industry International Trade and Development Type Privately Held, VC-backed Founded 2012 Employees 501-1000 Funding ...

    Confidential

    Irvine, CA
    5 days ago
  • $82.6k - $162.8k

     ...services that simplify complexity, we enable our clients to operate with resilience, grow with confidence, and proactively manage to secure success. Identity security market is undergoing a fundamental transformation. Non-human identities (NHIs) include service accounts,... 
    Local area
    Visa sponsorship

    Deloitte

    Costa Mesa, CA
    2 days ago
  •  ...Onsite at OC Data Center Our client seeks a Tier 2 Senior Cyber Security Analyst to support a 24x7x365 Security Operations Center. The...  ...recommend new security tools, techniques, and technologies aligned to IT security strategy. Use COTS/GOTS and custom tools and... 
    Hourly pay
    Interim role
    Local area
    Trial period
    Shift work
    Weekend work
    Day shift

    Eliassen Group

    Tustin, CA
    a month ago
  • $129k - $171k

     ...strategically overseeing M&A integrations.ABOUT THE ROLEAs a technical IT Operations Manager for Acquisitions, you will architect and...  ...execution for consolidating disparate infrastructures into a unified, secure, and scalable operating model that enables Anduril's long-term... 
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Costa Mesa, CA
    7 hours ago
  • $210k - $260k

     ...obsession to accelerate our clients’ businesses through designing the products and services their customers truly value.OverviewA Director of Technology is a software engineering expert who leads the high-quality delivery of software and enterprise technology solutions... 

    Publicis Media

    Irvine, CA
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Director of IT Security. Be the first to apply!