Back to jobs
New

Director of Cyber Security

Remote

 

DIRECTOR OF CYBER SECURITY

Location: United States — Remote: West Coast preferred
Department: Information Technology — Security, Risk & Compliance


Eligibility: U.S. citizenship required

ABOUT RAPIDFORT

RapidFort is a cybersecurity company focused on helping organizations secure and optimize their software supply chain and containerized environments. Our platform helps teams reduce software vulnerabilities and attack surface while improving the security and efficiency of modern cloud-native applications.

We work with commercial enterprises and public-sector organizations operating in highly regulated and security-sensitive environments.

 

Title: Director of Cyber Security

Department: Information Technology — Security, Risk & Compliance

Reports To: Chief Information Officer, with a standing reporting line to the Audit Committee

Direct Reports: Security operations, security engineering, and governance/risk/compliance, including a dedicated compliance specialist

Location: REMOTE

Employment Type: Full-time

Travel: Periodic travel for audits, customer engagements, and leadership meetings

On-Call: Incident commander for declared security incidents

ABOUT THE ROLE

RapidFort Inc. is looking for a Director of Cyber Security to own our security posture and the risk position behind it — what our controls are, whether they work, what remains exposed, and who has accepted that exposure.

This is a horizontal role by design. Cloud Operations, Infrastructure Engineering, and Corporate IT each own an estate and run it. You own the standard those estates are held to, the evidence that the standard is met, and the response when it is not.

You set the requirement and verify the outcome; the estate owner executes the remediation. That separation is deliberate — it is what makes the assurance worth anything.

You will own the ISO 27001 ISMS and the SOC 2 Type 2 program end to end, command security incidents with authority to direct containment across any estate, and give executive leadership and the Audit Committee an honest, current view of where our risk actually sits.

You will also own two program we need closed: FedRAMP authorization and CMMC Level 2. Both are live commitments rather than aspirations, and between them they will reshape how we scope, evidence, and monitor controls. You will have a dedicated compliance specialist to run the evidence machinery across all four frameworks — your job is to sequence them against one control set rather than four, and to carry the scoping and risk decisions that a specialist cannot.

Security is also part of our commercial proposition. You will be the person customers’ security teams talk to — questionnaires, customer audits, and the security terms in our contracts — and the person who decides what we will not agree to.

This role reports to the CIO but carries a standing reporting line to the Audit Committee, including the explicit right to escalate unresolved material risk without CIO clearance. We would rather write that down than leave it to goodwill.

WHAT YOU’LL DO

Policy, standards, and risk

• Own the information security policy set and the control framework, mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, and our customer and regulatory obligations.

• Own the technical standards the estate owners implement — hardening baselines, encryption, logging and retention, authentication, segmentation, and secure configuration.

• Own the risk framework and the risk register: current, evidenced, reviewed on cadence, with named owners.

• Own the exception process and approve risk acceptances below the material threshold; prepare and escalate anything above it.

• Own security architecture review for significant changes and new technology, before commitment.

• Report the risk position to the CIO, executive leadership, and the Audit Committee.

Detection and incident response

• Own security monitoring across endpoints, cloud, on-premises, corporate applications, and identity — coverage, detection content, and tuning.

• Own the SIEM estate and any managed detection provider relationship.

• Act as incident commander for declared security incidents, with authority to direct containment in any estate.

• Own post-incident review and drive remediation into the owning function’s backlog, tracked to closure.

• Run tabletop and live exercises across technical teams and executive leadership.

Vulnerability and threat management

• Own the vulnerability management program: scanning coverage, severity model, and remediation SLAs.

• Own the prioritization model — excitability, exposure, business impact — so remediation effort is directed rather than alphabetical.

• Track SLA attainment by estate owner, report it, and escalate breaches.

• Own penetration testing and red team engagements: scope, vendors, cadence, and finding closure.

• Own security testing requirements in the SDLC — SAST, dependency scanning, secrets detection, image scanning — and the gating thresholds.

Identity and access governance

• Own the access governance model: least privilege, segregation of duties, and the evidence each control must produce.

• Own privileged access policy — vaulting, just-in-time elevation, session recording, and break-glass.

• Own the design, scope, and cadence of access reviews, and certify their completion.

• Own authentication and session policy: MFA requirements, phishing-resistant factors, conditional access, and device trust.

Compliance and customer assurance

• Own the ISO 27001 ISMS: scope, Statement of Applicability, internal audit program, management review, and certification maintenance.

• Own the SOC 2 Type 2 program: control narrative, evidence calendar, and the audit period itself.

• Close out FedRAMP authorization: authorization path and agency sponsorship, system boundary, the NIST SP 800-53 baseline, System Security Plan, 3PAO assessment, POA&M, and the monthly continuous monitoring that follows.

• Close out CMMC Level 2: CUI scoping and enclave boundary, NIST SP 800-171 implementation, SSP and POA&M, SPRS submission, C3PAO assessment, and annual affirmation.

• Sequence all four frameworks against one control set — shared evidence, one calendar, and a single answer to a control tested under more than one regime.

• Own the external auditor and certification body relationship, plus the agency sponsor relationship where one is required, and coordinate evidence from each estate owner.

• Build continuous control monitoring so compliance is a measured state, not an annual scramble.

• Direct the compliance specialist, who runs evidence collection, control testing, POA&M tracking, and audit logistics. You keep framework scope, control interpretation, assessor and sponsor relationships, and the risk decisions behind them.

• Own customer security assurance — questionnaires, customer audits, trust documentation, and security terms in contracts and DPAs.

• Own the customer assurance pipeline: questionnaire intake, a library of pre-approved answers, and a turnaround commitment to Sales. The specialist drafts; you approve anything that commits us to a control, a date, or a contractual term.

• Own controlled distribution of audit artifacts under NDA — SOC 2 report, penetration test summaries, certifications, authorization packages — and decide what is not released.

Third-party risk and security culture

• Own vendor and SaaS security assessment: tier, assessment depth, sign-off before contract, and reassessment cadence.

• Own security requirements in vendor contracts — control obligations, right to audit, and incident notification terms.

• Own the awareness program, phishing simulation, and role-specific training for developers, privileged operators, and executives.

 

COMPENSATION & BENEFITS

RapidFort offers a competitive total rewards package that includes:

• Base Salary: $200,000–$245,000 USD annually, depending on experience, qualifications, and location
• Annual performance-based bonus
• Equity: Stock options in RapidFort
• Medical, dental, and vision insurance
• 401(k) retirement plan
• Paid time off and company holidays
• Paid sick leave
• Company-provided equipment
• Professional development and growth opportunities

RapidFort is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

 

Apply for this job

*

indicates a required field

Phone
Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in RapidFort, Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 07/31/2029

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.