- Company Name
- EVONA
- Job Title
- Security & IT Director
- Job Description
-
**Job title:** Security & IT Director
**Role Summary:**
Lead the global cybersecurity, information security, and enterprise IT operations for a high‑growth Earth‑observation data platform. Own strategy, compliance, and day‑to‑day security operations across cloud, DevOps, and product teams, ensuring secure design, scalable infrastructure, and continuous compliance with CMMC, SOC 2, GDPR, and NIST standards.
**Expectations:**
- Deliver a mature, compliant, cloud‑native security posture for a rapidly scaling SaaS platform.
- Securely extend enterprise IT processes, device management, and support for internal and customer-facing systems.
- Provide executive‑level reporting on risk, compliance status, and IT performance.
**Key Responsibilities:**
1. Own global security strategy, policy framework, and roadmap.
2. Lead attainment and recertification of CMMC Lv 2, SOC 2 Type II, GDPR, and NIST 800‑171/800‑53 compliance.
3. Build governance, standards, and procedures across engineering, DevOps, product, and legal.
4. Oversee cloud security – IAM, encryption, monitoring, logging, configuration hardening.
5. Direct security operations: vulnerability management, penetration testing, vendor risk, incident response.
6. Manage internal audits, risk assessments, POA&M, and support external/audit readiness.
7. Oversee enterprise IT – procurement, asset inventory, license management, access control, support processes.
8. Ensure endpoint security (MDM, patching, VPN, encryption) for all employee devices.
9. Partner with SDLC teams to embed secure development practices.
10. Report status and initiatives to C‑suite and board.
**Required Skills:**
- 7+ years in information security, cybersecurity, or IT security leadership.
- Proven ability to build and operate security programs in cloud‑native startup/scale‑up settings.
- Hands‑on experience with CMMC Lv 2, SOC 2 Type II, GDPR, NIST 800‑171/800‑53.
- Strong knowledge of AWS/GCP, IAM, zero‑trust architecture, logging, and network security.
- Experience managing SaaS ecosystems, device management, and enterprise IT operations.
- Excellent cross‑functional communication, risk‑based decision making, and analytical skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- CISSP, CISM, CCSP, or comparable certification preferred.
- Eligibility to obtain a U.S. security clearance; current clearance is a plus.