Director, Information Security - Reston, VA

Bowman Consulting Group, Ltd.Reston, VA
3d

About The Position

Bowman has an opportunity for a Director, Information Technology to join our team in Reston, VA. At Bowman, we believe in creating opportunities for aspiring people to thrive and achieve ambitious goals. That’s why a career at Bowman is more than a job. It is an opportunity to be part of a diverse and engaged community of professionals, to be treated as a respected and valued member of a motivated team and to be empowered to do exceptional work that advances the best interest of everyone involved. We recognize the importance of creating a work environment that is both rewarding to our employees and supportive of our unwavering commitment to provide unparalleled service to our clients. Purpose The Director of Information Security leads the enterprise security function to protect information assets and manage risk across the organization. This position is responsible for strategic oversight and leadership across all major security domains, including endpoint security, vulnerability management, infrastructure security, cloud security, logging and detection, data protection, application security, GRC, and incident response. The Director will align security initiatives with business objectives, develop a robust security architecture, ensure regulatory compliance, and foster a culture of cybersecurity awareness. The role includes managing hands-on security professionals and scaling the team to meet evolving organizational needs.

Requirements

  • Minimum of fifteen (15) years of progressive IT experience, including at least six (6) years in information security roles.
  • Bachelor’s degree in computer science, cybersecurity, or related field required; advanced degree preferred.
  • One or more advanced security certifications required (e.g., CISSP, CISM, CISA, CCSP).
  • Proven experience building and leading security teams.
  • Strong knowledge of enterprise security architecture, security operations, GRC frameworks, and risk management.
  • Experience with Microsoft O365, Azure AD, virtual networks, firewalls, and modern security toolsets.
  • Familiarity with frameworks such as NIST CSF, ISO 27001, CIS Controls, CMMC.

Responsibilities

  • Report to the CIO/CISO and contribute to executive-level decision making on security matters.
  • Provide strategic leadership over the information security function, including technical operations, GRC, and incident response.
  • Supervise a growing team of security professionals, with responsibility for hiring, performance management, training, and development.
  • Build and execute a multi-year information security roadmap aligned with business goals and evolving threat landscapes.
  • Collaborate with IT, Legal, HR, Marketing, Compliance, Product, and business units to implement practical, risk-based security controls and policies across the enterprise.
  • Serve as a subject matter expert on cybersecurity, advising stakeholders across the enterprise.
  • Communicate risk posture, security metrics and program maturity to executive leadership and governance bodies.
  • Lead the design, implementation, and continuous improvement of secure enterprise architectures, ensuring protection of data, applications, and infrastructure.
  • Oversee technical security operations, including endpoint security (EDR/XDR & MDM), vulnerability management, logging and detection (SIEM, SOAR, threat intelligence, UEBA, CSPM/ASM), data protection (DLP, classification, encryption, backup and governance), application and DevSecOps (SAST/DAST, SBOM, secrets, API and container security), and cloud/infrastructure security (CWPP, IaC scanning, and hybrid/cloud hardening).
  • Develop and implement comprehensive GRC programs addressing risk management, compliance standards(e.g., NIST 800-171, CMMC, ISO, CIS), customer requirements, audit readiness, policy management, and vendor risk.
  • Direct incident response, conduct root cause analysis, and implement corrective actions.
  • Oversee business continuity and resilience initiatives such as DR automation, tabletop exercises, and cross-team crisis readiness.
  • Establish and maintain security metrics, KPIs, and reporting processes.
  • Develop and maintain the information security budget, ensuring strategic allocation of resources.
  • Stay informed of emerging threats, technologies, and regulatory changes to continuously improve security posture.
  • Support internal and external security audits and regulatory inquiries.
  • Oversee development and delivery of training and awareness programs to promote a security-conscious workforce.

Benefits

  • Medical, dental, vision, life, and disability insurance
  • 401(k) retirement savings plan with company match
  • Paid time off, sick leave, and paid holidays
  • Tuition reimbursement and professional development support
  • Discretionary bonuses and other performance-based incentives
  • Employee Assistance Program (EAP), wellness initiatives, and employee discounts

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Director

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service