DIRECTOR IT SECURITY

The NORDAM Group•Tulsa, OK
•Onsite

About The Position

Responsible for establishing, executing, and continuously improving the enterprise cybersecurity strategy across all systems, data, IT and OT environments – on-premise, hybrid, or cloud-based - and all operational environments. Ensures compliance with global, aerospace, and industry-specific regulatory requirements, including CMMC, NIST SP 800-171, NIST SP 800-53, NIST Cybersecurity Framework, and OEM/customer cybersecurity standards, and other global operating standards e.g. Data Privacy Framework (DPF). Oversees risk management, security operations, incident response, governance, and training across the global organization.

Requirements

  • Minimum 4 Year / Bachelors Degree. Cyber Security or other IT degree
  • Minimum Graduate Degree. Cyber Security or other IT degree
  • If applicable, a combination of experience and training may be substituted for the education requirement.
  • 12 - 15 or more years experience year(s) Significant experience in IT Systems, Security or Cybersecurity; implementing, managing and securing on-premise/cloud hybrid environments
  • year(s) Security Certification such as CISSP, CISA, CCSK, CMMC, etc.
  • year(s) NIST SP 800-171, NIST SP 800-53 or CMMC frameworks, Controlled Unclassified Information data (EAR, ITAR, CUI), Enterprise Business Systems (SAP ERP) and Microsoft 365 GCC or GCCH
  • 5 or more year(s) IT management / leadership
  • Demonstrates deep knowledge of IT security life cycle, including threat modeling, detection engineering, hardening and incident response
  • Solid understanding of the Cyber Kill Chain, MITRE ATT&CK, Zero Trust concepts and modern defense frameworks
  • Understand NIST and operationalize cybersecurity frameworks: CMMC Level 2, NIST SP 800-171, NIST SP 800-53, NIST CSF and OEM/customer security requirements
  • Familiar with MRP and MRP systems, including SAP, and enterprise application security considerations
  • Knowledge of manufacturing operations technology equipment (shop floor controls)
  • Cloud security expertise including Microsoft 365, Azure, identity governance, conditional access and security configuration baselines
  • Familiar with third party vendor relationships, vendor risk assessments and new technology/security reviews
  • Strong understanding of vulnerability management, patch governance, logging, monitoring, SIEM/IDS/IPS and endpoint protection lifecycle
  • Working knowledge in supporting international sites and global IT/security operations
  • Experience developing and maintaining SSPs, POA/&Ms, policies, procedures and audit evidence for compliance requirements
  • Knowledgeable in CUI protection, data classification, DLP controls, retention and regulatory data-handling practices
  • Excellent communication skills, both in written and verbal forms
  • Strong interpersonal skills in areas such as teamwork, facilitation, etc.
  • Competent in use of standard software applications such as Microsoft Word, Excel, Power Point, etc. and operate standard office equipment
  • Make telephone and direct personal contact with internal and external personnel and make formal presentations to small or large groups
  • Exhibit excellent analytical skills and the ability to manage multiple projects proficiently while working in a demanding, dynamic environment; strong project management abilities
  • Ability to apply principles and practices of work leadership and management; communicate objectives and expectations and motivate performance
  • Ability to aggregate multiple sources of data into usable information in a short period of time
  • Ability to remediate security findings via efforts of other teams within the organization

Responsibilities

  • Lead development, communication, and execution of the enterprise cybersecurity strategy; govern security posture across on-premise, hybrid, OT, and Cloud environments; liaise with IT management to align existing technical solutions and skills with future architectural requirements; align security programs with organizational objectives, global operations, and regulatory obligations.
  • Oversee compliance with CMMC Level 2, NIST SP 800-171, NIST SP 800-53, DoD, aerospace OEM, and other mandated standards; maintain all required artifacts such as SSPs, POA&Ms, policies and evidence packages to support formal assessments, surveys, questionnaires and audits; drive governance practices consistent with enterprise policies, including permission governance and secure SharePoint/OneDrive data management; monitor changes in regulatory frameworks and update controls, procedures and technologies accordingly.
  • Lead enterprise IT risk management, including risk assessments, remediation planning and reporting; ensure global consistency in risk treatment across business units, engineering, operations and supply chain.
  • Oversee design, deployment and lifecycle management of security technologies such as endpoint protection, firewalls, IDS/IPS, SIEM, identity platforms and cloud security controls; implement secure configuration baselines and vulnerability management programs.
  • Direct IAM practices including role-based access, privileged access controls and lifecycle management; govern permissions and inheritance models across collaboration systems (SharePoint/OneDrive).
  • Ensure protection of sensitive data including Controlled Unclassified Information (CUI) - using classification, encryption, retention, auditing and DLP enforcement; oversee secure design of shared repositories, collaboration sites and business data environments, e.g. M365, SharePoint/OneDrive, Teams, .NET, etc.; manage security issues and incidents to protect company assets, including intellectual property and regulated data; participate in problem and change management forums.
  • Direct enterprise incident response plans, threat detection, monitoring and forensics capability; conduct regular exercises and ensure all facilities maintain mature response readiness; govern disaster recovery, back-up strategies and business-continuity planning; provide strategic leadership and governance across Security Operations Center overseeing enterprise-wide incident detections, response remediation and threat investigations, directing development and continuous improvement of SOC/IR playbooks and automation and defining KRAs/KPIs that ensure measurable operational performance, risk reduction and alignment with organization security objectives.
  • Evaluate and manage cybersecurity posture of vendors, suppliers and joint-venture partners, e.g. third-party cyber risk management; enforce contractual and regulatory security requirements across the supply chain.
  • Create, maintain and enforce cybersecurity policies, standards and procedures across the organization; deliver enterprise training and awareness programs tailored to IT, operations, engineering and shop-floor teams; responsible to provide robust training to end-users on security processes, procedures, risk and importance of proper usage; promotes training and individual role accountability with other departments.
  • Identify and implement ongoing enhancements to security operations, tooling and governance; drive maturity improvements tied to audit findings, risk assessments and evolving strategic goals.
  • Lead and develop multi-disciplinary security teams including cloud security, identity governance, compliance, vulnerability management and operations; foster collaboration with IT, engineering, quality, operations, legal and supply chain to embed security into daily workflows; perform typical responsibilities of management including evaluation, organization, integration, coaching and personnel actions.
  • Performs other duties as required. These duties may include assignments in job classifications and departments other than the primary assignment.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service