Director, IT

COMTECH TELECOMMUNICATIONSChandler, AZ
Onsite

About The Position

Comtech's Satellite & Space business is seeking a Director of Information Technology to lead IT operations and to own the cybersecurity and regulatory compliance posture of a satellite and space communications manufacturer operating under U.S. government contracts and export control. The successful candidate will run the day-to-day IT function: infrastructure, business systems, end-user services, and the team that delivers them. The candidate will own CMMC certification and sustainment, NIST SP 800-171 implementation, DFARS cybersecurity obligations, and the IT dimension of ITAR and EAR export control and be accountable for the accuracy of what the business represents to the government about its cybersecurity posture. The business is a low-volume, high-mix, program-driven manufacturer of complex hardware with a substantial engineering and test population. Infrastructure serves engineering labs and the production floor as well as corporate users, and the compliance boundary must hold across all three.

Requirements

  • Demonstrated leadership of a CMMC and/or NIST SP 800-171 compliance program in a defense-contracting environment with accountability for the outcome, including direction of the team or partners performing the work.
  • Sufficient hands-on grounding in these frameworks: Direct work on System Security Plans, POA&Ms, SPRS scoring, or control implementation
  • Experience leading a governance, risk, and compliance function or equivalent technical compliance team, including resourcing decisions and management of outside assessors and consultants.
  • Working command of DFARS 252.204-7012 and related clauses, including incident reporting obligations and subcontractor flow-down.
  • Demonstrated experience applying ITAR and EAR requirements to IT systems and access control.
  • Experience managing ERP and PLM platforms, hybrid or cloud infrastructure, mixed Linux/Windows environments, and IT service management.
  • Demonstrated budget ownership with quantified cost and service outcomes.
  • Ability to obtain or maintain a U.S. Government Security Clearance may be required.

Nice To Haves

  • Has taken an organization through a successful C3PAO CMMC Level 2 assessment as the accountable owner.
  • Has built or materially strengthened a GRC function, including defining control ownership and an evidence and internal-testing cadence.
  • Experience in satellite, space, RF, defense electronics, or comparable low-volume, high-complexity export-controlled manufacturing.
  • Experience with operational technology and industrial control security on a production floor.

Responsibilities

  • Lead the governance, risk, and compliance team that executes the compliance program. Set priorities, allocate resources, define the standard for work product, and hold the team accountable for schedule and quality.
  • Direct and critically review the team's work with sufficient command of the underlying frameworks to challenge a control assessment, test an assertion that a control is implemented, and recognize when documentation describes an intended state rather than an operating one. This role is accountable for the team's conclusions, not only for its activity.
  • Assess team capability against program requirements and close gaps through hiring, development, or specialist support. Decide what is performed in-house versus sourced to outside assessors, consultants, or managed providers, and manage those providers to defined scope and deliverables.
  • Establish and run the compliance operating rhythm: control ownership assignments, evidence collection cadence, internal control testing schedule, risk register review, and management reporting.
  • Report compliance status, open gaps, and residual risk to the CFO and segment leadership without filtering. Ensure the organization's stated posture and its actual posture never diverge.
  • Own the CMMC program end to end and sustaining it through the three-year cycle and annual affirmation, directing the GRC team through boundary scoping, implementation of the NIST SP 800-171 practices, assessment, and ongoing sustainment.
  • Review and approve the System Security Plan and Plan of Action & Milestones and hold the team to maintain them as living documents rather than artifacts produced for an assessment window. Challenge POA&M items that persist without progress or that understate residual risk.
  • Own the SPRS score. Direct its calculation, approve what is submitted, and confirm it is defensible against the underlying evidence before submission.
  • Set the compliance requirements for External Service Providers and Cloud Service Providers, including FedRAMP Moderate or equivalent for services handling CUI, and approve the team's assessment of provider adequacy.
  • Own compliance with DFARS 252.204-7012, 7019, 7020, and 7021, directing the team on covered defense-information safeguarding, media preservation, and flow-down to subcontractors and suppliers.
  • Own the decision to report a cyber incident and the 72-hour reporting obligation to DIBNet. Ensure the team maintains the detection, triage, and evidence-preservation capability that decision depends on.
  • Approve cybersecurity representations made in proposals, prime flow-downs, and customer questionnaires. The organization must not certify or attest to controls over an environment it does not operate.
  • Direct Section 889 screening in IT procurement — network, telecom, and video surveillance equipment and services — against prohibited-source requirements.
  • Serve as the IT owner of export compliance in partnership with Trade Compliance and Legal. Direct the team on access control over export-controlled technical data, prevention of deemed exports through system access, citizenship- and geography-based access restrictions, and encryption controls where relied upon for compliance.
  • Review and approve the administrative access model, ensuring no foreign-person administrative access to systems containing controlled technical data, including via outsourced or offshore support arrangements.
  • Ensure the team produces and retains the IT-side evidence supporting DDTC and BIS requirements: access logs, data-location attestation, and controls documentation.
  • Own IT general controls — logical access provisioning and de-provisioning, change management, segregation of duties, privileged access review. Serve as IT's point of accountability to internal and external audit and direct remediation of identified deficiencies.
  • Own the CUI and FCI data boundary: identification, marking support, handling, segmentation, and lifecycle.
  • AI governance — acceptable-use standards and technical controls preventing CUI or export-controlled technical data from reaching external models.
  • Own the cybersecurity program: identity and access management, endpoint detection and response, logging and monitoring, vulnerability and patch management, security awareness training, and third-party risk.
  • Design and enforce segmentation between corporate IT, engineering labs, and production and test operational technology (OT). Establish a control approach for legacy and unpatchable test equipment consistent with IEC 62443 principles.
  • Align IT strategy with business and operational objectives, supporting complex, program-driven hardware production and substantial engineering and test population.
  • Lead IT operations for the business: network, compute, storage, backup, endpoint management, and end-user support.
  • Design and maintain resilient network architecture serving corporate users, engineering and test labs, and the production floor, within the compliance boundary.
  • Own infrastructure strategy — on-premises, cloud, or hybrid — decided on documented total cost of ownership and constrained by CUI and export-control data-boundary requirements, including the cost premium of government cloud regions where required.
  • Own incident response and disaster recovery planning and testing. Maintain incident response capability specifically built to meet contractual reporting obligations, including the DFARS 72-hour requirement, not solely to restore service.
  • Own availability, performance, and lifecycle of ERP, PLM, and manufacturing systems against committed, measurable targets, published availability objectives and tier-1 recovery time and recovery point objectives, validated by annual disaster-recovery testing.
  • Own master data integrity, item master, bill of materials, cost, customer and vendor master, as the prerequisite for reliable financial and operational reporting.
  • Maintain the data and reporting platform supporting financial close, program cost reporting, and operational metrics.
  • Lead system implementations and upgrades with business-case discipline and Finance and Operations sign-off on data validation.
  • Own the IT operating and capital plans; deliver monthly variance explanation with root cause and corrective action.
  • Build and defend the IT cost model, distinguishing steady-state run-rate from one-time transition and compliance-remediation cost.
  • Justify material spend with documented total cost of ownership, return on investment, and payback. Own software and SaaS lifecycle — renewal calendar, true-up exposure, and elimination of unused licensing.
  • Lead vendor selection and negotiation against stated cost and service targets, including C3PAO, assessor, and security-service providers.
  • Lead, develop, and retain the IT organization across infrastructure, security, business systems, end-user support, and governance, risk, and compliance.
  • Direct external partners and managed-service providers against fixed scope, schedule, and budget.
  • Serve as IT's senior interface to Operations, Engineering, Finance, Contracts, Trade Compliance, and Legal.

Benefits

  • Comtech’s Drug-Free Workplace Program
  • Equal Opportunity Employer
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service