RapidFort Inc. is looking for a Director of Cyber Security to own our security posture and the risk position behind it — what our controls are, whether they work, what remains exposed, and who has accepted that exposure. This is a horizontal role by design. Cloud Operations, Infrastructure Engineering, and Corporate IT each own an estate and run it. You own the standard those estates are held to, the evidence that the standard is met, and the response when it is not. You set the requirement and verify the outcome; the estate owner executes the remediation. That separation is deliberate — it is what makes the assurance worth anything. You will own the ISO 27001 ISMS and the SOC 2 Type 2 program end to end, command security incidents with authority to direct containment across any estate, and give executive leadership and the Audit Committee an honest, current view of where our risk actually sits. You will also own two program we need closed: FedRAMP authorization and CMMC Level 2. Both are live commitments rather than aspirations, and between them they will reshape how we scope, evidence, and monitor controls. You will have a dedicated compliance specialist to run the evidence machinery across all four frameworks — your job is to sequence them against one control set rather than four, and to carry the scoping and risk decisions that a specialist cannot. Security is also part of our commercial proposition. You will be the person customers’ security teams talk to — questionnaires, customer audits, and the security terms in our contracts — and the person who decides what we will not agree to. This role reports to the CIO but carries a standing reporting line to the Audit Committee, including the explicit right to escalate unresolved material risk without CIO clearance. We would rather write that down than leave it to goodwill.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director
Education Level
No Education Listed