Director of Information Systems Security (ISSO) at WiredPeople, Inc. | Torre

Director of Information Systems Security (ISSO)

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (anywhere)
Shared by
Emma of Torre.ai
4 months ago

Responsibilities


A Message from WiredPeopleWiredPeople is seeking a highly experienced and strategic Director of Information Systems Security (ISSO) to lead security and compliance initiatives. In this role, you will play a critical part in safeguarding information assets and ensuring adherence to complex regulatory frameworks. This position is a full-time and fully remote role.SummaryThe Director of ISSO will lead a team of Information Systems Security Officers (ISSOs) and cybersecurity professionals to develop, implement, and maintain comprehensive information security and privacy programs. You will oversee risk management, vulnerability assessments, security authorizations, and compliance with federal and state guidelines (including NIST, FISMA, HIPAA, and FedRAMP). The ideal candidate is a strategic leader with deep technical expertise and a proven track record of managing security operations in highly regulated environments.Duties & ResponsibilitiesLeadership & StrategyDirect and mentor a team of ISSOs, security engineers, and compliance analysts, fostering a culture of continuous improvement and professional development.Develop and execute the organization's information security strategy in alignment with overarching business goals and client requirements.Act as the primary point of contact for senior leadership and external stakeholders regarding information systems security posture, risks, and compliance status.Drive the adoption of "secure-by-design" principles across all enterprise systems and client deliverables.Compliance & Risk ManagementOversee the Risk Management Framework (RMF) process, ensuring timely and successful Authorization to Operate (ATO) for all organizational and client systems.Ensure strict compliance with relevant regulatory standards, including NIST SP 800-53, FISMA, FedRAMP, HIPAA, and DoD IL requirements.Direct comprehensive risk assessments, vulnerability scanning, and penetration testing activities, and manage the remediation of identified vulnerabilities.Maintain oversight of Plan of Action and Milestones (POA&M) processes, ensuring risks are mitigated within required timeframes.Security Operations & Incident ResponseLead the organization's incident response strategy, ensuring rapid detection, containment, and eradication of security threats.Oversee the continuous monitoring program to ensure ongoing security compliance and threat intelligence integration.Coordinate with legal, HR, and public relations teams during high-impact security incidents to ensure unified and compliant communication.Policy & DocumentationDevelop, implement, and maintain enterprise-wide security policies, procedures, and System Security Plans (SSPs).Ensure all system documentation, including Privacy Impact Assessments (PIAs) and Security Assessment Reports (SARs), is accurate and up-to-date.Design and execute comprehensive security awareness and training programs for all staff and contractors.Education & CertificationsBachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field. (A Master’s degree is highly preferred).Experience and CertificationsExperience:10+ years of progressive experience in information security, IT compliance, or cyber risk management.5+ years of experience in a leadership or management role overseeing security teams.Extensive hands-on experience managing the NIST RMF and achieving ATOs for complex systems.Certifications: Must hold one or more active, industry-recognized senior security certifications (e.g., CISSP, CISM, GSLC, or CISA).Skills & AbilitiesExceptional understanding of federal and state security compliance frameworks.Strong executive presence and the ability to communicate complex technical risks to non-technical stakeholders.Proven ability to operate in a fast-paced environment and deliver reliable results.