7 часов назад
Information Assurance Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Assurance Lead (Cybersecurity) (NIST/CMMC/ITAR): Leading governance, risk, compliance, and technical assurance for mission-critical aerospace systems with an accent on security audits, threat-informed defense, and export-controlled information. Focus on modeling adversary tactics with MITRE ATT&CK, integrating SIEM and GRC tooling for continuous monitoring, and translating complex security risks into actionable executive guidance.
Location: Remote within Texas, United States. Access to export-controlled technical data may require additional U.S. export-control screening, and meeting eligibility requirements is a condition of employment.
Full-time employment; salary not specified.
Company
develops commercial human spaceflight services, advanced spacesuits, and next-generation orbital infrastructure.
What you will do
- Lead the Information Assurance roadmap and align internal and customer-facing systems with organizational risk appetite and current threats.
- Serve as the primary lead for security audits and certifications, including NIST, CMMC, and ISO 27001.
- Oversee technical security assessments, threat modeling, and remediation strategies for complex networks using MITRE ATT&CK and related defensive frameworks.
- Partner with Engineering, Legal, Program, Safety, and Mission Assurance stakeholders to integrate security controls into the SDLC and supplier lifecycle.
- Drive compliance automation by integrating SIEM and GRC platforms, continuous monitoring, and telemetry mapping.
- Translate security risks, adversary trends, defensive readiness, and regulatory changes into actionable executive reporting.
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, or a related discipline, or equivalent practical experience.
- At least 8 years of progressively responsible experience in technical cybersecurity, Information Assurance, risk management, or IT audit, including 3 years focused on governance, risk, compliance, or audit.
- Expert knowledge of NIST SP 800-53, NIST SP 800-171, CMMC, and the protection of sensitive, regulated, and export-controlled information under ITAR/EAR.
- Practical experience with threat-informed defense models such as MITRE ATT&CK, D3FEND, or SPARTA.
- Must satisfy applicable U.S. export-control eligibility requirements to access restricted technical data or technology.
- Must be willing to work evenings and weekends when required by critical project milestones.
Nice to have
- Certifications such as CISSP, CISM, CISA, GSNA, or CCA.
- Experience leading work in ambiguous, fast-moving environments and applying agile project management methods.
Culture & Benefits
- Mission-driven work focused on commercial human spaceflight and space infrastructure.
- Collaborative environment spanning engineering, legal, program, safety, and mission assurance functions.
- Core values include leadership, innovation, teamwork, accountability, technical rigor, and execution discipline.
- Work is primarily office-based in nature, with tasks potentially performed indoors or outdoors.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →