DIRECTOR IT SECURITY

Nordam Group
  • Tulsa, OK
    3 days ago

    Job Description

    Position Details

    Req ID

    req2340

    Job Title

    DIRECTOR IT SECURITY

    Division

    Corporate

    Shift

    First Shift

    Job Summary

    Job Summary

    Responsible for establishing, executing, and continuously improving the enterprise cybersecurity strategy across all systems, data, IT and OT environments - on-premise, hybrid, or cloud-based - and all operational environments. Ensures compliance with global, aerospace, and industry-specific regulatory requirements, including CMMC, NIST SP 800-171, NIST SP 800-53, NIST Cybersecurity Framework, and OEM/customer cybersecurity standards, and other global operating standards e.g. Data Privacy Framework (DPF). Oversees risk management, security operations, incident response, governance, and training across the global organization.

    Essential Functions & Key Responsibilities

    • Cybersecurity Leadership & Strategy - Lead development, communication, and execution of the enterprise cybersecurity strategy; govern security posture across on-premise, hybrid, OT, and Cloud environments; liaise with IT management to align existing technical solutions and skills with future architectural requirements; align security programs with organizational objectives, global operations, and regulatory obligations.
    • Governance, Compliance & Regulatory Requirements - Oversee compliance with CMMC Level 2, NIST SP 800-171, NIST SP 800-53, DoD, aerospace OEM, and other mandated standards; maintain all required artifacts such as SSPs, POA&Ms, policies and evidence packages to support formal assessments, surveys, questionnaires and audits; drive governance practices consistent with enterprise policies, including permission governance and secure SharePoint/OneDrive data management; monitor changes in regulatory frameworks and update controls, procedures and technologies accordingly.
    • Risk Management - Lead enterprise IT risk management, including risk assessments, remediation planning and reporting; ensure global consistency in risk treatment across business units, engineering, operations and supply chain.
    • Security Architecture & Technology Management - Oversee design, deployment and lifecycle management of security technologies such as endpoint protection, firewalls, IDS/IPS, SIEM, identity platforms and cloud security controls; implement secure configuration baselines and vulnerability management programs.
    • Identity, Access & Privileged Governance - Direct IAM practices including role-based access, privileged access controls and lifecycle management; govern permissions and inheritance models across collaboration systems (SharePoint/OneDrive).
    • Data Protection & Information Security - Ensure protection of sensitive data including Controlled Unclassified Information (CUI) - using classification, encryption, retention, auditing and DLP enforcement; oversee secure design of shared repositories, collaboration sites and business data environments, e.g. M365, SharePoint/OneDrive, Teams, .NET, etc.; manage security issues and incidents to protect company assets, including intellectual property and regulated data; participate in problem and change management forums.
    • Incident Response, Monitoring & Resilience - Direct enterprise incident response plans, threat detection, monitoring and forensics capability; conduct regular exercises and ensure all facilities maintain mature response readiness; govern disaster recovery, back-up strategies and business-continuity planning; provide strategic leadership and governance across Security Operations Center overseeing enterprise-wide incident detections, response remediation and threat investigations, directing development and continuous improvement of SOC/IR playbooks and automation and defining KRAs/KPIs that ensure measurable operational performance, risk reduction and alignment with organization security objectives.
    • Vendor, Supplier & Partner Security - Evaluate and manage cybersecurity posture of vendors, suppliers and joint-venture partners, e.g. third-party cyber risk management; enforce contractual and regulatory security requirements across the supply chain.
    • Policies, Procedures & Training - Create, maintain and enforce cybersecurity policies, standards and procedures across the organization; deliver enterprise training and awareness programs tailored to IT, operations, engineering and shop-floor teams; responsible to provide robust training to end-users on security processes, procedures, risk and importance of proper usage; promotes training and individual role accountability with other departments.
    • Continuous Improvement - Identify and implement ongoing enhancements to security operations, tooling and governance; drive maturity improvements tied to audit findings, risk assessments and evolving strategic goals.
    • Leadership & Team Development - Lead and develop multi-disciplinary security teams including cloud security, identity governance, compliance, vulnerability management and operations; foster collaboration with IT, engineering, quality, operations, legal and supply chain to embed security into daily workflows; perform typical responsibilities of management including evaluation, organization, integration, coaching and personnel actions.

    Performs other duties as required. These duties may include assignments in job classifications and departments other than the primary assignment.

    Minimum Qualifications

    Education Requirements

    Minimum 4 Year / Bachelors Degree. Cyber Security or other IT degree

    Minimum Graduate Degree. Cyber Security or other IT degree

    If applicable, a combination of experience and training may be substituted for the education requirement.

    Experience Requirements

    12 - 15 or more years experience year(s) Significant experience in IT Systems, Security or Cybersecurity; implementing, managing and securing on-premise/cloud hybrid environments

    year(s) Security Certification such as CISSP, CISA, CCSK, CMMC, etc.

    year(s) NIST SP 800-171, NIST SP 800-53 or CMMC frameworks, Controlled Unclassified Information data (EAR, ITAR, CUI), Enterprise Business Systems (SAP ERP) and Microsoft 365 GCC or GCCH

    Supervisory/Management Experience year(s)

    Minimum Years of Experience year(s) Description

    5 or more year(s) IT management / leadership

    The supervisory/management experience requirement is included in, not additional to, the overall experience requirements. year(s)

    Skills and Competencies

    • Demonstrates deep knowledge of IT security life cycle, including threat modeling, detection engineering, hardening and incident response
    • Solid understanding of the Cyber Kill Chain, MITRE ATT&CK, Zero Trust concepts and modern defense frameworks
    • Understand NIST and operationalize cybersecurity frameworks: CMMC Level 2, NIST SP 800-171, NIST SP 800-53, NIST CSF and OEM/customer security requirements
    • Familiar with MRP and MRP systems, including SAP, and enterprise application security considerations
    • Knowledge of manufacturing operations technology equipment (shop floor controls)
    • Cloud security expertise including Microsoft 365, Azure, identity governance, conditional access and security configuration baselines
    • Familiar with third party vendor relationships, vendor risk assessments and new technology/security reviews
    • Strong understanding of vulnerability management, patch governance, logging, monitoring, SIEM/IDS/IPS and endpoint protection lifecycle
    • Working knowledge in supporting international sites and global IT/security operations
    • Experience developing and maintaining SSPs, POA/&Ms, policies, procedures and audit evidence for compliance requirements
    • Knowledgeable in CUI protection, data classification, DLP controls, retention and regulatory data-handling practices
    • Excellent communication skills, both in written and verbal forms
    • Strong interpersonal skills in areas such as teamwork, facilitation, etc.
    • Competent in use of standard software applications such as Microsoft Word, Excel, Power Point, etc. and operate standard office equipment
    • Make telephone and direct personal contact with internal and external personnel and make formal presentations to small or large groups
    • Exhibit excellent analytical skills and the ability to manage multiple projects proficiently while working in a demanding, dynamic environment; strong project management abilities
    • Ability to apply principles and practices of work leadership and management; communicate objectives and expectations and motivate performance
    • Ability to aggregate multiple sources of data into usable information in a short period of time
    • Ability to remediate security findings via efforts of other teams within the organization

    Physical Requirements

    Physical Requirements

    Must be able to work in excess of eight (8) hours per day and five (5) days per week, if required. Additionally, those who work at NORDAM Repair Division must be able to ascend and descend stairs.

    Demand - Frequency

    Walk - Frequent

    Use hands to handle or feel or manipulate - Frequent

    Reach with hands and arms - Frequent

    Stoop, kneel, crouch, or crawl - Occasional

    Talk and hear - Frequent

    Use close vision, depth perception, and ability to adjust - Constant

    Travel between facilities (drive) - Occasional

    Stand - Occasional

    Climb stairs - Occasional

    Weight - Frequency

    25 pounds - Occasional

    Work Environment

    Work Environment

    While performing the duties of this job, the Stakeholder is occasionally exposed to moving mechanical parts, fumes or airborne particles, toxic or caustic chemicals, and outside weather conditions. The noise level in the work environment is usually moderate.

    Supervision

    Supervision

    • Manages from 3 to 10 supervisory/management and/or salaried/professional Stakeholders

    EEO Statement

    The NORDAM Group LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity or expression, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law.

    Numbers & Facts

    LocationTulsa, OK

    Skills

    • Access Controlunmatched
    • Aerospace and Defenseunmatched
    • Alliance/Partner Marketingunmatched
    • Analysis Skillsunmatched
    • Architectural Servicesunmatched
    • Auditingunmatched
    • Automationunmatched
    • Business Continuity Planning (BCP)unmatched
    • Change Managementunmatched
    • Cloud Computingunmatched
    • Coachingunmatched
    • Communication Skillsunmatched
    • Computer Securityunmatched
    • Continuous Improvementunmatched
    • Cross-Functionalunmatched
    • Cryptographyunmatched
    • Data Managementunmatched
    • Data Recoveryunmatched
    • Depth Perceptionunmatched
    • Direct Response Advertisingunmatched
    • Disaster Recoveryunmatched
    • Endpoint Securityunmatched
    • Enterprise Protectionunmatched
    • Firewallsunmatched
    • Forensic Scienceunmatched
    • Hybrid Cloudunmatched
    • IR (Infrared)unmatched
    • Incident Responseunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Intellectual Property (IP)unmatched
    • International Operationsunmatched
    • Internet Securityunmatched
    • Interpersonal Skillsunmatched
    • Intrusion Detection Systemsunmatched
    • Intrusion Prevention Systemsunmatched
    • Leadershipunmatched
    • Legalunmatched
    • Machine Toolunmatched
    • Maintain Complianceunmatched
    • Management of Information Systems/Technology (MIS)unmatched
    • Manufacturingunmatched
    • Manufacturing Operationsunmatched
    • Manufacturing Technologyunmatched
    • Microsoft .NETunmatched
    • Microsoft Access Databaseunmatched
    • Microsoft Excelunmatched
    • Microsoft PowerPointunmatched
    • Microsoft SharePointunmatched
    • Microsoft Windows Azureunmatched
    • Microsoft Wordunmatched
    • Monitor Regulationsunmatched
    • Multitaskingunmatched
    • OEM (Original Equipment Manufacturer)unmatched
    • Office Equipmentunmatched
    • Operational Measurementunmatched
    • People Managementunmatched
    • Performance Metricsunmatched
    • Process Improvementunmatched
    • Project/Program Managementunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • SAPunmatched
    • Security Analysisunmatched
    • Security Architectureunmatched
    • Security Information and Event Management (SIEM)unmatched
    • Security Monitoringunmatched
    • Software Patchesunmatched
    • Supply Chainunmatched
    • Supply Chain Operationsunmatched
    • Team Buildingunmatched
    • Team Playerunmatched
    • Technical Leadershipunmatched
    • Threat Modelingunmatched
    • Training Programunmatched
    • Training/Teachingunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched
    • United States Department of Defense (DoD)unmatched
    • Vendor/Supplier Relationsunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder