Key Responsibilities• Lead readiness and ongoing compliance for CMMC Level 2 and NIST SP 800-171 across our defense-adjacent business units• Support SOC 2 and PCI DSS efforts, including evidence collection, control design, gap remediation, and audit coordination• Own security and infrastructure projects end to end: scope them, build the plan, coordinate vendors and internal stakeholders, drive them to agreed timelines, and keep leadership informed on status and risk• Administer and improve security tooling: endpoint protection, identity and access management, SIEM, MFA, email security, vulnerability management, and logging• Run access reviews, security awareness training, phishing simulations, and incident response tabletop exercises• Write and maintain the policies, procedures, and system security plans that our frameworks require, and make sure they reflect what we actually do• Partner with business unit leaders on risk decisions, vendor reviews, and security questions from customers and partners• Work alongside the core IT team on systems and infrastructure initiatives beyond security, including Microsoft 365/Entra ID and identity administration, server and network projects, endpoint management, and other technology work that supports all business units How We WorkFirst, we are lean. In your first year, success means:• Our CMMC Level 2 gap assessment is complete, the System Security Plan is written, and we are executing against a plan with dates we can defend to an assessor• Security and compliance projects land on their committed timelines, and when a date has to move, leadership hears it from you in advance rather than after the fact• Critical and high vulnerabilities are remediated within defined windows, and we can show the trend• Our security policies reflect how the business actually operates, so people follow them instead of working around them• Business unit leaders come to you early on decisions with security implications, because you have made yourself useful rather than obstructive.