Director Of It And Cybersecurity
CurrentAdvances the processes, strategy, capability, and maturity of IT cybersecurity and risk management at The Rockhill Group. Responsible for creating long-term strategy, development, implementation, and ongoing monitoring of a comprehensive enterprise cybersecurity program. The program is intended to maintain the integrity, confidentiality, and availability of the company's IT systems, data, and assets.RESPONSIBILITIES• Responsible for creating a best practice strategy and annual roadmaps to monitor IT infrastructure and security measures• Responsible for directly managing external vendor and service providers• Responsible for planning and implementing security safeguards and standards• Ensure access control, endpoint management, and vulnerability management are current and implemented within the enterprise • Protect unauthorized use and access to corporate and personal data; enforce adherence to compliance standards • Lead incident response team to contain, investigate, remediate, and prevent cybersecurity incidents• Help create enterprise-wide security awareness and security training to educate our workforce against potential security threats• Lead research and evaluation of industry leading enterprise security tools• Participate in developing a change management process and review board• Maintain system interfaces, equipment and support of remote sites• Assess and prepare for NIST 800-171 and CMMC compliance• Assess DFARS NIST 800-171 controls compliance• Lead efforts to implement secure solutions compliant with DFARS requirements• Participates in the creation of enterprise security documentsDUTIES• Research and selection of IT applications, security tools and network interfaces• ISO Quality certification audits• Lead a cybersecurity capability benchmark assessment• Support and liaison to COO for assigned projects• Configuration, maintenance and support of corporate assets