RPM xConstruction logo
RPM xConstructionPosted 1 week ago

INFORMATION SECURITY OFFICER

On-siteMcKinney, Texas, United States

Full TimeMedium

Job Summary

Develop and continuously update RPM's enterprise information security strategy, policies, and standards aligned with NIST CSF, NIST SP 800-171, CMMC 2.0, and ISO 27001. Serve as the primary point of accountability for security decisions, presenting risk posture and program maturity to executive leadership on a regular cadence. Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party systems, maintaining a prioritized risk register with remediation owners. Own and maintain the incident response plan, leading responses to security incidents, data breaches, and fraud by coordinating with IT, Legal, and external counsel. Ensure compliance with federal and government-adjacent construction contracts, including CMMC 2.0 and NIST SP 800-171, by managing the System Security Plan, Plan of Action and Milestones, and acting as the point of contact for audits and insurance assessments. Partner with Legal and Procurement to embed security requirements into contracts, design company-wide security awareness training, and prepare periodic security posture reports for the board. Primarily office-based with periodic travel to project sites; availability for occasional after-hours response.

Required Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field
  • 7+ years of progressive experience in information security, risk management, or IT compliance
  • At least 3 years in a leadership role
  • Ability to translate technical risk into business terms for executive and ownership audiences
  • Strong project management and cross-functional collaboration skills
  • Excellent written and verbal communication skills
  • Sound judgment under pressure
  • Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed
  • Availability for occasional after-hours response in the event of a security incident

Desired Qualifications

  • Master's degree
  • Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements
  • Experience in construction, engineering, real estate development, or another project-based industry
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA)
  • CRISC (Certified in Risk and Information Systems Control)
  • CCSP or equivalent cloud security certification
  • Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce