665,268open jobs
38,876companies
100,271added this week
Browse all
Salary
$200k – $245k per year
Location
Remote (United States)
Seniority
Architect
Employment
Full-Time
Overview
Company
Impact
Profile match
RapidFort is a software supply chain security company that helps enterprises and US government agencies eliminate container vulnerabilities, secure Kubernetes environments, and protect cloud-native infrastructure.

DIRECTOR OF CYBER SECURITY

Location: United States - Remote: West Coast preferred

Department: Information Technology - Security, Risk & Compliance

Eligibility: U.S. citizenship required

ABOUT RAPIDFORT

RapidFort is a cybersecurity company focused on helping organizations secure and optimize their software supply chain and containerized environments. Our platform helps teams reduce software vulnerabilities and attack surface while improving the security and efficiency of modern cloud-native applications.

We work with commercial enterprises and public-sector organizations operating in highly regulated and security-sensitive environments.

Title: Director of Cyber Security

Department: Information Technology - Security, Risk & Compliance

Reports To: Chief Information Officer, with a standing reporting line to the Audit Committee

Direct Reports: Security operations, security engineering, and governance/risk/compliance, including a dedicated compliance specialist

Location: REMOTE

Employment Type: Full-time

Travel: Periodic travel for audits, customer engagements, and leadership meetings

On-Call: Incident commander for declared security incidents

ABOUT THE ROLE

RapidFort Inc. is looking for a Director of Cyber Security to own our security posture and the risk position behind it - what our controls are, whether they work, what remains exposed, and who has accepted that exposure.

This is a horizontal role by design. Cloud Operations, Infrastructure Engineering, and Corporate IT each own an estate and run it. You own the standard those estates are held to, the evidence that the standard is met, and the response when it is not.

You set the requirement and verify the outcome; the estate owner executes the remediation. That separation is deliberate - it is what makes the assurance worth anything.

You will own the ISO 27001 ISMS and the SOC 2 Type 2 program end to end, command security incidents with authority to direct containment across any estate, and give executive leadership and the Audit Committee an honest, current view of where our risk actually sits.

You will also own two program we need closed: FedRAMP authorization and CMMC Level 2. Both are live commitments rather than aspirations, and between them they will reshape how we scope, evidence, and monitor controls. You will have a dedicated compliance specialist to run the evidence machinery across all four frameworks - your job is to sequence them against one control set rather than four, and to carry the scoping and risk decisions that a specialist cannot.

Security is also part of our commercial proposition. You will be the person customers’ security teams talk to - questionnaires, customer audits, and the security terms in our contracts - and the person who decides what we will not agree to.

This role reports to the CIO but carries a standing reporting line to the Audit Committee, including the explicit right to escalate unresolved material risk without CIO clearance. We would rather write that down than leave it to goodwill.

WHAT YOU’LL DO

Policy, standards, and risk

  • Own the information security policy set and the control framework, mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, and our customer and regulatory obligations.
  • Own the technical standards the estate owners implement - hardening baselines, encryption, logging and retention, authentication, segmentation, and secure configuration.
  • Own the risk framework and the risk register: current, evidenced, reviewed on cadence, with named owners.
  • Own the exception process and approve risk acceptances below the material threshold; prepare and escalate anything above it.
  • Own security architecture review for significant changes and new technology, before commitment.
  • Report the risk position to the CIO, executive leadership, and the Audit Committee.

Detection and incident response

  • Own security monitoring across endpoints, cloud, on-premises, corporate applications, and identity - coverage, detection content, and tuning.
  • Own the SIEM estate and any managed detection provider relationship.
  • Act as incident commander for declared security incidents, with authority to direct containment in any estate.
  • Own post-incident review and drive remediation into the owning function’s backlog, tracked to closure.
  • Run tabletop and live exercises across technical teams and executive leadership.

Vulnerability and threat management

  • Own the vulnerability management program: scanning coverage, severity model, and remediation SLAs.
  • Own the prioritization model - excitability, exposure, business impact - so remediation effort is directed rather than alphabetical.
  • Track SLA attainment by estate owner, report it, and escalate breaches.
  • Own penetration testing and red team engagements: scope, vendors, cadence, and finding closure.
  • Own security testing requirements in the SDLC - SAST, dependency scanning, secrets detection, image scanning - and the gating thresholds.

Identity and access governance

  • Own the access governance model: least privilege, segregation of duties, and the evidence each control must produce.
  • Own privileged access policy - vaulting, just-in-time elevation, session recording, and break-glass.
  • Own the design, scope, and cadence of access reviews, and certify their completion.
  • Own authentication and session policy: MFA requirements, phishing-resistant factors, conditional access, and device trust.

Compliance and customer assurance

  • Own the ISO 27001 ISMS: scope, Statement of Applicability, internal audit program, management review, and certification maintenance.
  • Own the SOC 2 Type 2 program: control narrative, evidence calendar, and the audit period itself.
  • Close out FedRAMP authorization: authorization path and agency sponsorship, system boundary, the NIST SP 800-53 baseline, System Security Plan, 3PAO assessment, POA&M, and the monthly continuous monitoring that follows.
  • Close out CMMC Level 2: CUI scoping and enclave boundary, NIST SP 800-171 implementation, SSP and POA&M, SPRS submission, C3PAO assessment, and annual affirmation.
  • Sequence all four frameworks against one control set - shared evidence, one calendar, and a single answer to a control tested under more than one regime.
  • Own the external auditor and certification body relationship, plus the agency sponsor relationship where one is required, and coordinate evidence from each estate owner.
  • Build continuous control monitoring so compliance is a measured state, not an annual scramble.
  • Direct the compliance specialist, who runs evidence collection, control testing, POA&M tracking, and audit logistics. You keep framework scope, control interpretation, assessor and sponsor relationships, and the risk decisions behind them.
  • Own customer security assurance - questionnaires, customer audits, trust documentation, and security terms in contracts and DPAs.
  • Own the customer assurance pipeline: questionnaire intake, a library of pre-approved answers, and a turnaround commitment to Sales. The specialist drafts; you approve anything that commits us to a control, a date, or a contractual term.
  • Own controlled distribution of audit artifacts under NDA - SOC 2 report, penetration test summaries, certifications, authorization packages - and decide what is not released.

Third-party risk and security culture

  • Own vendor and SaaS security assessment: tier, assessment depth, sign-off before contract, and reassessment cadence.
  • Own security requirements in vendor contracts - control obligations, right to audit, and incident notification terms.
  • Own the awareness program, phishing simulation, and role-specific training for developers, privileged operators, and executives.

COMPENSATION & BENEFITS

RapidFort offers a competitive total rewards package that includes:

  • Base Salary: $200,000-$245,000 USD annually, depending on experience, qualifications, and location
  • Annual performance-based bonus
  • Equity: Stock options in RapidFort
  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Paid time off and company holidays
  • Paid sick leave
  • Company-provided equipment
  • Professional development and growth opportunities

RapidFort is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
665,268 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$18k – $47k per year (Estimated) • Remote • Full-Time
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
Junior Legal Council 2 hours ago
$18k – $50k per year (Estimated) • Remote/Hybrid • Sofia
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Apply
Remote • Full-Time
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
HIPAA
NIST 800-53
NIST 800-171
FedRAMP
Apply
$28k – $61k per year (Estimated) • Remote • 7+ years exp • Bachelor's Degree • Bishkek
Python
Java
SQL
PowerShell
Bash
Databases
MySQL
PostgreSQL
Snowflake
Google BigQuery
Amazon Redshift
Amazon Aurora
BigQuery
AI/ML
Wikipedia
DevOps
Terraform
CloudFormation
Datadog
Prometheus
CI/CD
AWS
Amazon EC2
Amazon S3
IAM
Amazon CloudWatch
Cybersecurity
SOC 2
Least Privilege
Apply
$175k – $337k per year (Estimated) • Remote • 12+ years exp • Sydney
Python
Go
TypeScript
SQL
Databases
Snowflake
Databricks
Google BigQuery
BigQuery
AI/ML
Model Context Protocol
AI Agents
RAG
DevOps
GCP
Azure
AWS
Kubernetes
Platform Engineering
Cybersecurity
ISO 27001
SOC 2
GDPR
Apply
$100k – $125k per year • Equity • Remote/Hybrid • Full-Time • 2+ years exp
Python
Bash
DevOps
Puppet
Ansible
VMWare
Chef
Ubuntu
Configuration Management
Proxmox VE
KVM
Hyper-V
Cybersecurity
ISO 27001
SOC 2
Apply
$120k – $160k per year • Remote • 5+ years exp
DevOps
Kubernetes
Cybersecurity
Zero Trust
Apply
$120k – $160k per year • Equity • Remote • 5+ years exp
DevOps
Docker
Kubernetes
Marketing
Salesforce
HubSpot
Marketo
Apply
$150k – $200k per year • Remote • Full-Time • 5+ years exp
Python
Go
Java
C++
DevOps
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Apply
$120k – $200k per year • Remote/Hybrid • 2+ years exp • Bachelor's Degree
DevOps
Docker
Kubernetes
Cybersecurity
CVE
Marketing
Salesforce
LinkedIn Ads
Google Ads
HubSpot
Reddit
Apply
See all jobs
This is one of many
665,268 more open roles from verified company boards, updated every day.