Lead and support the implementation of NIST CSF 2.0 across enterprise systems and applications.
Assess security controls and document implementation status, risks, and gaps.
Develop and maintain core security documentation, including System Security Plans (SSP), Business Impact Analyses (BIA), Contingency Plans, Change Management Plans, and related governance artifacts.
Create and manage Plans of Action and Milestones (POA&M) to track remediation efforts and risk mitigation activities.
Collaborate with the CIO, Information Security team, system owners, and stakeholders to ensure security controls are properly implemented and monitored.
Provide subject matter expertise in risk assessment, technical security controls, SIEM, and XDR solutions.
Support audit readiness and preparation for independent security assessments.
Mentor junior team members and promote security best practices across the organization.
Required Qualifications
Bachelor’s degree in Information Technology, Cybersecurity, or a related field (or equivalent experience).
10+ years of experience in information security, including senior or lead-level responsibilities.
Strong hands-on experience in risk management, security assessments, security architecture, and incident response.
Solid understanding of enterprise IT infrastructure and security operations.