ETAP

ETAP

Director of IT Security

Irvine, California, United States of America · Director · Full-time

Work authorization required$138k-$230kDetected 30 days ago
CI/CDCybersecuritySOC OperationsIncident ResponseComplianceStakeholder ManagementCadenceLeadershipCommunicationCollaborationCISSP

About the role

  • A practical security program that scales with clear priorities, minimal bureaucracy, and measurable risk reduction.
  • Audit- and customer-ready security posture (evidence organized, controls operating, owners assigned).
  • Cross-functional security ownership: security responsibilities embedded across IT, Engineering, and business teams rather than centralized in a large security staff.

Responsibilities

  • Lead a lightweight security governance cadence (e.g., monthly risk review, quarterly executive updates) to drive decisions, remove blockers, and maintain accountability.
  • Own security policies, exceptions, and compensating controls
  • Maintain an enterprise risk register, including IT, product/engineering, vendor, and compliance risks
  • drive mitigation plans with clear owners and deadlines.
  • Partner with R&D to implement scalable controls (e.g., MFA, least privilege, secure configurations, patching SLAs, logging baselines).
  • Collaborate with Engineering/R&D to implement secure development practices appropriate for the organization (secure SDLC expectations, code and dependency risk management, environment protections).
  • Partner with QA/Quality and Legal to maintain certifications, manage findings, and ensure contractual/regulatory obligations are met.
  • Own security policies, exceptions, and compensating controls; ensure policies are practical, adopted, and periodically reviewed.
  • Maintain an enterprise risk register, including IT, product/engineering, vendor, and compliance risks; drive mitigation plans with clear owners and deadlines.
  • Partner with Legal on interpretation of regulatory, NSA, customer, and contractual security obligations, translating requirements into operational controls.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or equivalent experience.
  • 10+ years in information security/IT risk roles with at least 5 years leading security programs or teams.
  • Strong ability to translate security requirements into practical controls in an environment with limited dedicated resources.
  • Proven executive communication skills: clear risk narratives and recommendations.
  • Required
  • Demonstrated experience leading audits and compliance readiness (internal/external/customer), including documentation and evidence management.

Skills

  • Experience with NSA environments, FOCI mitigation, or government-regulated security programs.
  • Familiarity with NIST Cybersecurity Framework 2.0, RMF concepts and secure controlled environment practices.
  • Experience supporting product development/engineering environments and CI/CD ecosystems.
  • CISSP, CISM, CISA, CRISC, or similar.
  • Risk-based prioritization in resource-constrained environments
  • Cross-functional governance and stakeholder management
  • Audit readiness and evidence-driven compliance
  • Incident leadership and decision-making under pressure
  • clear risk narratives and recommendations.
  • Strongly Preferred
  • Preferred Certifications
  • Core Competencies

Compensation

  • $137,500 - $229,500 Annual
  • This pay range represents the minimum and maximum compensation that the position offers, and final compensation can vary within the range depending on work location, job experience, skills, and relevant educational attainment and/or training.
  • Establish and maintain the company's security strategy, annual roadmap, and control framework aligned to business priorities and resource constraints.

Equal opportunity

  • ETAP is an Equal Opportunity Employer.

Visa & Work Authorization

  • Background checks will be conducted in accordance with local laws and may, subject to those laws, include proof of educational attainment, employment history verification, proof of work authorization, criminal records, identity verification

This listing is sourced directly from ETAP's careers page and normalized into a canonical job model.