Logo for RAPIDFORT

Director of Cyber Security

Role overview

Qualifications

  • U.S. citizenship required
  • Experience with ISO 27001 and SOC 2 compliance
  • Strong understanding of risk management and security policies
  • Proven leadership in security incident management

Responsibilities

  • Own the information security policy set and control framework
  • Act as incident commander for declared security incidents
  • Own the vulnerability management program and prioritization model
  • Manage customer security assurance and compliance documentation

Key facts

Hard skills

Other skills

  • Governance
  • Leadership
  • Communication
  • Teamwork
  • Problem Solving

About the company

RAPIDFORT logo

RAPIDFORT

Cybersecurity

RapidFort, Inc. is a leading software supply chain security company that provides an innovative platform designed to automatically secure container applications and accelerate compliance processes. The company's comprehensive solution addresses critical cybersecurity challenges by removing up to 95% of Common Vulnerabilities and Exposures (CVEs) from container images without requiring any code changes. RapidFort's unified platform offers three core capabilities: curated near-zero CVE container images with FIPS 140-3 validation and daily builds, DevTime protection tools that generate Software Bill of Materials (SBOM) and Real Bill of Materials (RBOM) for vulnerability remediation, and RunTime protection that automatically secures unused components and reduces software attack surfaces by 60-90%. The platform serves organizations seeking to reduce development costs by 10%, accelerate software releases by 2-3 weeks, and achieve faster compliance with FedRAMP, cATO, CMMC, and SOC2 standards. RapidFort's solution integrates seamlessly with existing development workflows and technology stacks, consuming less than 1% system overhead while providing comprehensive security hardening. Trusted by government agencies including the U.S. Air Force and Space Force, as well as enterprise customers, RapidFort addresses the growing challenge of software supply chain security by eliminating "zombie code" – the 50-90% of unused software components that create unnecessary security risks. The company's approach enables organizations to spend more time building products rather than maintaining and updating dormant code, ultimately strengthening security posture while improving operational efficiency.

Company details

IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

DIRECTOR OF CYBER SECURITY

Location: United States — Remote: West Coast preferred
Department: Information Technology — Security, Risk & Compliance


Eligibility: U.S. citizenship required

ABOUT RAPIDFORT

RapidFort is a cybersecurity company focused on helping organizations secure and optimize their software supply chain and containerized environments. Our platform helps teams reduce software vulnerabilities and attack surface while improving the security and efficiency of modern cloud-native applications.

We work with commercial enterprises and public-sector organizations operating in highly regulated and security-sensitive environments.

Title: Director of Cyber Security

Department: Information Technology — Security, Risk & Compliance

Reports To: Chief Information Officer, with a standing reporting line to the Audit Committee

Direct Reports: Security operations, security engineering, and governance/risk/compliance, including a dedicated compliance specialist

Location: REMOTE

Employment Type: Full-time

Travel: Periodic travel for audits, customer engagements, and leadership meetings

On-Call: Incident commander for declared security incidents

ABOUT THE ROLE

RapidFort Inc. is looking for a Director of Cyber Security to own our security posture and the risk position behind it — what our controls are, whether they work, what remains exposed, and who has accepted that exposure.

This is a horizontal role by design. Cloud Operations, Infrastructure Engineering, and Corporate IT each own an estate and run it. You own the standard those estates are held to, the evidence that the standard is met, and the response when it is not.

You set the requirement and verify the outcome; the estate owner executes the remediation. That separation is deliberate — it is what makes the assurance worth anything.

You will own the ISO 27001 ISMS and the SOC 2 Type 2 program end to end, command security incidents with authority to direct containment across any estate, and give executive leadership and the Audit Committee an honest, current view of where our risk actually sits.

You will also own two program we need closed: FedRAMP authorization and CMMC Level 2. Both are live commitments rather than aspirations, and between them they will reshape how we scope, evidence, and monitor controls. You will have a dedicated compliance specialist to run the evidence machinery across all four frameworks — your job is to sequence them against one control set rather than four, and to carry the scoping and risk decisions that a specialist cannot.

Security is also part of our commercial proposition. You will be the person customers’ security teams talk to — questionnaires, customer audits, and the security terms in our contracts — and the person who decides what we will not agree to.

This role reports to the CIO but carries a standing reporting line to the Audit Committee, including the explicit right to escalate unresolved material risk without CIO clearance. We would rather write that down than leave it to goodwill.

WHAT YOU’LL DO

Policy, standards, and risk

• Own the information security policy set and the control framework, mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, and our customer and regulatory obligations.

• Own the technical standards the estate owners implement — hardening baselines, encryption, logging and retention, authentication, segmentation, and secure configuration.

• Own the risk framework and the risk register: current, evidenced, reviewed on cadence, with named owners.

• Own the exception process and approve risk acceptances below the material threshold; prepare and escalate anything above it.

• Own security architecture review for significant changes and new technology, before commitment.

• Report the risk position to the CIO, executive leadership, and the Audit Committee.

Detection and incident response

• Own security monitoring across endpoints, cloud, on-premises, corporate applications, and identity — coverage, detection content, and tuning.

• Own the SIEM estate and any managed detection provider relationship.

• Act as incident commander for declared security incidents, with authority to direct containment in any estate.

• Own post-incident review and drive remediation into the owning function’s backlog, tracked to closure.

• Run tabletop and live exercises across technical teams and executive leadership.

Vulnerability and threat management

• Own the vulnerability management program: scanning coverage, severity model, and remediation SLAs.

• Own the prioritization model — excitability, exposure, business impact — so remediation effort is directed rather than alphabetical.

• Track SLA attainment by estate owner, report it, and escalate breaches.

• Own penetration testing and red team engagements: scope, vendors, cadence, and finding closure.

• Own security testing requirements in the SDLC — SAST, dependency scanning, secrets detection, image scanning — and the gating thresholds.

Identity and access governance

• Own the access governance model: least privilege, segregation of duties, and the evidence each control must produce.

• Own privileged access policy — vaulting, just-in-time elevation, session recording, and break-glass.

• Own the design, scope, and cadence of access reviews, and certify their completion.

• Own authentication and session policy: MFA requirements, phishing-resistant factors, conditional access, and device trust.

Compliance and customer assurance

• Own the ISO 27001 ISMS: scope, Statement of Applicability, internal audit program, management review, and certification maintenance.

• Own the SOC 2 Type 2 program: control narrative, evidence calendar, and the audit period itself.

• Close out FedRAMP authorization: authorization path and agency sponsorship, system boundary, the NIST SP 800-53 baseline, System Security Plan, 3PAO assessment, POA&M, and the monthly continuous monitoring that follows.

• Close out CMMC Level 2: CUI scoping and enclave boundary, NIST SP 800-171 implementation, SSP and POA&M, SPRS submission, C3PAO assessment, and annual affirmation.

• Sequence all four frameworks against one control set — shared evidence, one calendar, and a single answer to a control tested under more than one regime.

• Own the external auditor and certification body relationship, plus the agency sponsor relationship where one is required, and coordinate evidence from each estate owner.

• Build continuous control monitoring so compliance is a measured state, not an annual scramble.

• Direct the compliance specialist, who runs evidence collection, control testing, POA&M tracking, and audit logistics. You keep framework scope, control interpretation, assessor and sponsor relationships, and the risk decisions behind them.

• Own customer security assurance — questionnaires, customer audits, trust documentation, and security terms in contracts and DPAs.

• Own the customer assurance pipeline: questionnaire intake, a library of pre-approved answers, and a turnaround commitment to Sales. The specialist drafts; you approve anything that commits us to a control, a date, or a contractual term.

• Own controlled distribution of audit artifacts under NDA — SOC 2 report, penetration test summaries, certifications, authorization packages — and decide what is not released.

Third-party risk and security culture

• Own vendor and SaaS security assessment: tier, assessment depth, sign-off before contract, and reassessment cadence.

• Own security requirements in vendor contracts — control obligations, right to audit, and incident notification terms.

• Own the awareness program, phishing simulation, and role-specific training for developers, privileged operators, and executives.

COMPENSATION & BENEFITS

RapidFort offers a competitive total rewards package that includes:

• Base Salary: $200,000–$245,000 USD annually, depending on experience, qualifications, and location
• Annual performance-based bonus
• Equity: Stock options in RapidFort
• Medical, dental, and vision insurance
• 401(k) retirement plan
• Paid time off and company holidays
• Paid sick leave
• Company-provided equipment
• Professional development and growth opportunities

RapidFort is an equal opportunity employer. We consider qualified applicants without regard to race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Cybersecurity Advisor Related jobs

Other jobs at RAPIDFORT

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.