Job Description
Company: United Launch Alliance
Location: Arlington, US
Chief Information Security Officer (CISO)
At ULA, the Chief Information Security Officer (CISO) is responsible for the overall security of the ULA enterprise IT infrastructure and application portfolio including all IT infrastructure, applications, and data.
The CISO is responsible for maintaining compliance with all security and compliance contractual requirements including DFARS, ISO 27000, AS9100, CMMC, as well as maintaining classified systems security, compliance, and accreditation.
Primary Responsibilities:
• Leadership of the IT Cyber Security Team and Security Operations Center (SOC) including both ULA employees and service providers.
• Overall security of the ULA enterprise IT infrastructure and application portfolio including all IT infrastructure, applications, and data.
• Maintain compliance with all security and compliance contractual requirements including DFARS, ISO 27000, AS9100, CMMC, as well as maintaining classified systems security, compliance, and accreditation.
• Review and analyze contracts for security and compliance implications and make favorable redlines, as appropriate and necessary.
• Use the Risk Management Framework principles to implement security and compliance controls while enabling organizational agility and execution.
• Ensure the security of United Launch Alliance data, systems, and overall IT enterprise architecture through the implementation and management of leading information security controls, industry best-practices, advanced monitoring and analysis solutions, advanced threat management solutions, intrusion detection and prevention systems, risk management.
• Develop and execute a robust and innovative information security strategy and multi-year roadmap leveraging advances in cyber security technologies and capabilities, state-of-the-art secure operating systems, networks, applications, and database products.
• Business process development, documentation of IT policies and procedures, and integration of the IT security value stream across the enterprise.
• Ensure a high level of system and data integrity through in-depth monitoring, event analysis, immediate incident response, and rapid recovery.
• Manage ULA access control, support ULA legal and the office of internal governance with investigations.
• Manage cyber incidents and vulnerabilities to resolution resulting from vulnerability scanning and advanced persistent threat notifications.
• Partner with other IT teams including IT infrastructure, IT project management office, IT vendor management office, IT applications, and other business units such as engineering and launch to implement appropriate IT security and compliance controls while enabling successful execution of IT projects and meeting project schedules.
• Serve as a voting member of the IT change management board and IT architecture board.
• Assess organizational impacts and develop risk mitigation strategies.
• Incorporate organizational change initiatives into plans to increase acceptance and improve results.
• Utilize approval processes to validate the investment value for IT projects.
• Drive enhanced security initiative projects to closure.
• Conducts risk assessment and provides recommendations for application design.
• Prepare security reports to regulatory agencies.
Required Education:
Bachelor’s degree from an accredited college or university required, Master’s degree in cybersecurity, information technology, business administration, or related field preferred.
Minimum Years of Experience:
Minimum of 10 years of related work experience.
Basic Qualifications:
Minimum of 10+ years of progressive experience in cybersecurity, information security, IT operations, or related technical/administrative disciplines within complex enterprise environments.
At least 4+ years of demonstrated leadership experience managing high-performing teams of 20+ security professionals, including exempt employees, technical leaders, and outsourced security operations center (SOC) resources.
Ability to obtain and maintain a TS/SCI security clearance is required; U.
S.
citizenship required.
Industry-recognized security certifications such as Certified Information Systems Security Professional (CISSP) strongly preferred; additional certifications such as CISM, CISA, or Security+ are a plus.
Proven track record of successfully leading enterprise cybersecurity programs and security operations centers (SOC), including incident response, threat detection, vulnerability management, and continuous monitoring initiatives.
Extensive knowledge of cybersecurity technologies, frameworks, architectures, and operational best practices across cloud, network, endpoint, identity, and data security domains.
Deep understanding of defense industrial base (DIB) security and compliance requirements, including ITAR, DFARS, NIST 800-171, NIST 800-53, CNSSI 1253, CMMC, ISO 27001, and AS9100 compliance frameworks.
Demonstrated experience interpreting, reviewing, and negotiating contractual security and compliance requirements, including identifying risk exposure and recommending favorable contract redlines when appropriate.
Strong understanding of third-party/vendor risk management lifecycle processes, including sourcing, procurement, onboarding, governance, compliance monitoring, and vendor relationship management.
Financial and operational acumen with experience evaluating business cases, budgeting, depreciation schedules, capitalization strategies, return on investment (ROI), and total cost of ownership (TCO) analyses.
Proven ability to recruit, mentor, develop, and retain high-performing teams while fostering a culture of accountability, collaboration, and continuous improvement.
Executive-level communication a.
Source: Jobilize