Director of Cybersecurity, Governance, Risk and Compliance
Gross, Mendelsohn & Associates, P.A. Director of Cybersecurity, Governance, Risk and Compliance
Summary
Build and lead the cybersecurity governance, risk & compliance advisory practice at a Mid-Atlantic CPA/advisory firm, serving clients (especially government contractors) and the firm itself. Day to day: NIST 800-171 gap assessments, SSPs/POA&Ms, DFARS and CMMC readiness, oversight of security controls, and executive risk reporting.
Gross Mendelsohn, one of the Mid-Atlantic’s leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to build and lead our cybersecurity and IT risk advisory capabilities.
This is a visible, high-impact leadership role responsible for designing, implementing, and overseeing enterprise cybersecurity and IT compliance programs for both clients and the firm, particularly government contractors and organizations operating in regulated environments.
As cybersecurity requirements continue to intensify, this role will sit at the intersection of IT architecture, regulatory compliance, risk advisory, and executive leadership. The Director will help position Gross Mendelsohn as a trusted advisor in cybersecurity governance, CUI compliance, and federal regulatory readiness.
Recognized with nine Top Workplace awards, Gross Mendelsohn is committed to professional excellence, collaboration, and long-term growth. This opportunity offers leadership visibility, strategic influence, and the ability to build and expand a critical service line within a respected independent firm.
Key Responsibilities
Cybersecurity & IT Governance Leadership
-
Serve as the firm’s senior leader for cybersecurity governance, risk, and compliance advisory services
-
Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, and related standards
-
Lead end-to-end CUI and federal compliance programs, including development and maintenance of System Security Plans (SSP) and Plans of Action & Milestones (POA&M)
-
Conduct NIST SP 800-171 gap assessments and develop prioritized remediation roadmaps
-
Support clients with DFARS 252.204-7012 compliance, SPRS scoring, and CMMC readiness initiatives
-
Prepare clients for audits, mock assessments, and government inquiries
IT Infrastructure & Security Oversight
-
Oversee implementation and validation of technical cybersecurity controls, including:
-
Multi-factor authentication
-
Encryption (data at rest and in transit)
-
Endpoint protection
-
Logging, SIEM, and continuous monitoring
-
Network segmentation
-
Secure configuration and hardening standards
-
Provide advisory oversight of secure cloud environments, including Microsoft GCC High, Azure Government, and AWS GovCloud
-
Establish identity and access management frameworks and privileged access controls
-
Evaluate backup, disaster recovery, and business continuity processes
-
Direct incident response strategy and regulatory reporting obligations
Supply Chain & Flow-Down Advisory
-
Advise prime contractors on subcontractor cybersecurity flow-down requirements
-
Assess subcontractor readiness and compliance risk exposure
-
Support documentation required for federal scrutiny
Training & Continuous Improvement
-
Develop and deliver CUI-specific and role-based cybersecurity training
-
Implement measurable security awareness initiatives, including phishing simulations
-
Lead annual program reviews and continuous improvement initiatives
-
Maintain compliance posture during infrastructure changes, acquisitions, or system transitions
Executive Advisory & Reporting
-
Prepare executive-level cybersecurity risk reports and board-ready briefings
-
Translate complex technical risk into actionable business guidance
-
Collaborate with firm leadership to expand cybersecurity service offerings