Director of Information Security
Summary
A leadership role owning ARRO's enterprise information security, compliance, and technical programs: driving FedRAMP/NIST 800-53/CMMC/TX-RAMP/SOC 2 authorization and continuous monitoring, running GRC, and leading cross-functional technical initiatives while managing a GRC Lead and Technical Program Manager. Remote position.
Director of Information Security
Department: Information Security
Location: Remote
Reports to: Executive Director
Direct Reports: GRC Lead, Technical Program Manager
Summary
The Director of Information Security, Compliance & Technical Programs is responsible for leading ARRO’s enterprise security and compliance program while overseeing the execution of critical cross-functional technical initiatives across the organization.
As ARRO continues to expand its partnerships with federal and state agencies, this role will ensure the organization maintains a strong security posture aligned with industry and government frameworks including FedRAMP, NIST 800-53, CMMC, TX-RAMP, SOC 2, and related regulatory standards.
This role leads ARRO’s enterprise security and compliance program, including governance, risk management, regulatory alignment, and continuous monitoring initiatives.
The Director will lead ARRO’s Governance, Risk, and Compliance (GRC) function and provide oversight to the Technical Program Manager, ensuring security initiatives and technical programs are executed effectively across engineering, cloud infrastructure, and operations teams.
Key Responsibilities
Security Program Leadership
· Serve as the program owner for ARRO’s enterprise information security program, ensuring security governance and risk management practices are effectively implemented across the organization
· Lead the development and ongoing maturity of ARRO’s security framework aligned with FedRAMP, NIST 800-53, CMMC, TX-RAMP, SOC 2, and other applicable regulatory standards
· Establish and maintain ARRO’s Continuous Monitoring Program, ensuring ongoing validation of security controls through vulnerability management, control assessments, risk reporting, and remediation tracking
· Oversee the development and maintenance of security policies, standards, and procedures
· Ensure security controls are implemented across ARRO’s cloud infrastructure, platform, and operational processes
· Lead security incident response planning and security program maturity initiatives
FedRAMP & Regulatory Compliance
· Own ARRO’s FedRAMP Authorization to Operate (ATO) strategy and execution, guiding the organization through the authorization process and ongoing compliance requirements.
· Coordinate internal and external stakeholders involved in the authorization process including consultants, assessors, and sponsoring agencies
· Oversee the preparation, maintenance, and accuracy of FedRAMP security documentation and artifacts, including System Security Plans (SSPs), POA&Ms, control narratives, and supporting evidence.
· Ensure ARRO maintains operational readiness for security assessments, control testing, and authorization reviews.
· Establish and maintain processes necessary to support continuous monitoring obligations following authorization.
· Support customer and partner security assessments related to federal, state, and enterprise regulatory requirements.
Governance, Risk & Compliance (GRC)
· Provide leadership and direction to the GRC Lead
· Oversee the development and maintenance of key compliance artifacts including:
o System Security Plans (SSPs)
o Plans of Action and Milestones (POA&Ms)
o Risk registers
o Security policies and procedures
· Ensure ARRO maintains a structured risk management program, including identification, assessment, prioritization, and remediation of security risks
· Coordinate readiness activities with 3PAO assessors and external security consultants
· Establish internal governance processes to track compliance posture and remediation progress
Technical Program Leadership
· Provide leadership and strategic direction to the Technical Program Manager
· Oversee the execution of complex cross-functional initiatives including:
o Cloud infrastructure initiatives
o Security and compliance programs
o Platform reliability improvements
o Operational and infrastructure modernization efforts
· Establish program governance processes that improve visibility, accountability, and coordination across engineering and operations teams
· Support alignment between engineering delivery, cloud infrastructure initiatives, and compliance requirements
Cross-Functional Security Alignment
· Partner closely with Engineering leadership to ensure security practices are integrated into the software development lifecycle
· Collaborate with cloud and infrastructure teams to ensure secure architecture and operational practices
· Provide executive leadership with visibility into ARRO’s security posture, compliance progress, and risk landscape
· Promote a culture of security awareness, operational discipline, and continuous improvement
Team Leadership
· Lead and mentor the GRC Lead and Technical Program Manager
· Establish clear ownership and accountability for security and compliance initiatives
· Foster collaboration across engineering, product, customer operations, and infrastructure teams
· Ensure teams are aligned around ARRO’s security and compliance objectives
Qualifications
Required
· Experience leading security, compliance, or risk management programs in cloud or SaaS environments
· Familiarity with FedRAMP, NIST 800-53, or similar regulatory frameworks
· Experience coordinating complex cross-functional technical initiatives
· Strong program management, organizational, and leadership skills
· Ability to translate regulatory and technical requirements into structured operational programs
Preferred
· Experience supporting FedRAMP authorization or federal security programs
· Familiarity with Azure Government or GCC High environments
· Experience working with 3PAO assessors, security auditors, or compliance consultants
· Background in cloud infrastructure, DevSecOps, or security architecture
Success in This Role
Success in this role will be measured by ARRO’s ability to:
· Achieve and maintain FedRAMP authorization readiness
· Maintain a mature and sustainable enterprise security program
· Ensure consistent execution of cross-functional technical and compliance initiatives
· Strengthen ARRO’s reputation as a trusted technology partner to government and emergency response organizations