Vice President, Cyber Security & GRC
Summary
First executive owner of security and GRC at a data-center construction firm: builds the whole security program from scratch — SOC 2 Type II, identity (M365/Entra ID), risk register, third-party risk — on-site in Austin, TX, reporting to the SVP of Technology.
- Enterprise cybersecurity strategy, roadmap, and architecture across a hybrid, heavily field-deployed environment.
- Identity as the primary security control plane: single sign-on, conditional access, privileged access, joiner-mover-leaver automation, and access recertification.
- Detection and response capability, vulnerability management, endpoint hardening, and encryption enforcement.
- Incident response: planning, exercising, and serving as incident commander when it counts.
- Security awareness and role-based training measured on outcomes, not completion rates.
- The policy framework end to end — drafting, executive approval, attestation, exceptions, and annual review.
- The enterprise technology risk register: scoring methodology, treatment plans with named owners, and escalation of overdue items.
- The control framework and testing calendar, mapped across SOC 2 Trust Services Criteria, NIST CSF, and additional frameworks as adopted.
- SOC 2 Type 1 and Type 2 delivery, examiner relationship, evidence library, and management responses to findings.
- A register of security and privacy obligations arising from client contracts, insurance attestations, and applicable law across US and EMEA operations.
- Quarterly reporting to the executive team and annual reporting to the board.
- Security architecture and acquisition control across the SaaS estate, including a written standard for how platforms are evaluated, integrated, monitored, and retired.
- Data classification and handling across collaboration platforms, the data warehouse, and reporting layers.
- SaaS rationalization and licensing strategy in partnership with Business Platforms & Intelligence.
- A tiered third-party risk program, oversight of our managed service partner, and the security terms in technology agreements.
- Governance of enterprise AI tooling — permitted use, data boundaries, approval workflow, and monitoring.
- First 90 days. A documented view of our posture, control gaps, and platform estate. A live risk register with named owners. The steering committee chartered and running. Collaboration with IT Leadership for SOC II Type ! Certification early Q1 FY27
- Six months. SOC 2 Type 1 delivered on target. A control testing calendar in operation. Identity lifecycle automation resolved. A costed plan for the managed service transition.
- Twelve months. Type 2 underway. Single sign-on and conditional access at target coverage. Third-party risk program running. A standard client security response package in use. Quarterly GRC reporting accepted by the executive team.
- Ten or more years in information technology, with at least seven in information security and at least four leading a security function or a substantial security program.
- End-to-end ownership of a SOC 2 examination & ISO Certification— scoping, control design, evidence production, examiner management, and report issuance. Not coordination of someone else’s audit.
- Ownership of a GRC function or program: policy framework, risk register, control testing, exception management, and executive-level risk reporting.
- Deep working expertise in Microsoft 365 and Entra ID security — conditional access, identity protection, privileged identity management, data loss prevention, retention, and tenant configuration.
- Demonstrated experience securing a multi-platform SaaS estate, including identity federation and lifecycle automation.
- Practical incident response leadership, including communicating with executives and outside parties during a live event.
- Experience overseeing outsourced control operators — reviewing provider evidence and testing it rather than accepting assertions.
- The ability to write a board-ready memo and present risk and investment trade-offs to a non-technical audience.
- A bachelor’s degree in a related field, or equivalent demonstrated experience.
- CISSP, CISM, or CCISO. CRISC or CISA is specifically relevant to the GRC mandate.
- Experience in construction, engineering, staffing, logistics, or another distributed, field-heavy workforce.
- Government-contracting or defense-adjacent exposure, including NIST SP 800-171 or CMMC.
- Private-equity or venture-backed company experience with board-level security reporting.
- Cross-border operations, including EMEA data protection obligations.
- ISO 27001 implementation or certification experience.
- Azure, Snowflake, or modern data platform security experience.
- Full-time on-site at our Bee Caves Road, Austin, TX 78737 office. This role is not hybrid and not remote.
- Up to 20% travel, including project sites, data center locations, and periodic travel to Europe.
- Availability outside standard hours for security incidents and defined escalation windows.
- Background check and periodic re-screening consistent with company policy and client requirements.
