Lead Cybersecurity Engineer (Compliance)
HRU
- Oshkosh, WI
- $112,000-155,000 per year
- Permanent
- Full-time
- Lead or participate in cybersecurity compliance efforts, including preparation for and execution of assessments (e.g., CMMC).
- Translate cybersecurity control requirements into system-level configurations and interpret system security capabilities for compliance.
- Prepare reports identifying gaps in policies, processes, and controls, and recommend remediation strategies.
- Advise leadership on program budgets and coordinate with regional leads to develop compliance strategies adapted to different cultures and languages.
- Conduct or lead IT audits, presenting findings in a way that is clear to diverse stakeholders.
- Stay informed on research, trends, and developments in all areas of regulatory compliance.
- Serve as a trusted advisor to business functions (Finance, HR, Engineering) and IT teams.
- Ensure business and technical requirements align with policy, regulatory, and contractual compliance.
- Contribute to the development and maintenance of our cybersecurity strategy.
- Bachelor's degree in Cybersecurity, Information Systems, Communications, Computer Science, or equivalent.
- 6 or more years of experience in cybersecurity with direct involvement in regulatory or framework compliance (CMMC, NIST 800-171, PCI, ISO 27001, SOC2, FAR, DFARS, etc.).
- Strong technical background with the ability to translate cybersecurity regulations into technical controls and advise engineering teams.
- Experience participating in or leading cybersecurity compliance assessments such as CMMC or ISO certification.
- Documented and demonstrated experience with defense regulatory compliance requirements including CMMC, NIST, and DFARS.
- Graduate degree in Cybersecurity, Information Systems, Management, or equivalent.
- Relevant industry certifications (CISSP, CEH, GIAC, Security+, SSAP, etc.).
- In-depth knowledge of regulatory compliance models (NIST, HIPAA, PCI, ISO, etc.).
- Hands-on design or operational experience in infrastructure, cloud, or application development.
- Knowledge of security controls for networks, applications, and operating systems.
- Experience leading IT audits and communicating technical concepts to non-technical stakeholders.
- Active or eligible for U.S. Government Secret clearance.
- Experience drafting information security policies, procedures, and standards.
- Experience testing effectiveness and adherence of cybersecurity controls.
- Ability to translate complex contractual and regulatory requirements into actionable information system configurations.
- Strong cross-functional collaboration skills.
- We prefer to have candidates based in Oshkosh, WI. Candidates may also be based in McConnellsburg, PA; Hagerstown, MD; or Orlando, FL. Those who are not based in Oshkosh, WI will travel to our headquarters (in Oshkosh, WI) approximately 4 times per year. To be clear, this role is NOT open to fully remote candidates.
- Hybrid schedule with 3 days onsite and two days remote each week.
- Routine office environment with periods of sitting, computer use, and communication.
- Occasional overtime, weekend work, or off shift hours as needed (but this will be quite rare).
- Some stress due to deadlines or cyclical workloads.
- EOE (including Disability/Veterans)