Apply Edge Start your job search

Chief Information Security Officer (CISO)

Dracoe · Aberdeen, NC

Apply & track with Apply Edge

DracoeDracoe is focused on ensuring Western democracies maintain a decisive edge in a rapidly changing global security environment. Built on real-world operational experience, the company develops mission-ready, sovereign manufacturing capabilities that enable drone dominance and deliver operational advantage. Dracoe designs and mass-produces NDAA-compliant drones and open-architecture systems in state-of-the-art facilities across the United States. Every platform is engineered for mission success, combining cutting-edge technology with proven reliability and relevance for defense and security applications. The organization partners closely with customers to design, develop, and scale tailored solutions, and is actively recruiting for multiple positions to support its growth.Chief Information Security Officer (CISO)Department: Dracoe HQ / SecurityReports To: Director of Security, CEO and COOLocation: Aberdeen, North CarolinaSecurity DepartmentThe Security Department is responsible for safeguarding Dracoe's people, information, facilities, technologies, products, and operations. The department integrates cybersecurity, information security, industrial security, personnel security, physical security, compliance, resilience, and insider threat functions into a unified Security capability.Roles & ResponsibilitiesSecurity Leadership & Governance§ Lead the Security Department and establish a unified security strategy spanning cybersecurity, information security, physical security, personnel security, industrial security, compliance, and resilience.§ Serve as the executive accountable for protecting Dracoe’s people, information, technologies, facilities, products, and operations.§ Provide leadership and direction to the Facility Security Officer (FSO), who serves as Deputy Head of Security.§ Report security risks, compliance status, and program maturity to executive leadership and the Board.Compliance & Regulatory Assurance§ Lead compliance with Cybersecurity Maturity Model Certification (CMMC), National Institute of Standards and Technology (NIST) requirements, Defense Federal Acquisition Regulation Supplement (DFARS) clauses, International Traffic in Arms Regulations (ITAR), Export Administration Regulations (EAR), and customer security obligations.§ Own cybersecurity governance, System Security Plans (SSP), Plans of Action and Milestones (POA&M), policies, standards, and audit readiness.Cybersecurity & Information Security§ Lead cybersecurity, information security, cloud security, operational technology security, and secure engineering programs.§ Govern security architecture, identity management, vulnerability management, threat detection, incident response, and security operations.§ Ensure the protection of Controlled Unclassified Information (CUI), intellectual property, and defense-related technical data.Risk, Resilience & Supply Chain Security§ Lead enterprise risk management, business continuity, disaster recovery, and operational resilience programs.§ Establish third-party risk management and supply chain assurance programs.§ Ensure security requirements are embedded within customer, supplier, and subcontractor relationships.Security Culture§ Build and maintain a proactive security culture across the organisation.§ Sponsor awareness, insider threat, and security engagement programs.Qualifications – Required§ Minimum 8 years of progressive experience in cybersecurity, information security, risk management, or Security leadership, including at least 3 years in a senior leadership role.§ Demonstrated experience implementing and maintaining compliance with Cybersecurity Maturity Model Certification (CMMC), National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171), and Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012.§ Experience developing System Security Plans (SSP), Plans of Action and Milestones (POA&M), policies, standards, and assessment evidence.§ Experience securing Federal Risk and Authorization Management Program (FedRAMP) compliant cloud environments and Department of Defense Impact Level environments.§ Strong understanding of Controlled Unclassified Information (CUI) requirements and 32 Code of Federal Regulations Part 2002.§ Experience securing manufacturing, operational technology (OT), and industrial control systems (ICS) environments.§ Active United States Secret Security Clearance or ability to obtain one.§ United States citizenship required.Qualifications – Preferred§ Active Top Secret or Top Secret / Sensitive Compartmented Information (TS/SCI) clearance.§ Certified Information Systems Security Professional (CISSP).§ Certified Information Security Manager (CISM).§ Certified Cloud Security Professional (CCSP).§ Experience with Certified Third-Party Assessment Organization (C3PAO) assessments.§ Experience in aerospace, defense manufacturing, or unmanned aircraft systems.