Apply Edge Start your job search

Director of Information Security

ClinLab Solutions Group · Greater Boston

Apply & track with Apply Edge

We are seeking a Director of Information Security (CISO) to build and lead our information security program as we scale our digital manufacturing infrastructure for aerospace, defense, and medical customers. Reporting to the VP of IT, you'll establish the strategy, policies, and controls that protect our intellectual property, production systems, and customer data, while enabling the business to move fast.This is a hands on, founding role: you'll build the security function from the ground up, standing up governance frameworks, hiring and developing a team over time, and partnering closely with IT, engineering, manufacturing, and legal to embed security into how we design, build, and ship. Given our work with defense and aerospace customers, you'll also own our compliance posture against frameworks like CMMC, NIST 800 171, and ITAR/EAR, making sure certification and audit readiness keep pace with our growth.Key ResponsibilitiesBuild and lead the company's information security program from the ground up, defining strategy, roadmap, and governance as the company scales.Own compliance and certification efforts for CMMC, NIST 800 171, and ITAR/EAR, partnering with legal, contracts, and program teams to meet customer and government requirements across our defense and aerospace work.Design and implement security policies, standards, and controls covering IT infrastructure, cloud environments, OT/manufacturing systems, and endpoints.Lead risk assessments and manage a prioritized remediation roadmap, balancing security rigor with the pace of a scaling manufacturing operation.Establish incident response, business continuity, and disaster recovery plans, and lead the organization's response to security incidents when they occur.Partner with IT, software, and manufacturing engineering teams to secure production systems, industrial control systems, and the software that runs our printers and factories.Manage security tooling and vendor relationships, including SIEM, endpoint detection, identity and access management, and vulnerability management platforms.Build and mature security awareness training and insider risk programs across the organization.Recruit, hire, and develop a security team as the function grows, setting the technical and cultural bar for the group.Serve as the primary point of contact for customer security questionnaires, third party audits, and government compliance assessments.Report on security posture, risk, and compliance status to executive leadership and, as needed, the board.QualificationsBachelor's degree in Computer Science, Information Security, Engineering, or a related field, or equivalent hands on experience.10+ years of progressive information security experience, including 5+ years in a senior security leadership role (CISO, Director of Security, or equivalent).CISSP certification required.Demonstrated experience building or maturing a security program from an early stage, including policy development, risk management, and control implementation.Direct experience with CMMC, NIST 800 171, and/or ITAR/EAR compliance in a manufacturing, defense, or aerospace environment.Strong knowledge of cloud security (AWS and/or Azure), network security, identity and access management, and endpoint protection.Experience securing OT/industrial environments or manufacturing systems, or strong familiarity with the unique risks of converging IT and OT.Proven experience leading incident response and crisis management for security events.Excellent communication skills, with experience translating technical risk into business terms for executive and customer audiences.Must be a U.S. citizen.PreferredAdditional certifications such as CISM or CCISO.Experience achieving or maintaining CMMC certification (Level 2 or above) for a manufacturing or defense contractor.Familiarity with export control regimes (ITAR/EAR) and working with classified or controlled unclassified information (CUI).Experience in an additive manufacturing, industrial, or advanced manufacturing environment.Background in a high growth or scale up company, building security functions with limited early headcount.Experience with security frameworks such as NIST CSF, ISO 27001, or SOC 2.Active U.S. Department of State clearance status.