ForgeApply
Try it free

ForgeApply · Job listing

Vice President of Cybersecurity & Chief Information Security Officer (CISO)

Avav

Simi Valley, CA | Germantown, US$246k – $393konsite

Tailor your resume to this posting in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Avav's site. Free trial, no card required.

About this role

Worker Type

Regular Job Description

  Summary The “Vice President of Cybersecurity & Chief Information Security Officer (CISO)” is a senior executive responsible for establishing, implementing, and maintaining AV’s enterprise vision, strategy, and cybersecurity program to ensure the confidentiality, integrity, and availability of the organization’s information assets and technology resources.

The CISO provides strategic leadership for the organization’s cybersecurity function in support of both classified and unclassified defense programs. This role is responsible for ensuring compliance with Department of Defense (DoD) cybersecurity requirements, advancing the organization’s Cybersecurity Maturity Model Certification (CMMC) posture, implementing and maintaining alignment with National Institute of Standards and Technology (NIST) frameworks, and ensuring adherence to applicable federal laws, regulations, and contractual obligations. Additionally, the CISO will develop and execute cybersecurity strategies that support AV’s accelerated growth, acquisition, and integration initiatives.

Reporting to the Chief Information Officer (CIO), the CISO serves as the principal advisor to executive leadership and the Board of Directors on all matters related to cybersecurity, information security governance, cyber risk management, and the protection of Controlled Unclassified Information (CUI), classified national security information, and other sensitive organizational assets.

Position Responsibilities

Strategic Leadership & Governance • Develop and implement comprehensive cybersecurity strategy aligned with business objectives and national security requirements • Establish and maintain information security governance framework, policies, standards, and procedures • Serve as primary liaison with government customers, Defense Contract Management Agency (DCMA), Defense Counterintelligence and Security Agency (DCSA), and other regulatory bodies • Provide regular briefings to the Board of Directors, CEO, and executive leadership on security posture, risks, and initiatives • Lead enterprise risk management activities related to cybersecurity and information protection • Oversee cybersecurity budget planning, resource allocation, and investment prioritization

Compliance & Regulatory Management • Ensure organizational compliance with NIST SP 800-171, CMMC 2.0, DFARS, ITAR, and other applicable regulations • Lead and maintain Cybersecurity Maturity Model Certification (CMMC) readiness and certification efforts • Manage System Security Plan (SSP) development, Plan of Action & Milestones (POA&M), and continuous monitoring programs • Oversee NIST 800-53 control implementation for classified systems and Risk Management Framework (RMF) authorization processes • Coordinate with Defense Industrial Base (DIB) Cybersecurity Program requirements • Develop and execute insider threat detection and prevention programs • Lead international cybersecurity compliance strategy, ensuring adherence to UK MoD DEFCON 658 / Def Stan 05-138 , Cyber Essentials Plus , UK/EU GDPR , and applicable international data privacy and sovereignty regulations. • Establish cross-border data transfer controls and security architectures supporting NATO, AUKUS, and Five Eyes allied defense initiatives.

Technical Security Operations • Direct enterprise security operations including Security Operations Center (SOC), incident response, and threat intelligence • Oversee implementation and management of security technologies including SIEM, EDR, DLP, IAM, and encryption solutions • Ensure secure system development lifecycle practices and DevSecOps integration • Manage vulnerability management, penetration testing, and security assessment programs • Direct cloud security architecture and controls for classified and unclassified environments • Oversee identity and access management programs including privileged access management • Oversee cybersecurity governance for Special Access Programs (SAP/SAR) , SCIF network operations, COMSEC, and TEMPEST compliance in coordination with Government Security/OPSEC teams.

Incident Response & Business Continuity • Lead cyber incident response planning, coordination, and execution • Ensure timely reporting of cyber incidents to DoD, FBI, and other required agencies per DFARS 252.204-7012 • Coordinate with legal, CIO along with executive teams during security incidents • Oversee business continuity and disaster recovery planning for critical security systems • Manage relationships with external incident response partners and forensic specialists

Third-Party & Supply Chain Security • Establish and enforce third-party risk management and vendor security assessment programs • Oversee supply chain security controls and acquisition security requirements • Ensure subcontractor cybersecurity compliance flows down through contracts • Manage security requirements for cloud service providers and managed service providers

Organization Leadership • Build, lead, and mentor high-performing information security and cybersecurity teams • Establish organizational structure spanning cybersecurity operations, governance/risk/compliance, security architecture, and program security • Foster culture of security awareness and accountability throughout the organization • Implement and maintain security education, training, and awareness programs for all personnel • Develop succession planning and talent development strategies for security organization

Basic Qualifications (Required Skills & Experience)

Education • Bachelor’s degree in computer science, Information Security, Cybersecurity, Engineering, or related technical field required • Master's degree in related fields is strongly preferred  

Experience • Minimum 15 years of progressive experience in information security, with at least 10 years in senior leadership roles • Extensive experience in defense contracting environment with classified programs • Proven track record i

Ready to apply to Avav?

Tailor my resume for this role

Similar jobs

More like this: Security & Cybersecurity Jobs · More jobs at Avav · Browse all jobs