Demo

Director, Information Security & Compliance

Citadel Electric Group, Inc.
Kansas, MO Full Time
POSTED ON 8/1/2026
AVAILABLE BEFORE 1/27/2027

Lead CMMC Level 2 and NIST SP 800-171 compliance, cybersecurity, IT governance, and physical security for a growing 250 person electrical contractor.

Reports To: President/CFO

๐€๐›๐จ๐ฎ๐ญ ๐ญ๐ก๐ž ๐‘๐จ๐ฅ๐ž

Citadel Electric Group performs commercial, industrial, and federal construction work. This newly created, hands-on leadership role will own our security and compliance program, protect our Controlled Unclassified Information environment, oversee Microsoft 365 security and configurations, supervise internal IT, manage our MSP, and maintain audit-ready evidence.

You will also own company-wide physical-security standards for facilities, controlled areas, the yard, warehouse, fleet, equipment, and active jobsites. This is not an advisory-only role. We need an accountable internal owner who will make decisions, verify execution, lead incidents, and hold internal and external resources accountable.

๐–๐ก๐š๐ญ ๐˜๐จ๐ฎ ๐–๐ข๐ฅ๐ฅ ๐Ž๐ฐ๐ง

๐…๐ž๐๐ž๐ซ๐š๐ฅ ๐‚๐จ๐ฆ๐ฉ๐ฅ๐ข๐š๐ง๐œ๐ž ๐š๐ง๐ ๐‚๐Œ๐Œ๐‚

โ€ข Own NIST SP 800-171 compliance, SPRS assessments, CMMC Level 2 readiness, and preparation for applicable self-assessments, government assessments, and third-party assessments.

โ€ข Maintain the SSP, POA&M, CUI boundary, SPRS score, control narratives, assessment results, affirmations, and supporting evidence.

โ€ข Coordinate with federal customers, assessors, counsel, the MSP, and internal stakeholders.

โ€ข Support Citadelโ€™s obligations under DFARS 252.204-7012, 252.204-7019, 252.204-7020, and 252.204-7021, as applicable.

๐‚๐ฒ๐›๐ž๐ซ๐ฌ๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐š๐ง๐ ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐Ÿ‘๐Ÿ”๐Ÿ“

โ€ข Build and operate the cybersecurity program, including policies, risk management, incident response, security awareness, access governance, asset inventory, vendor risk, and recurring control reviews.

โ€ข Review and validate Entra ID, Conditional Access, MFA, Intune, Defender, Purview, logging, administrative roles, endpoint security, and data-protection controls.

โ€ข Identify weaknesses, direct remediation, and challenge the MSP when configurations, documentation, responsiveness, or recommendations do not meet Citadelโ€™s requirements.

๐๐ก๐ฒ๐ฌ๐ข๐œ๐š๐ฅ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ

โ€ข Own access control and badging, visitor management, surveillance and CCTV, intrusion detection, alarms, monitoring, controlled-area requirements, and physical protection of sensitive information and IT assets.

โ€ข Establish physical-security standards for the yard, warehouse, equipment storage, fleet, vehicles, and active jobsites.

โ€ข Coordinate implementation and incident response with Operations, Safety, project leadership, and outside vendors.

๐ˆ๐“ ๐†๐จ๐ฏ๐ž๐ซ๐ง๐š๐ง๐œ๐ž ๐š๐ง๐ ๐ˆ๐ง๐œ๐ข๐๐ž๐ง๐ญ ๐‘๐ž๐ฌ๐ฉ๐จ๐ง๐ฌ๐ž

โ€ข Create and maintain an annual IT and cybersecurity roadmap and help prioritize budget, lifecycle, backup and recovery, logging, endpoint, identity, network, and infrastructure decisions.

โ€ข Ensure material technology changes are reviewed, approved, tested, documented, and tied to business risk.

โ€ข Lead cybersecurity incidents and significant IT-risk events through triage, containment, investigation, recovery, root-cause analysis, corrective action, executive communication, and required reporting.

๐„๐ฏ๐ข๐๐ž๐ง๐œ๐ž, ๐’๐ญ๐š๐Ÿ๐Ÿ, ๐š๐ง๐ ๐•๐ž๐ง๐๐จ๐ซ๐ฌ

โ€ข Own the compliance evidence repository and documentation standards for internal IT, the MSP, vendors, and control owners.

โ€ข Directly supervise Citadelโ€™s IT team

โ€ข Own the MSP relationship as a security and engineering partnership and hold vendors accountable for outcomes, responsiveness, documentation, and secure execution.

๐‘๐ž๐ช๐ฎ๐ข๐ซ๐ž๐ ๐๐ฎ๐š๐ฅ๐ข๐Ÿ๐ข๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ

โ€ข Eight or more years of progressive experience in cybersecurity, information security, IT infrastructure, compliance, or risk management, including at least three years in a senior, lead, supervisory, or management capacity.

โ€ข Direct experience leading or materially supporting CMMC Level 2, NIST SP 800-171, DFARS cybersecurity requirements, SPRS assessments, DIBCAC reviews, C3PAO assessments, or comparable federal-contractor readiness work.

โ€ข Working knowledge of NIST SP 800-171 and familiarity with NIST SP 800-53 and the NIST Cybersecurity Framework.

โ€ข Practical experience with Microsoft 365, Entra ID, Intune, Defender, Purview, Conditional Access, MFA, logging, and administrative security.

โ€ข Experience implementing or overseeing access control, badging, visitor management, surveillance, alarms, intrusion detection, and protection of sensitive assets.

โ€ข Experience supervising internal IT personnel, managing an MSP, or leading technical vendors through accountable delivery.

โ€ข Experience leading cybersecurity incidents or significant IT-risk events and producing defensible documentation.

โ€ข Strong plain-English communication with owners, executives, field supervisors, project teams, tradespeople, vendors, federal customers, counsel, and assessors.

โ€ข Ability to successfully complete required background screening and satisfy applicable federal-customer access requirements.

โ€ข This position may involve access to export-controlled technical data and other restricted information. The selected candidate must be able to satisfy all access requirements imposed by applicable law, regulation, executive order, or government contract.

๐๐ซ๐ž๐Ÿ๐ž๐ซ๐ซ๐ž๐ ๐๐ฎ๐š๐ฅ๐ข๐Ÿ๐ข๐œ๐š๐ญ๐ข๐จ๐ง๐ฌ

โ€ข Successful CMMC Level 2 assessment experience or prior engagement with a C3PAO, DIBCAC, federal customer, or government cybersecurity assessor.

โ€ข In-house experience with a federal contractor, defense supplier, construction company, manufacturer, or engineering-services firm.

โ€ข GCC, GCC High, ITAR, or EAR experience.

โ€ข Experience building practical security programs for mid-sized operating businesses or distributed operations.

โ€ข Relevant credentials such as CISSP, CISM, CRISC, CMMC CCP, CMMC CCA, ASIS PSP, ASIS CPP, or comparable demonstrated expertise.

๐–๐ก๐š๐ญ ๐“๐ก๐ข๐ฌ ๐‘๐จ๐ฅ๐ž ๐ˆ๐ฌ ๐๐จ๐ญ

This is not a pure CIO, passive compliance, or help-desk management position. You will review configurations, validate controls, walk facilities and jobsites, lead incidents, produce evidence, make decisions, and ensure remediation is completed.

๐‚๐จ๐ฆ๐ฉ๐ž๐ง๐ฌ๐š๐ญ๐ข๐จ๐ง ๐š๐ง๐ ๐๐ž๐ง๐ž๐Ÿ๐ข๐ญ๐ฌ

โ€ข Competitive base salary commensurate with experience, discussed with finalists.

โ€ข Performance bonus opportunity.

โ€ข Health and dental insurance for you and your dependents, with premiums paid by Citadel.

โ€ข 401(k) with a 3% company contribution.

โ€ข Additional discretionary profit-sharing contribution that has historically been 14% of eligible compensation, subject to plan terms, eligibility requirements, company performance, and annual approval.

โ€ข Paid time off.

โ€ข Company-provided cell phone.

๐‹๐จ๐œ๐š๐ญ๐ข๐จ๐ง ๐š๐ง๐ ๐“๐ซ๐š๐ฏ๐ž๐ฅ

Travel is primarily local and during the business day, with occasional out-of-area or overnight travel for project sites, federal-customer engagements, vendor meetings, training, and CMMC assessment activities.

๐‡๐จ๐ฐ ๐ญ๐จ ๐€๐ฉ๐ฉ๐ฅ๐ฒ

Apply directly through this posting. Applications will be reviewed on a rolling basis.


Citadel Electric Group, Inc. is an Equal Opportunity Employer

Salary.com Estimation for Director, Information Security & Compliance in Kansas, MO
$201,371 to $241,920
If your compensation planning software is too rigid to deploy winning incentive strategies, itโ€™s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Director, Information Security & Compliance?

Sign up to receive alerts about other jobs on the Director, Information Security & Compliance career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$220,784 - $286,649
Income Estimation: 
$270,069 - $359,305
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$220,784 - $286,649
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Not the job you're looking for? Here are some other Director, Information Security & Compliance jobs in the Kansas, MO area that may be a better fit.

  • Olin Corporation Independence, MO
  • Title: Information Security Systems Specialist Location: Independence, MO Salary: $92,100 - $138,800 Schedule: 9/80 Focus: Olin Winchester is hiring an Inf... more
  • 4 Days Ago

  • Winchester Ammunition Independence, MO
  • Title: Information Security Systems Specialist Location: Independence, MO Salary: $92,100 - $138,800 Schedule: 9/80 Focus: Olin Winchester is hiring an Inf... more
  • 11 Days Ago

AI Assistant is available now!

Feel free to start your new journey!