What are the responsibilities and job description for the Director, IT Risk and Compliance position at Tech Army, LLC?
Position Overview
The IT Risk and Compliance Director will provide on-demand cybersecurity staff augmentation services to support the Department in proactively identifying, analyzing, and mitigating cybersecurity risks across its enterprise environment.
Key Responsibilities
- Conduct comprehensive vulnerability assessments using industry-standard tools and methodologies.
- Perform penetration testing using a structured approach progressing from passive to active techniques.
- Identify and analyze Indicators of Compromise (IOCs), unauthorized access attempts, and data exfiltration risks.
- Apply and interpret the Common Vulnerability Scoring System (CVSS) for risk prioritization.
- Conduct threat hunting activities to detect active or persistent threats within enterprise environments.
- Provide incident response support, including containment, eradication, and recovery recommendations.
Required Qualifications
- Bachelor's or Master's degree from an accredited college or university in Computer Science, Information Systems, or a related field, or four (4) years of equivalent work experience. Relevant experience may be substituted for education on a year-for-year basis, where applicable.
- Demonstrated experience providing cybersecurity services for large, complex enterprise environments, preferably within government or criminal justice agencies.
- Proven experience delivering threat hunting, vulnerability assessments, penetration testing (internal and external), and incident response services.
- Experience supporting environments subject to Criminal Justice Information Services (CJIS) Security Policy requirements.
- Ability to provide cybersecurity advisory services, including strategy, governance, risk and compliance (GRC), and remediation planning.
- Minimum of five (5) years of hands-on cybersecurity experience in one or more of the following areas:
- Threat Hunting & Threat Intelligence
- Penetration Testing & Ethical Hacking
- Vulnerability Management
- Incident Response & Digital Forensics
- Demonstrated experience operating in both offensive security roles (Red Team/Penetration Testing) and defensive security roles (SOC, Blue Team, and Incident Response).
Preferred Qualifications
- Experience conducting Red Team and adversarial simulation exercises.
- Experience supporting cybersecurity roadmap development and maturity assessments.
- Relevant industry certifications such as:
- CISSP (Certified Information Systems Security Professional)
- CEH (Certified Ethical Hacker)
- OSCP (Offensive Security Certified Professional)
- GIAC (Global Information Assurance Certification)
- CISM (Certified Information Security Manager)
- CISA (Certified Information Systems Auditor)
- Experience integrating with client Managed Service Providers (MSPs) and internal IT teams.
Salary : $125 - $130