Now hiring

INFORMATION SECURITY OFFICER @ RPM

McKinney, Texas, USOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Key Responsibilities

Security Strategy & Governance

• Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).

• Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.

• Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.

• Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.

Regulatory & Federal Contract Compliance

• Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.

• Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.

• Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.

• Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.

• Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.

Risk Management

• Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.

• Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.

• Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.

Incident Response & Operations

• Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.

• Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.

• Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.

• Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.

Security Architecture & Technical Oversight

• Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.

• Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.

• Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.

Training & Culture

• Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.

• Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.

Reporting & Documentation

• Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.

• Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.

Qualifications

Education

• Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.

Experience

• 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.

• Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.

• Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.

Certifications (one or more preferred)

• CISSP (Certified Information Systems Security Professional)

• CISM (Certified Information Security Manager)

• CMMC Certified Professional (CCP) or Certified Assessor (CCA)

• CRISC (Certified in Risk and Information Systems Control)

• CCSP or equivalent cloud security certification

Skills & Attributes

• Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.

• Ability to translate technical risk into business terms for executive and ownership audiences.

• Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.

• Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.

• Sound judgment under pressure, particularly during incident response.

Working Conditions

• Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.

• Availability for occasional after-hours response in the event of a security incident.

• This position is located in McKinney, Texas. We do not compensate for relocation.

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores