About this role
Key Responsibilities
Security Strategy & Governance
• Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
• Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
• Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
• Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.
Regulatory & Federal Contract Compliance
• Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
• Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
• Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.
• Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
• Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
Risk Management
• Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
• Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
• Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.
Incident Response & Operations
• Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
• Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
• Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
• Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.
Security Architecture & Technical Oversight
• Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
• Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
• Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.
Training & Culture
• Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
• Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.
Reporting & Documentation
• Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
• Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.
Qualifications
Education
• Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.
Experience
• 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
• Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
• Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.
Certifications (one or more preferred)
• CISSP (Certified Information Systems Security Professional)
• CISM (Certified Information Security Manager)
• CMMC Certified Professional (CCP) or Certified Assessor (CCA)
• CRISC (Certified in Risk and Information Systems Control)
• CCSP or equivalent cloud security certification
Skills & Attributes
• Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
• Ability to translate technical risk into business terms for executive and ownership audiences.
• Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
• Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
• Sound judgment under pressure, particularly during incident response.
Working Conditions
• Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
• Availability for occasional after-hours response in the event of a security incident.
• This position is located in McKinney, Texas. We do not compensate for relocation.