Key Responsibilities
Security Strategy & Governance
- Develop, implement, and continuously update RPM's enterprise information security strategy, policies, and standards, aligned with business objectives and industry frameworks (NIST CSF, NIST SP 800-171, CMMC 2.0, ISO 27001).
- Serve as the primary point of accountability for information security decisions, presenting risk posture, incident trends, and program maturity to executive leadership on a regular cadence.
- Own the company's information security governance structure, including policy review cycles, exception handling, and security committee coordination.
- Maintain a multi-year security roadmap that balances regulatory obligations, cyber insurance requirements, and the operational realities of a construction and development environment, including field offices, job trailers, project management systems, and connected job-site equipment.
Regulatory & Federal Contract Compliance
- Own compliance with cybersecurity requirements tied to RPM's federal, DoD, and government-adjacent construction contracts, including CMMC 2.0 (Levels 1-2) and NIST SP 800-171, and monitor the phased CMMC rollout (in effect since November 2025) for changes affecting current and upcoming bids.
- Ensure proper identification, marking, and protection of Controlled Unclassified Information (CUI) and Federal Contract Information (FCI) across project documentation, estimating, and file-sharing systems.
- Maintain and update the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and supporting evidence needed for CMMC self-assessments, third-party assessments (C3PAO), and DFARS 252.204-7012/7019/7020 flow-down requirements.
- Track evolving federal, state, and industry compliance requirements, including cyber insurance underwriting standards and client contractual security clauses, and translate them into actionable internal controls.
- Act as RPM's point of contact for compliance audits, client security questionnaires, and insurance carrier risk assessments.
Risk Management
- Lead enterprise cybersecurity risk assessments across corporate IT, project sites, and third-party or subcontractor systems; maintain a prioritized risk register with remediation owners and timelines.
- Evaluate and manage security risk associated with vendors, subcontractors, design partners, and cloud or SaaS platforms used for project management, estimating, accounting, and document control.
- Partner with Legal and Procurement to ensure security requirements are included in subcontractor, vendor, and client contracts.
Incident Response & Operations
- Own and maintain RPM's incident response plan, including detection, containment, eradication, recovery, and post-incident review procedures.
- Lead the response to security incidents, data breaches, and suspected fraud, including wire and payment fraud, a common risk in construction payment workflows, coordinating with IT, Legal, executive leadership, and external forensics or legal counsel as needed.
- Oversee security monitoring, logging, and alerting across corporate networks, cloud environments, and remote or job-site connectivity.
- Ensure timely notification obligations are met for clients, regulators, and insurance carriers in the event of a reportable incident.
Security Architecture & Technical Oversight
- Partner with IT leadership to ensure secure architecture, configuration, and access controls across networks, endpoints, cloud platforms, project management/ERP systems, and remote job-site connectivity.
- Oversee identity and access management practices, including least-privilege access, multi-factor authentication, and periodic access reviews for corporate and field personnel.
- Review and approve security requirements for new technology deployments, including project management software, drone or GPS survey data systems, and connected job-site equipment.
Training & Culture
- Design and deliver company-wide security awareness training, including phishing and social-engineering simulations, tailored to both office staff and field or project personnel.
- Build a culture of security accountability across all levels of the organization, from executive leadership to project superintendents and site staff.
Reporting & Documentation
- Maintain accurate, audit-ready documentation of policies, risk assessments, control evidence, and training records.
- Prepare periodic security posture reports and metrics for executive leadership and, where applicable, the board or ownership group.
Qualifications
Education
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field required; Master's degree preferred.
Experience
- 7+ years of progressive experience in information security, risk management, or IT compliance, including at least 3 years in a leadership role.
- Demonstrated experience supporting compliance with CMMC, NIST SP 800-171, or similar federal/defense contracting cybersecurity requirements strongly preferred.
- Experience in construction, engineering, real estate development, or another project-based industry is a plus, but not required.
Certifications (one or more preferred)
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- CMMC Certified Professional (CCP) or Certified Assessor (CCA)
- CRISC (Certified in Risk and Information Systems Control)
- CCSP or equivalent cloud security certification
Skills & Attributes
- Strong working knowledge of NIST CSF, NIST SP 800-171/800-172, CMMC 2.0, and general security frameworks such as ISO 27001 and SOC 2.
- Ability to translate technical risk into business terms for executive and ownership audiences.
- Strong project management and cross-functional collaboration skills, comfortable working with IT, Legal, Finance, Estimating, and Field Operations.
- Excellent written and verbal communication skills, including experience preparing documentation for audits and assessments.
- Sound judgment under pressure, particularly during incident response.
Working Conditions
- Primarily office-based with periodic travel to project sites, regional offices, or client locations as needed.
- Availability for occasional after-hours response in the event of a security incident.
- Locations
- McKinney, Texas, United States
- Education
- bachelor degree and postgraduate degree
- Experience
- 7+ years