<p>ongoing development and management of our security program, responsible for establishing and executing our enterprise information security strategy, ensuring governance, risk management, compliance, and operational excellence across all offices.</p><p><br></p><ul><li>Develop and maintain security strategy, policies, and risk governance aligned with business objectives</li><li>Ensure compliance with NIST 800-171, CMMC, and client-driven requirements</li><li>Manage identity and access governance (hybrid AD/Entra), enforcing least privilege and Zero Trust principles</li><li>Optimize and integrate security technology stack (Fortinet, Microsoft Defender E5, Arctic Wolf MDR/SOCaaS, Intune/MEM, KnowBe4)</li><li>Lead security awareness, culture, and firmwide training initiatives</li><li>8+ years in information security</li><li>Experience managing enterprise security programs and operational security tools</li><li>Demonstrated expertise with NIST 800-171, CMMC, MDR/SOC providers, and enterprise tooling</li><li>Excellent executive communication, collaboration and stakeholder management skills</li></ul><p><br></p><p>Excellent benefits including MDV, 401k +match</p><p>Salary: $150 - $178k + bonus</p><p>Hybrid in Portland, OR</p><p><br></p>