- Enterprise cybersecurity strategy, roadmap, and architecture across a hybrid, heavily field-deployed environment.
- Identity as the primary security control plane: single sign-on, conditional access, privileged access, joiner-mover-leaver automation, and access recertification.
- Detection and response capability, vulnerability management, endpoint hardening, and encryption enforcement.
- Incident response: planning, exercising, and serving as incident commander when it counts.
- Security awareness and role-based training measured on outcomes, not completion rates.
- The policy framework end to end — drafting, executive approval, attestation, exceptions, and annual review.
- The enterprise technology risk register: scoring methodology, treatment plans with named owners, and escalation of overdue items.
- The control framework and testing calendar, mapped across SOC 2 Trust Services Criteria, NIST CSF, and additional frameworks as adopted.
- SOC 2 Type 1 and Type 2 delivery, examiner relationship, evidence library, and management responses to findings.
- A register of security and privacy obligations arising from client contracts, insurance attestations, and applicable law across US and EMEA operations.
- Quarterly reporting to the executive team and annual reporting to the board.
- Security architecture and acquisition control across the SaaS estate, including a written standard for how platforms are evaluated, integrated, monitored, and retired.
- Data classification and handling across collaboration platforms, the data warehouse, and reporting layers.
- SaaS rationalization and licensing strategy in partnership with Business Platforms & Intelligence.
- A tiered third-party risk program, oversight of our managed service partner, and the security terms in technology agreements.
- Governance of enterprise AI tooling — permitted use, data boundaries, approval workflow, and monitoring.
- First 90 days. A documented view of our posture, control gaps, and platform estate. A live risk register with named owners. The steering committee chartered and running. Collaboration with IT Leadership for SOC II Type ! Certification early Q1 FY27
- Six months. SOC 2 Type 1 delivered on target. A control testing calendar in operation. Identity lifecycle automation resolved. A costed plan for the managed service transition.
- Twelve months. Type 2 underway. Single sign-on and conditional access at target coverage. Third-party risk program running. A standard client security response package in use. Quarterly GRC reporting accepted by the executive team.
- Ten or more years in information technology, with at least seven in information security and at least four leading a security function or a substantial security program.
- End-to-end ownership of a SOC 2 examination & ISO Certification— scoping, control design, evidence production, examiner management, and report issuance. Not coordination of someone else’s audit.
- Ownership of a GRC function or program: policy framework, risk register, control testing, exception management, and executive-level risk reporting.
- Deep working expertise in Microsoft 365 and Entra ID security — conditional access, identity protection, privileged identity management, data loss prevention, retention, and tenant configuration.
- Demonstrated experience securing a multi-platform SaaS estate, including identity federation and lifecycle automation.
- Practical incident response leadership, including communicating with executives and outside parties during a live event.
- Experience overseeing outsourced control operators — reviewing provider evidence and testing it rather than accepting assertions.
- The ability to write a board-ready memo and present risk and investment trade-offs to a non-technical audience.
- A bachelor’s degree in a related field, or equivalent demonstrated experience.
- CISSP, CISM, or CCISO. CRISC or CISA is specifically relevant to the GRC mandate.
- Experience in construction, engineering, staffing, logistics, or another distributed, field-heavy workforce.
- Government-contracting or defense-adjacent exposure, including NIST SP 800-171 or CMMC.
- Private-equity or venture-backed company experience with board-level security reporting.
- Cross-border operations, including EMEA data protection obligations.
- ISO 27001 implementation or certification experience.
- Azure, Snowflake, or modern data platform security experience.
- Full-time on-site at our Bee Caves Road, Austin, TX 78737 office. This role is not hybrid and not remote.
- Up to 20% travel, including project sites, data center locations, and periodic travel to Europe.
- Availability outside standard hours for security incidents and defined escalation windows.
- Background check and periodic re-screening consistent with company policy and client requirements.
Skills Required
- 10 or more years of experience in information technology
- At least 7 years of experience in information security
- At least 4 years leading a security function or substantial security program
- End-to-end ownership of SOC 2 examinations, including scoping, control design, evidence production, examiner management, and report issuance
- Ownership of a GRC function or program, including policy framework, risk register, control testing, exception management, and executive risk reporting
- Deep working expertise in Microsoft 365 and Entra ID security, including Conditional Access, Identity Protection, Privileged Identity Management, Data Loss Prevention, retention, and tenant configuration
- Experience securing a multi-platform SaaS estate, including identity federation and lifecycle automation
- Practical incident response leadership, including executive and external communications during live incidents
- Experience overseeing outsourced control operators and reviewing provider evidence
- Ability to write board-ready memos and present risk and investment trade-offs to non-technical audiences
- Bachelor’s degree in a related field or equivalent demonstrated experience
- CISSP, CISM, or CCISO certification
- CRISC or CISA certification
- Experience in construction, engineering, staffing, logistics, or another distributed field-heavy workforce
- Government contracting or defense-adjacent experience, including NIST SP 800-171 or CMMC
- Private-equity or venture-backed company experience with board-level security reporting
- Cross-border operations experience, including EMEA data protection obligations
- ISO 27001 implementation or certification experience
- Azure, Snowflake, or modern data platform security experience
What We Do
The fifth industrial revolution is here, and it runs on data centers and the skilled labor who build and sustain them. Behind every AI breakthrough, cloud platform, and digital connection is a data center, and behind every data center are the people who build, commission, and operate them. By bringing blue-collar jobs back to the front lines of innovation, Overwatch(SDVOSB) is proving that the future of technology depends on human expertise as much as it does on machines. Your mission-critical journey starts and scales with us. We deliver end-to-end solutions for the data center lifecycle, design, build, staffing, and sustainment, powered by a workforce you can trust.







