1

Director Of Cybersecurity Jobs in Spring, TX (NOW HIRING)

This position will report directly to the Director of Sales, Americas at PAS. Achieve annual sales ... cyber security or enterprise software and/or related consulting services Minimum of 3 years of ...

This position will report directly to the Director of Sales, Americas at PAS. • Achieve annual ... cyber security or enterprise software and/or related consulting services • Minimum of 3 years of ...

Qualys is a leading provider of cloud-based cybersecurity and compliance solutions, helping ... The Director of Strategic Partners will be responsible for expanding and accelerating Qualys ...

Cybersecurity GRC Manager (Hybrid)

Houston, TX · On-site

$106K - $143K/yr

... with direct exposure to executive leadership. Reporting to the KES CISO, this role will help ... Enjoy the flexibility of a hybrid work schedule (3 days in office) while working from one of our ...

The Information Security organization will continue to own cybersecurity governance, policy, threat ... The Director will define and advance Eaton's network strategy through architecture standards ...

... of life. W&T Offshore is seeking an experienced OT Cybersecurity Specialist. This direct-hire ... opportunity is ideal for professionals looking to join a well-established upstream oil and gas ...

Position Summary The Director of Information Security is responsible for leading Weatherford's global cybersecurity strategy, governance, operations, identity management, and risk management program ...

Showing results 41-60

Director Of Cybersecurity information

What does a director of cybersecurity do?

A Director of Cybersecurity is responsible for overseeing an organization's information security strategy and ensuring the protection of digital assets from cyber threats. They lead a team of security professionals, develop policies and procedures, and coordinate responses to security incidents. Additionally, they work with other departments to ensure compliance with regulations and keep the organization updated on the latest security technologies and best practices. Their role is critical in minimizing risk and maintaining the integrity of sensitive data.

What are the key skills and qualifications needed to thrive as a director of cybersecurity?

To thrive as a Director of Cybersecurity, you need deep expertise in information security frameworks, risk management, and incident response, often supported by a bachelor’s or master’s degree in cybersecurity or a related field. Familiarity with tools like SIEM platforms, vulnerability scanners, and advanced certifications such as CISSP or CISM are typically required. Strong leadership, strategic thinking, and effective communication are crucial soft skills to lead teams and collaborate with stakeholders. These skills ensure robust protection of organizational assets, regulatory compliance, and rapid response to evolving cyber threats.

What are some of the main challenges a director of cybersecurity faces when leading a security team in a large organization?

A Director of Cybersecurity in a large organization often encounters challenges such as aligning security strategies with business objectives, managing a diverse team of security professionals, and staying ahead of rapidly evolving threats. Balancing resources between proactive risk management and immediate incident response can be demanding, as is fostering a culture of security awareness across departments. Additionally, Directors must regularly communicate complex technical issues to executive leadership and ensure compliance with industry regulations, all while adapting to organizational changes and technological advancements.

What is the difference between Director Of Cybersecurity vs Security Manager?

AspectDirector Of CybersecuritySecurity Manager
CertificationsCISSP, CISM, CISACISSP, Security+
Work EnvironmentStrategic, executive-level, policy developmentOperational, team management, day-to-day security tasks
Employer & Industry UsageLarge corporations, government agencies, tech firmsOrganizations of all sizes, including SMBs and enterprises
Search & Comparison IntentUnderstanding leadership roles, strategic responsibilitiesOperational security tasks, team oversight

The Director Of Cybersecurity focuses on strategic planning, policy development, and overseeing cybersecurity programs at an organizational level. In contrast, the Security Manager handles daily security operations, manages security teams, and implements security measures. Both roles require relevant certifications like CISSP but differ in scope and responsibilities, with the director playing a more strategic role and the manager focusing on operational execution.

What are popular job titles related to Director Of Cybersecurity jobs in Spring, TX?

For Director Of Cybersecurity jobs in Spring, TX, the most frequently searched job titles are:

What job categories do people searching Director Of Cybersecurity jobs in Spring, TX look for?

The top searched job categories for Director Of Cybersecurity jobs in Spring, TX are:

What cities near Spring, TX are hiring for Director Of Cybersecurity jobs?

Cities near Spring, TX with the most Director Of Cybersecurity job openings:

Infographic showing various Director Of Cybersecurity job openings in Spring, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 74% In-person, and 26% Remote job distribution.

Senior Director, Cybersecurity & Enterprise Infrastructure

Rimkus

Houston, TX • On-site

Full-time

This job post has expired 3 days ago. Applications are no longer accepted.


Job description

Join Rimkus and unlock your potential with endless opportunities for growth, learning, and making a difference!
Rimkus is a worldwide leader in Engineering and Technical Consulting. Rimkus experts specialize in building envelope, engineering, forensic consulting, dispute resolution, construction management services, and solutions built for the environment.
NOW IS THE TIME to join this growing and stable company!
Position Summary
The Senior Director, Cybersecurity & Enterprise Infrastructure is the accountable leader for the security, resilience, and technical foundation of Rimkus's technology estate. Reporting to the Chief Transformation Officer, this leader owns enterprise cybersecurity, cloud and hybrid infrastructure, endpoint and identity platforms, the enterprise data platform, the technology integration of acquired businesses, and the compliance and audit program that evidences all of it.
This is a leader-of-leaders role. It directs a multidisciplinary organization of infrastructure engineers, data engineers, systems and security staff, and the IT systems director function - setting architecture and standards, building bench strength, and converting security findings into completed, evidenced remediation.
Rimkus operates in a client environment where confidentiality, privileged information, and defensible data handling are core to the business. As a private-equity-backed, acquisitive professional services firm, the company is subject to sponsor-directed security assessments, client due diligence, and formal audit expectations - while simultaneously acquiring and integrating businesses on a recurring basis. Cybersecurity is therefore not a subordinate function of this role - it is its center of gravity, and every acquisition either strengthens or dilutes it.
Because the position reports into the Transformation organization, it carries an explicit mandate to standardize, consolidate, and modernize rather than merely operate.
Scope & Organizational Context
Security ownership: This role is the company's accountable cybersecurity leader - including security strategy, security operations, incident response, and the formal compliance and audit program. It also owns the technology compliance control library and evidence readiness.
Technical breadth: Microsoft Entra ID and M365 E5 identity estate, Azure and hybrid infrastructure, network and remote access, endpoint and device management, backup/DR, the enterprise data and analytics platform, and enterprise applications infrastructure.
Organizational mandate: Rebuild depth and continuity following the departure of long-tenured technical staff. A significant portion of the first year is eliminating key-person dependency through documentation, cross-training, hiring, and automation - so that no critical system depends on a single individual's undocumented knowledge.
Transformation mandate: Reporting into the Transformation organization, this role is expected to consolidate and standardize a technology estate that has grown through acquisition - retiring redundant platforms, unifying identity and endpoint management, and establishing a repeatable integration playbook rather than treating each deal as a one-off project.
Inorganic growth: Rimkus grows through acquisition. This role owns the technology and security workstream across the full deal lifecycle - pre-LOI and confirmatory diligence, Day 1 readiness, post-close integration, and platform rationalization - and is accountable for ensuring acquired environments are brought up to Rimkus control standards on a defined timeline.
Stakeholders: Executive leadership, the Transformation organization, Corporate Development, the private-equity sponsor's technology operating team, Legal and Risk, Compliance, Finance, HR, business-line and acquired-entity leadership, clients responding to security due diligence, and external assessment, audit, and managed-service partners.
Key Responsibilities
Cybersecurity Strategy & Leadership
• Own enterprise cybersecurity strategy, target-state architecture, and a funded multi-year roadmap aligned to business risk and growth.
• Serve as the accountable security leader: maintain the security policy set, the enterprise risk register with quantified business impact, and documented risk-acceptance decisions.
• Establish and chair a security governance forum; report posture, risk trend, and remediation progress to executive leadership, the Board, and the private-equity sponsor on a defined cadence.
• Lead and coordinate independent security assessments, penetration tests, and sponsor-directed reviews; own the remediation plan, evidence package, and measurable score improvement window over window.
• Own client-facing security due diligence, security questionnaires, contractual security terms, and cyber insurance underwriting responses.
• Build and operate a security awareness, phishing simulation, and role-based training program with measured behavioral outcomes.
• Set the security investment strategy: extract full value from entitlements already licensed before adding tooling; justify new spend with quantified risk reduction.
Identity & Access Management
Identity is the primary security perimeter for this environment. This is the single most consequential technical accountability in the role.
• Own Microsoft Entra ID architecture, hybrid identity, and the M365 tenant identity security model end to end.
• Design, govern, and change-control Conditional Access. Replace accumulated app-by-app policy sprawl with a documented, tenant-wide baseline (all users x all cloud applications) plus a governed exception register with owners and expiry dates.
• Drive universal multifactor authentication to full coverage and lead adoption of phishing-resistant methods (FIDO2/passkeys, Windows Hello for Business, certificate-based authentication); retire weak factors.
• Eliminate legacy authentication protocols enterprise-wide and migrate remaining dependencies - scanners, SMTP relays, line-of-business integrations - to OAuth 2.0 and modern authentication.
• Implement and operate Privileged Identity Management: just-in-time elevation, approval workflow, time-bound roles, session justification, and recurring access reviews. Eliminate standing administrative privilege.
• Govern trusted network locations and remote-access trust assumptions. Ensure privileged and administrative access paths - management APIs, PowerShell, device-code flow, service-to-service - are explicitly controlled rather than implicitly trusted by network position.
• Own service principal, enterprise application, and OAuth consent governance: least-privilege API permissions, admin-consent workflow, ownership attestation, and credential/secret rotation.
• Establish identity lifecycle automation (joiner / mover / leaver), entitlement and access reviews, guest and external-collaboration governance, and the elimination of shared and generic accounts.
• Harden credential standards: minimum length, breach-password correlation, rotation policy, elimination of blanket expiry exemptions, and group-managed service accounts for service identities.
Security Operations, Threat Detection & Incident Response
• Own SIEM and security analytics (Microsoft Sentinel): data-source onboarding and completeness, retention and archive tiering sufficient for forensic reconstruction, detection engineering, tuning, and ingestion cost management.
• Validate detection coverage against MITRE ATT&CK and close gaps across initial access, credential access, persistence, privilege escalation, lateral movement, and exfiltration.
• Own the Microsoft Defender XDR stack - Defender for Identity, Endpoint, Cloud Apps/CASB, and Office 365 - with defined triage SLAs by severity and a managed, non-aging alert queue.
• Establish continuous (24x7) monitoring coverage, in-house or through a managed detection and response partner, with defined escalation paths, on-call rotation, and enforced performance SLAs.
• Author, socialize, and test the incident response plan and playbooks - credential exposure, business email compromise, ransomware, insider data theft, service-account and privileged-identity compromise, third-party breach - with named roles and decision authority.
• Run tabletop and purple-team exercises at least annually; drive after-action findings to closure.
• Lead investigation and containment during live incidents: forensic triage, evidence preservation and chain of custody, and coordination with Legal, HR, Communications, outside counsel, insurers, and law enforcement as required.
• Own identity threat detection and response - including credential-exposure response, risky-identity remediation to documented closure within SLA, service-account credential attack detection, and token-theft defense.
• Own vulnerability and patch management, external attack surface monitoring, secure configuration baselines, and remediation SLAs by severity.
• Own the insider risk and data loss prevention program: data classification, sensitivity labeling, and monitoring and enforcement against removable-media exfiltration, mass download, and sharing to personal accounts - with specific controls for PHI, PCI, PII, and litigation-sensitive material.
Cloud & Enterprise Infrastructure
• Direct Azure and hybrid cloud strategy: landing zone and subscription governance, network topology, identity and RBAC model, Key Vault and secrets management, Azure Policy, Defender for Cloud, and Well-Architected reviews.
• Own infrastructure-as-code and configuration management; move change execution from manual console work to automated, peer-reviewed, auditable pipelines.
• Oversee network, firewall, SD-WAN, DNS and email security, and remote access across all offices; modernize implicitly trusted VPN architecture toward zero-trust network access and segmentation.
• Own data center, virtualization, storage, and the remaining on-premises footprint, including cloud migration and legacy platform exit plans.
• Own backup, immutable and air-gapped recovery, disaster recovery, and business continuity; define, test, and evidence RTO and RPO for every critical system with documented exercises at least annually.
• Own the Microsoft 365 estate - Exchange Online, SharePoint/OneDrive, Teams - and Copilot/AI readiness including the data-governance prerequisites.
• Own ITSM discipline: change, incident, and problem management, capacity planning, availability and service-delivery SLAs, and published operational metrics.
Endpoint, Device Trust & Modern Workplace
• Own endpoint management (Intune, Autopilot, and co-managed configuration manager estate); consolidate legacy management paths and retire duplicate tooling.
• Raise device compliance above target and extend compliant-device Conditional Access from selected applications to all users and all workloads.
• Enforce full-disk encryption, EDR coverage, application control, and patch compliance to defined, reported thresholds across Windows, macOS, iOS, and Android.
• Own the end-user computing experience, service desk performance, and the quality of onboarding and offboarding execution.
Data Engineering & Analytics Platform
• Lead the data engineering function: pipeline and integration architecture, orchestration, warehouse/lakehouse platform, and business intelligence delivery.
• Establish data governance - ownership, classification, lineage, retention, and quality standards - in partnership with Legal, Compliance, and business lines.
• Secure the data platform: least-privilege and row/column-level access, managed identities and secrets management, encryption in transit and at rest, and monitoring of analytics service accounts and service principals.
• Partner with business leadership to deliver reporting and analytics products that improve client delivery, utilization, and operational decision-making.
• Govern AI and machine learning adoption, including acceptable-use standards, data-protection controls, and review of AI-connected data surfaces.
Compliance, Audit & Risk Governance
• Own the technology compliance program mapped to NIST Cybersecurity Framework and NIST 800-53, CIS Controls v8, ISO 27001, and applicable HIPAA, PCI DSS, and privacy obligations.
• Maintain the control library, control owners, testing calendar, and evidence repository; operate continuous control monitoring so the organization is audit-ready at any time rather than at audit time.
• Lead internal and external audits and assessments, SOC 2 readiness where applicable, and client and legal security due diligence.
• Ensure audit and activity log retention, completeness, and immutability are sufficient for forensic reconstruction, legal hold, and eDiscovery obligations; own the Purview compliance capability.
• Own third-party and vendor risk assessment, security terms in contracts, and ongoing supplier monitoring.
• Ensure records retention, data residency, and cross-border data handling meet client, contractual, and regulatory requirements across the international footprint.
• Extend the compliance and control program to acquired entities on a defined timeline, and represent the combined environment in client, sponsor, and audit inquiries.
Mergers, Acquisitions & Technology Integration
Rimkus grows inorganically. This role owns the technology and security workstream across the full deal lifecycle and is expected to make integration a repeatable capability rather than a recurring fire drill.
Diligence: Lead technology and cybersecurity due diligence on acquisition targets - identity and tenant architecture, security posture and control maturity, prior incidents and breach history, infrastructure and technical debt, application and data estate, licensing and contract assignability, key-person and vendor dependencies, and cyber insurance history.
Risk quantification: Translate diligence findings into quantified integration cost, one-time and run-rate synergy estimates, remediation timelines, and identified deal risks - presented in a form Corporate