Director of Cybersecurity & Compliance
SPINEN, Inc. Macon, Georgia, United States
IT Services and IT Consulting · 11-50 employees
About the role
The Director of Cybersecurity & Compliance is responsible for defining and enforcing security standards to reduce risk and improve compliance across client environments. This role involves conducting security assessments, driving remediation efforts, and serving as a trusted advisor to clients regarding security strategy.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 3-5 years of experience in cybersecurity, compliance, or IT operations. Strong knowledge of security frameworks like CIS, SOC 2, and NIST is required, along with excellent communication and analytical skills.
Full description
Director of Cybersecurity & Compliance
Job Summary:
The Director of Cybersecurity & Compliance is responsible for reducing security risk and improving compliance outcomes across Spinen and client environments by defining, enforcing, and sustaining strong security standards. This role focuses on identifying security gaps, driving remediation efforts, strengthening client security postures, and helping organizations align with industry-recognized compliance frameworks.
The Director serves as Spinen's security subject matter expert, working closely with Pods, clients, vendors, and internal teams to ensure security controls are implemented consistently, risks are proactively addressed, and compliance objectives are achieved. This is a hands-on, client-facing role with authority to lead security initiatives, influence decision-making, and drive measurable security improvements without management responsibilities.
Supervisory Duties:
· None
Core Responsibilities:
Security Standards & Baseline Enforcement
- Define, document, and continually improve Spinen's baseline security standards
- Support the implementation and ongoing maintenance of CIS Controls across client environments
- Design and maintain layered security and compliance standards for clients with advanced regulatory requirements
- Research, evaluate, and recommend security technologies, tools, and best practices
- Partner with Pod leadership to standardize security solutions and processes
- Ensure security standards are implemented consistently and efficiently across environments
Client Environment Oversight & Remediation
- Conduct proactive security assessments to identify risks, vulnerabilities, and control gaps
- Develop actionable remediation plans and work with Pods and clients to execute them
- Engage directly with clients to explain security risks, required controls, and recommended improvements
- Serve as a trusted advisor to client leadership teams regarding security strategy and risk reduction
- Track security posture improvements and help clients achieve measurable security outcomes
Compliance Program Support
- Assist clients with compliance and security framework alignment, including CIS Controls, SOC 2, CMMC, NIST, and similar standards
- Support the development, maintenance, and improvement of security policies, procedures, and documentation
- Identify compliance gaps and coordinate remediation efforts with internal and client stakeholders
- Maintain awareness of emerging compliance requirements and industry best practices
- Assist with client audits, assessments, and security reviews as needed
Security Operations & Incident Response
- Participate in security incident investigations and response activities
- Coordinate with Pods, vendors, and clients during security events
- Assist in identifying root causes and implementing corrective actions
- Contribute to the continuous improvement of incident response processes and security monitoring capabilities
- Help ensure lessons learned are documented and incorporated into future security practices
Client Communication & Security Consulting
- Present security findings, recommendations, and risk assessments to technical and non-technical audiences
- Build trusted relationships with clients through proactive communication and consultative guidance
- Translate technical security concepts into practical business discussions
- Support client strategic planning initiatives related to cybersecurity and compliance
- Partner with Solution Managers and Pod leadership to align security recommendations with business objectives
Continuous Improvement & Innovation
- Identify opportunities to automate repetitive security and compliance activities
- Evaluate new technologies and approaches that improve security outcomes
- Contribute to the development and enhancement of Spinen's security service offerings
- Promote security awareness and best practices throughout the organization
- Participate in ongoing professional development and certification efforts
Required Skills & Abilities
- Strong understanding of cybersecurity principles, risk management, and security operations
- Working knowledge of security frameworks and controls such as CIS Controls, SOC 2, CMMC, NIST, or similar standards
- Ability to identify risks and develop practical remediation strategies
- Strong communication skills with the ability to explain technical concepts to non-technical audiences
- Experience building relationships and influencing outcomes without direct authority
- Strong analytical, organizational, and problem-solving skills
- Ability to manage multiple priorities across multiple client environments
- Commitment to continuous learning and professional growth
- Proficiency with Microsoft Office and common business technologies
Education & Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent experience
- 3-5 years of experience in cybersecurity, compliance, IT operations, or managed services
- MSP, MSSP, consulting, or multi-client environment experience strongly preferred
- Experience participating in security assessments, remediation efforts, incident response, or compliance initiatives
- Industry certifications such as CISSP, CISM, CEH, Security+, SC-200, SC-100, or equivalent certifications are a plus
Physical Requirements
- Prolonged periods of sitting and working on a computer
- Ability to lift up to 50 lbs. as needed
- May be required to work outside normal business hours during security incidents or client emergencies
Similar roles
-
Security Engineer (Security Automation Engineer)- Mid
Connected Logistics Springfield, Virginia, United States · $100K–$110K/yr
-
Cloud Security Engineer - Mid
Connected Logistics Springfield, Virginia, United States · $120K–$130K/yr
-
Senior Cloud Security Engineer
Connected Logistics Springfield, Virginia, United States · $120K–$130K/yr
-
Cybersecurity SME
Diaconia LLC Bath Township, Ohio, United States · $90K–$125K/yr
-
Director of Cybersecurity Operations
Baylor University Waco, Texas, United States
-
Director, Cybersecurity
Asset Living Dallas, Texas, United States