Information Security Compliance Manager
Listed on 2026-04-28
-
Security
Cybersecurity
Overview
Re:
Build Manufacturing is a growing family of industrial and engineering businesses combining enabling technologies, operational superiority, and strategic M&A to build America’s next generation industrial company. At Re:
Build we deploy deep expertise in engineering, operations management, and technology to supercharge the performance of our member companies. We leverage deep professional expertise and a candid, principled operating culture to drive differentiated outcomes. Ours is a fast-paced environment where individuals can stretch and be challenged to pursue their fullest potential.
Re:
Build was founded to pioneer a profitable model for the revitalization of US manufacturing. We’ve assembled a powerful set of complimentary capabilities and lines of business that enable us to pursue a wide range of end markets. Our acquired businesses are grounded in build-to-print and by-the-hour engineering and design services, and we’re leveraging their combined expertise to migrate to increasingly sophisticated program development and production, as well as the generation of our own products.
Our unique set of capabilities lend themselves to highly complex systems and products, and we offer customers a range of services including product and systems design, automation, fabrication, assembly, and large volume contract manufacturing. Our customers span a wide array of industries including aerospace, defense, mobility, healthcare, pharma, biotech, clean tech, chemicals, energy, lifestyle, food production, and industrial equipment.
This role serves as the primary technical authority on the Cybersecurity Maturity Model Certification (CMMC) framework, leading Re:
Build’s cross-functional compliance efforts, including maintenance of our existing Level 2 certification and expansion to include new business units, including CUI scoping, internal gap and mock assessments, control implementation, training, documentation, and certification assessment. This role is instrumental to Re:
Build’s critical initiative to sustain and expand CMMC certification, ensuring that all NIST SP 800-171 technical, administrative, and physical controls are properly implemented, validated, and documented across the enterprise, ensure program alignment with EAR, ITAR, and other customer requirements, and support expansion to include NIST SP 800-171r3 and 800-172
- Lead detailed gap analyses across technical, administrative, and physical controls to identify deficiencies and required remediation at both certified entities and entities pursuing CMMC certification.
- Translate CMMC practices into clear, actionable technical requirements for IT, Engineering, Manufacturing, Security, HR, and other impacted teams.
- Guide and validate the implementation of required controls, ensuring alignment with CMMC and NIST SP 800-171 assessment criteria.
- Support CUI scoping activities including asset inventory validation, boundary definition, and data flow mapping.
- Develop and implement compliance policies, procedures, and standards for cybersecurity, and assist other functions and business units in developing their own.
- Coordinate with IT, Legal, HR, and business units to ensure compliance requirements are understood and completed.
- Lead the creation, refinement, and maintenance of compliance documentation including SSPs, POA&Ms, Con Mon materials, policies, procedures, and evidence artifacts.
- Establish and implement structured evidence collection and artifact management processes to ensure audit readiness.
- Perform internal readiness assessments, mock audits, and control testing to maintain confidence in Re:
Build’s compliance posture and prepare for C3
PAO assessment. - Collaborate with assessors to support readiness and certification activities.
- Conduct risk assessments and provide recommendations to mitigate cybersecurity and compliance risks.
- Assess and report progress toward compliance objectives, including readiness status and control maturity.
- Advise leadership on compliance risks, technical challenges, and factors that may impact certification timelines or sustainment.
- Generate reports for cybersecurity leadership and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).