Compliance Lead/SOC/ISO/hybrid onsite in Herndon, VA
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
A global leader in energy storage optimization is seeking a Cybersecurity & Compliance Lead to join its team in Herndon, VA (hybrid, 2-3 days onsite). This is a full-time leadership opportunity focused on building and maturing cybersecurity, compliance, and risk management capabilities across a rapidly growing, mission-driven technology organization.
This is a highly visible, hands-on role for a security professional who enjoys building programs rather than simply maintaining them. The successful candidate will own and evolve the organization's cybersecurity and compliance strategy, drive ISO 27001 and SOC 2 readiness efforts, strengthen vendor risk management processes, and guide incident response and risk assessment activities. With direct influence on business and security decisions, this position offers the opportunity to make a meaningful impact on critical energy infrastructure while helping accelerate the transition toward a more sustainable future.
Required Skills & Experience- 7+ years of experience in cybersecurity, information security, governance, risk, and compliance (GRC), or related domains
- Experience leading or managing cybersecurity and compliance programs in a hands-on capacity
- Strong knowledge of ISO 27001, SOC 2, and security control frameworks
- Experience conducting risk assessments and developing mitigation strategies
- Vendor risk management and third-party security assessment experience
- Expertise creating, implementing, and maintaining information security policies and standards
- Experience developing and executing incident response processes and plans
- Knowledge of security monitoring, control validation, and continuous compliance practices
- Understanding of cloud security principles and modern IT infrastructure
- Strong stakeholder management and communication skills
- Ability to balance security requirements with operational and business objectives
- Experience working in lean or fast-paced environments where ownership and execution are critical
- Experience in energy, utilities, critical infrastructure, industrial technology, or highly regulated environments
- CISSP, CISM, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or similar certifications
- Familiarity with NIST CSF, NIST 800-53, or related security frameworks
- Experience supporting customer security reviews and audit requests
- Knowledge of OT/ICS security principles
- Experience with vulnerability management and security tooling oversight
- Background supporting SaaS platforms or cloud-native environments
- Strong program-building and process-improvement experience
Tech Breakdown
- 35% Security Governance, Risk & Compliance (ISO 27001, SOC 2, Controls)
- 25% Risk Management & Vendor Security Assessments
- 15% Incident Response & Security Operations Oversight
- 15% Policy Development & Security Program Maturation
- 10% Strategic Security Planning & Stakeholder Engagement
- 30% Lead and enhance cybersecurity and compliance initiatives
- 20% Conduct risk assessments and remediation planning
- 15% Manage third-party/vendor risk reviews
- 15% Develop, maintain, and improve security policies and procedures
- 10% Coordinate incident response readiness and security monitoring activities
- 10% Partner with internal stakeholders to drive security improvements and compliance objectives
- High-impact leadership role with significant ownership and visibility
- Opportunity to build and shape a cybersecurity program from the ground up
- Direct involvement in protecting technology that supports renewable energy and critical infrastructure
- Comprehensive benefits package including medical, dental, and vision coverage
- 401(k) with company match
- Paid vacation and holidays
- Professional development and certification support
- Opportunity to work alongside industry experts helping drive the future of sustainable energy and technology
#LI-CK2
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).