Skip to main content
R

Director, IT & Cybersecurity

Revamp Engineering, Inc
5 days ago
Full-time
Remote friendly (Oakland, United States)
United States
$160,000 - $220,000 USD yearly
Indeed

Role Summary Revamp is seeking a Director of IT & Cybersecurity to serve as the firm's senior information security leader and technical authority for IT architecture. You will own the information security program and the firm's identity, endpoint, networking, backup, and cloud environment, and you'll be accountable for technology risk across the business. You will report to the VP of Finance & Operations and have a direct line to the internal governance committee on security and technology risk. You will also work transparently with clients, their auditors, and outside providers so the business can make balanced, informed decisions. The scope of the role and its team will grow with the firm. Our engineers design utility-scale solar, storage, and power systems projects that advance the energy transition. You will make sure our engineers and partners have secure, reliable access to the tools they need, and that clients can trust how we protect their data. Duties & Responsibilities Core Technical & Functional Responsibilities Serve as the firm's technical authority for information security and IT architecture across on-premises and cloud environments, including secure design of internal tools and automations; set the standards others are held to and approve architecture, control, and change decisions against them. Define the firm's AI security posture, including the technical controls that protect firm and client data and security diligence on AI vendors. Administer and harden the security environment, including identity, endpoint management and protection, networking, and backup and recovery. Assess the program against the NIST Cybersecurity Framework (CSF) 2.0, define Revamp's target profile and risk tolerance, and own the maturity roadmap, executing the highest-priority remediation directly. Build, document, and test disaster recovery, business continuity, and incident response plans, including approved recovery time and recovery point objectives (RTO/RPO), verified restores, and tabletop exercises; serve as the hands-on incident lead. Draft and implement core security policies and standards, including access control, data classification and handling, and acceptable use; approve exceptions where business need and risk warrant them; and run security awareness training. Quality, Standards & Compliance Commission independent security assessments, audits, and penetration tests; prioritize findings and approve remediation closure. Ensure the program meets industry, jurisdictional, and client-specific requirements, and represent Revamp in client security reviews and third-party diligence. Collaboration & Communication Advise firm leadership and the internal governance committee on technology risk with costed options and a recommendation, and report program metrics on a regular cadence. Keep staff informed, in plain language, about the firm's technology strategy, roadmap, and changes that affect how they work. Program, Strategy & Innovation Own the two-to-three-year IT strategic plan and IT and security budget inputs, including a 6–12-month capacity forecast for storage, compute, licensing, and hardware. Lead strategic technology procurement and manage IT and security vendors, including scoping, selection, commercial terms in partnership with Finance, and accountability to contracted service levels. Direct outside IT providers day to day, develop the resourcing plan for in-house IT and security capability, and hire and lead that team as it grows. Own staff technology experience, including onboarding and offboarding, equipment, and end-user support. Maintain authoritative documentation and an inventory of systems, licenses, vendor contracts, and administrative control, and remove single points of dependency on any one person or provider. Additional Responsibilities Perform essential duties including meeting deliverables and deadlines. Perform additional related duties as assigned or directed. Knowledge, Skills, & Abilities Requi…

View the full posting and apply