Director of Cybersecurity Architecture and Engineering
le002 onterris payroll
📍 Remote🌐 Remote🕐 2d ago🔗 workday
Job Description
**About Us**
============
At Onterris, we build careers grounded in purpose, responsibility and real-world impact.
“For Planet and Progress” is our north star that guides everything we do. We believe environmental responsibility and human progress are interconnected, interwoven and international. Our scientists, engineers, field teams, consultants and professionals collaborate across disciplines and geographies, guiding industries and governments, ensuring that communities and environments thrive.
When you join us, you’re not just forging a career, you’re joining a movement. A movement for better thinking, smarter solutions and lasting impact.
Together, we will advance our way of life and protect the integrity of our environment every step of the way.
**A Day in the Life**
=====================
Reporting to the CISO, the **Director of Cybersecurity Architecture & Engineering** leads our security engineering team and is accountable for the design, implementation, and continuous improvement of our core security tooling and architecture. This role partners closely with our managed security services provider (MSSP), which delivers 24/7 SOC/NOC monitoring, and with our GRC team, which owns our compliance frameworks and assessments (including CMMC and NIST SP 800-171). This is a hands-on, player-coach role: the Director is expected to lead and develop a small, high-performing technical team while remaining technically capable of stepping into any tool domain when needed.
The compensation range for this role is $195,000 to $230,000 USD, in addition to an annual bonus (15%), commensurate with experience, skills, and geographic location.
To thrive in this role, you'll be comfortable taking ownership of the following responsibilities:
* Lead, mentor, and develop a team of security engineers responsible for perimeter and endpoint security, detection and monitoring, and vulnerability management engineering
* Serve as a hands-on technical backstop across the team's tool domains (firewall, EDR, SIEM, WAF, vulnerability management, and security awareness platforms), able to step in during absences or transitions
* Own the strategic relationship with our managed security services provider (MSSP), including SLAs, escalation processes, contract performance, and renewal
* Serve as the Tier 2/3 escalation point for security incidents raised by the MSSP, providing decision authority on containment, access, and asset-criticality judgment calls
* Serve as the primary technical point of contact between the security engineering team and the GRC team, ensuring technical controls required for CMMC, NIST SP 800-171, and other applicable frameworks are designed, implemented, and maintained
* Design and maintain security architecture standards for network segmentation, system hardening baselines, and identity and access boundaries, in partnership with the team that owns IAM
* Develop and continuously refine the security engineering roadmap and technical standards in alignment with the evolving threat landscape and business risk tolerance
* Define OKRs, metrics, and scorecards for the security engineering function and report on team health and risk posture to executive leadership
* Partner with development and infrastructure teams to identify and remediate application- and infrastructure-level vulnerabilities
* Own workforce planning for the team, including current team development and future headcount growth
* Ensure the team maintains up-to-date documentation of tool ownership, backup coverage, and operational runbooks
* Track developments in the digital business and threat environment to ensure they are reflected in security strategy and architecture
**Your Expertise and Skills**
=============================
These requirements reflect the knowledge, skills and abilities that help you do your best work here.
* 10+ years of progressive information security experience, including hands-on tool engineering and team leadership
* Bachelor's degree in Computer Science, Information Systems, or a related field
* Demonstrated experience managing or technically partnering with a managed security services provider (MSSP) for SOC/NOC functions
* Experience supporting CMMC and/or NIST SP 800-171 / 800-53 control implementation in partnership with a GRC or compliance function
* Deep technical knowledge across core security tooling categories: next-generation firewalls, EDR, SIEM, WAF, vulnerability management platforms, and security awareness platforms
* Strong understanding of network architecture, segmentation, and security concepts in large-scale environments
* Demonstrated ability to build, mentor, and retain a small, high-performing technical team
* Knowledge of federal cybersecurity and data privacy laws, regulations, and policies applicable to a federal contractor
* Strong understanding of the cybersecurity threat lifecycle, attack vectors, and intrusion set tactics, techniques, and procedures (TTPs)
* Excellent cross-functional communication skills, with the ability to translate technical risk for executive audiences
Work Environment
================
* This is a remote role within the U.S. with a willingness to travel as needed
* Primarily office/home-office based work; standard business hours with periodic escalation-tier on-call responsibilities outside business hours
Onterris is a leading global environmental solutions company partnering with organizations to solve complex challenges where environmental pressures, regulatory expectations and operational risks intersect. Guided by our mission to advance the way of life without compromising the integrity of our environment, we believe environmental responsibility and human progress are fundamentally connected. Our scientists, engineers, field teams and consultants apply systems thinking that unites science, data and practical expertise to deliver solutions that strengthen our clients’ resilience, mitigate risk and protect the air, water and soil that sustain communities, while uncovering responsible paths forward for planet and progress. For more information, visit [www.onterris.com](https://nam13.safelinks.protection.outlook.com/?url=http%3A%2F%2Fwww.onterris.com%2F&data=05%7C02%7Clydiatrent%40montrose-env.com%7C4c936d7c8a994e73550908de95af2160%7C5b44302eb106453e8382f3517483ea37%7C0%7C0%7C639112776558065834%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=JSRpTkVIEit1vsjJXoAZkLIAuA5gA25dmPZ1nuVhwRE%3D&reserved=0).
We are an equal opportunity employer and encourage applications from people of all backgrounds. We acknowledge that these experiences and perspectives help to enrich our teams and contribute to our ongoing success. We are committed to providing access and reasonable accommodation in our employment for all applicants. For US residents, click [here](https://nam13.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.eeoc.gov%2Fsites%2Fdefault%2Ffiles%2F2022-10%2FEEOC_KnowYourRights_screen_reader_10_20.pdf&data=05%7C02%7Clydiatrent%40montrose-env.com%7C4c936d7c8a994e73550908de95af2160%7C5b44302eb106453e8382f3517483ea37%7C0%7C0%7C639112776558091157%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=29zIVJmHimAAJ6qCtcmREbiapWIwa4ewf00mW7TVSRg%3D&reserved=0) to learn more.