Please mention DailyRemote when applying
At Onterris, we build careers grounded in purpose, responsibility and real-world impact.
“For Planet and Progress” is our north star that guides everything we do. We believe environmental responsibility and human progress are interconnected, interwoven and international. Our scientists, engineers, field teams, consultants and professionals collaborate across disciplines and geographies, guiding industries and governments, ensuring that communities and environments thrive.
When you join us, you’re not just forging a career, you’re joining a movement. A movement for better thinking, smarter solutions and lasting impact.
Together, we will advance our way of life and protect the integrity of our environment every step of the way.
Reporting to the CISO, the Director of Cybersecurity Architecture & Engineering leads our security engineering team and is accountable for the design, implementation, and continuous improvement of our core security tooling and architecture. This role partners closely with our managed security services provider (MSSP), which delivers 24/7 SOC/NOC monitoring, and with our GRC team, which owns our compliance frameworks and assessments (including CMMC and NIST SP 800-171). This is a hands-on, player-coach role: the Director is expected to lead and develop a small, high-performing technical team while remaining technically capable of stepping into any tool domain when needed.
The compensation range for this role is $195,000 to $230,000 USD, in addition to an annual bonus (15%), commensurate with experience, skills, and geographic location.
To thrive in this role, you'll be comfortable taking ownership of the following responsibilities:
Lead, mentor, and develop a team of security engineers responsible for perimeter and endpoint security, detection and monitoring, and vulnerability management engineering
Serve as a hands-on technical backstop across the team's tool domains (firewall, EDR, SIEM, WAF, vulnerability management, and security awareness platforms), able to step in during absences or transitions
Own the strategic relationship with our managed security services provider (MSSP), including SLAs, escalation processes, contract performance, and renewal
Serve as the Tier 2/3 escalation point for security incidents raised by the MSSP, providing decision authority on containment, access, and asset-criticality judgment calls
Serve as the primary technical point of contact between the security engineering team and the GRC team, ensuring technical controls required for CMMC, NIST SP 800-171, and other applicable frameworks are designed, implemented, and maintained
Design and maintain security architecture standards for network segmentation, system hardening baselines, and identity and access boundaries, in partnership with the team that owns IAM
Develop and continuously refine the security engineering roadmap and technical standards in alignment with the evolving threat landscape and business risk tolerance
Define OKRs, metrics, and scorecards for the security engineering function and report on team health and risk posture to executive leadership
Partner with development and infrastructure teams to identify and remediate application- and infrastructure-level vulnerabilities
Own workforce planning for the team, including current team development and future headcount growth
Ensure the team maintains up-to-date documentation of tool ownership, backup coverage, and operational runbooks
Track developments in the digital business and threat environment to ensure they are reflected in security strategy and architecture
These requirements reflect the knowledge, skills and abilities that help you do your best work here.
10+ years of progressive information security experience, including hands-on tool engineering and team leadership
Bachelor's degree in Computer Science, Information Systems, or a related field
Demonstrated experience managing or technically partnering with a managed security services provider (MSSP) for SOC/NOC functions
Experience supporting CMMC and/or NIST SP 800-171 / 800-53 control implementation in partnership with a GRC or compliance function
Deep technical knowledge across core security tooling categories: next-generation firewalls, EDR, SIEM, WAF, vulnerability management platforms, and security awareness platforms
Strong understanding of network architecture, segmentation, and security concepts in large-scale environments
Demonstrated ability to build, mentor, and retain a small, high-performing technical team
Knowledge of federal cybersecurity and data privacy laws, regulations, and policies applicable to a federal contractor
Strong understanding of the cybersecurity threat lifecycle, attack vectors, and intrusion set tactics, techniques, and procedures (TTPs)
Excellent cross-functional communication skills, with the ability to translate technical risk for executive audiences
This is a remote role within the U.S. with a willingness to travel as needed
Primarily office/home-office based work; standard business hours with periodic escalation-tier on-call responsibilities outside business hours
Onterris is a leading global environmental solutions company partnering with organizations to solve complex challenges where environmental pressures, regulatory expectations and operational risks intersect. Guided by our mission to advance the way of life without compromising the integrity of our environment, we believe environmental responsibility and human progress are fundamentally connected. Our scientists, engineers, field teams and consultants apply systems thinking that unites science, data and practical expertise to deliver solutions that strengthen our clients’ resilience, mitigate risk and protect the air, water and soil that sustain communities, while uncovering responsible paths forward for planet and progress. For more information, visit www.onterris.com.
We are an equal opportunity employer and encourage applications from people of all backgrounds. We acknowledge that these experiences and perspectives help to enrich our teams and contribute to our ongoing success. We are committed to providing access and reasonable accommodation in our employment for all applicants. For US residents, click here to learn more.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Others
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“ I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!