Information Security Assurance Assistant Group Supervisor
Location
United States
Posted
36 days ago
Salary
$105K - $290K / year
Seniority
Mid Level
Job Description
Information Security Assurance Assistant Group Supervisor
Johns Hopkins Applied Physics Laboratory
Role Description Are you passionate about being on a team of highly skilled, motivated and dedicated professionals charged with protecting sensitive data while supporting the JHU/APL mission? Do you want to integrate cybersecurity and compliance within our enterprise, sector and department networks? Are you passionate about protecting our Nations sensitive information? If so, we’re looking for someone like you to join our team at APL. We are seeking an Assistant Group Supervisor (AGS) in Information Security Assurance (ISA) to partner with the Group Supervisor in leading a high performing organization of cybersecurity professionals. This role operates within a shared leadership model, where the AGS and Group Supervisor share responsibilities across the two primary pillars of the group; threat detection and compliance, ensuring seamless leadership coverage across both domains. This AGS role will focus primarily on the compliance pillar. As the ISA Assistant Group Supervisor, you will serve as a strategic and operational leader responsible for: - Shared Leadership Model - Partner closely with the Group Supervisor to align strategy, priorities, and execution across the ISA Group - Share responsibility for overall group performance, section leadership, and staff engagement - Provide full leadership coverage in the absence of the Group Supervisor and across all ISA functions as needed - Ensure seamless integration and coordination between all sections and responsibility pillars - Operations Leadership - Lead the maturation of ISA’s cybersecurity risk management and compliance program - Provide strategic oversight of the Laboratory's compliance posture with government regulations with a primary focus on CMMC and NIST SP 800-171 requirements - Collaborate with business areas and technical staff to support compliance assessments and serve as a key liaison with Certified Third-Party Assessment Organizations (C3PAOs) - Drive a risk-based, "how do we get to yes" approach that balances compliance requirements, operational needs, and practical risk management - Establish and maintain processes for risk identification, assessment, acceptance, and mitigation - Provide oversight for security assessments, audits, and continuous monitoring activities - Lead the Laboratory's CMMC assessment program, including oversight of C3PAO relationships and preparation for annual affirmations of compliance across the organization - Provide guidance on cybersecurity requirements contained in RFIs, RFPs, and contracts to ensure compliance obligations are clearly understood and appropriately addressed - Lead the buildout of posture monitoring, configuration management, and cloud compliance capabilities across ISA sections - Ensure continuous monitoring principles are operationalized and aligned with both compliance requirements and the broader threat detection and response - Lead the hiring and development of section leadership and staff as the sections mature - Organizational Leadership - Ensure Section Supervisors are effectively managing staff performance, development, and accountability within their respective security functions - Identify and develop high-potential staff and build leadership bench strength across the broader ISA Group - Ensure staff are provided meaningful opportunities for growth aligned with organizational needs - Provide expert guidance on complex risk decisions, including exception handling and compensating controls - Partner with threat detection and incident response leadership to maintain feedback loops between detection findings and control improvements - Leverage data and analytics to identify systemic risks, control gaps, and trends across the security program - Provide executive management awareness of the ongoing state of compliance across the enterprise Qualifications - Have a Bachelor's degree in Cybersecurity, Computer Science, Information Systems, a related field, or requisite experience - Have at least 7 years of experience in cybersecurity, with significant experience in governance, risk, and compliance - Have at least 5 years of experience leading and/or managing teams with demonstrated ability to exercise sound judgment and discretion - Have strong working knowledge of NIST SP 800-171 and applicable federal cybersecurity compliance frameworks - Demonstrate the ability to translate policy and regulatory requirements into actionable security practices - Have experience balancing mission needs with security and compliance requirements in complex environments - Have familiarity with cloud security architectures, identity-first security models, or modern data platforms - Have experience using data and metrics to drive risk-based decisions - Possess excellent interpersonal, written, and oral communication skills, with a proven ability to operate effectively at all levels of leadership - Are able to obtain a Secret security clearance. If selected, you will be subject to a government security clearance investigation and must meet the requirements for access to classified information. Eligibility requirements include U.S. citizenship. Requirements - Have a Master's degree in Cybersecurity, Computer Science, Information Systems, a related field, or requisite experience, including significant cybersecurity leadership experience spanning both GRC and security operations - Have experience standing up or restructuring security operations functions, including defining mission scope and building teams - Have experience leading organizational transformation or modernization initiatives within a cybersecurity program - Have experience integrating security telemetry, behavioral analytics, or automated tooling into compliance or risk management workflows - Have experience implementing quantitative or risk-based decision frameworks - Hold relevant professional certifications (e.g., CISSP, CISM, CRISC) - Have an understanding of attack methodologies used by Nation State actors and the ATT&CK matrix to effectively assess risk Benefits - Generous benefits, including a robust education assistance program - Unparalleled retirement contributions - Healthy work/life balance - Comprehensive benefits package including retirement plans, paid time off, medical, dental, vision, life insurance, short-term disability, long-term disability, flexible spending accounts, education assistance, and training and development
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Head of Security
Greenhouse SoftwareMore than an ATS, we help businesses deliver measurable hiring results so they can build, grow and hire for what's next.
• Protect against state actors and insider threats • Define and operate security across NEAR Intents and NEAR One • Establish security standards, audit strategy, and release gating • Lead ecosystem-wide incident response • Design key management architecture • Define and run continuous testing strategy • Build a lean security function • Serve as voting member of NEAR Security Committee across institutional partners • Establish security practices for AI and agent systems
• Lead small- to mid-scale, multi-discipline projects with growing independence. • Guide projects from programming through closeout—clarifying requirements, coordinating design, documenting decisions. • Cultivate strong client relationships through clear communication and reliable follow-through. • Mentor Designers and engineers through hands-on guidance, reviews, and feedback.
• The Designer II is an entry-level contributor focused on strengthening discipline knowledge, advancing modeling capability, and taking greater ownership of coordination and documentation across projects. • You’ll apply workflows, tools, and BIM standards with increasing independence while supporting engineers and project teams in delivering coordinated construction documents. • You’ll contribute to project delivery through modeling, drawing updates, coordination support, documentation, and early QA activities. • As your technical understanding grows, you’ll take on more complex coordination and documentation responsibilities across Telecom/ICT, Audiovisual, Security, Acoustics, Network, Wi-Fi, and other technology disciplines as applicable. • Working closely with engineering mentors, production staff, and project teams, you’ll help maintain model quality, support coordination efforts, and reinforce TEECOM’s BIM and documentation standards. • You’ll begin identifying coordination risks, improving model organization, and contributing to more efficient project workflows.
Principal Technical Specialist - Vehicle & Connected Cyber Security
Ford Motor CompanyAt Ford Motor Company, we believe freedom of movement drives human progress. We also believe in providing you with the freedom to define and realize your dreams. With our incredible plans for the future of mobility, we have a wide variety of opportunities for you to accelerate your career potential as you help us define tomorrow’s transportation.
Role Description Reporting to the Senior Director of Vehicle and Connected Cybersecurity, this position plays a critical role in shaping cybersecurity architecture, influencing platform decisions, mentoring technical teams, and representing the organization with regulatory authorities, business partners, and industry forums. - Technical Leadership & Strategy - Act as the principal technical authority for vehicle, embedded, and connected cybersecurity across all vehicle programs and platforms. - Define and evolve cybersecurity architectures and technical standards for ECUs, in-vehicle networks, OTA, cloud backends, mobile apps, and V2X ecosystems. - Provide expert guidance on secure-by-design principles and emerging threats affecting automotive and connected systems. - Product & Engineering Engagement - Partner with vehicle, software, and systems engineering teams to integrate cybersecurity requirements throughout the product development lifecycle. - Lead or support threat modeling, risk assessments, and security architecture reviews for vehicle platforms and connected services. - Influence design decisions to balance security, safety, performance, cost, and customer experience. - Governance, Risk & Compliance - Support compliance with automotive cybersecurity standards and regulations (e.g., ISO/SAE 21434, UNECE R155/R156, NIST). - Provide technical input for cybersecurity policies, processes, and audit readiness. - Advise leadership on cybersecurity risk posture, residual risks, and mitigation strategies. - Incident Response & Vulnerability Management - Serve as a senior technical advisor during cybersecurity incidents affecting vehicles or connected services. - Guide root cause analysis, remediation strategies, and long-term corrective actions. - Oversee vulnerability disclosure, penetration testing findings, and coordinated response activities. - Industry & External Engagement - Represent the company in industry working groups, standards bodies, and technical forums. - Engage with suppliers and technology partners to assess cybersecurity capabilities and risks. - Monitor emerging threats, technologies, and regulatory trends impacting automotive cybersecurity. - Mentorship & Knowledge Development - Mentor and develop cybersecurity engineers and specialists across the organization. - Elevate overall cybersecurity maturity through knowledge sharing, best practices, and technical reviews. Qualifications - Bachelor’s degree in Computer Science, Electrical Engineering, Cybersecurity, or a related field (Master’s preferred). - 10+ years of experience in cybersecurity, with significant focus on embedded, automotive, or IoT systems. - Deep technical expertise in areas such as embedded security, secure boot, cryptography, PKI, in-vehicle networks (CAN, LIN, FlexRay, Ethernet), OTA updates, and cloud-connected systems. - Strong understanding of automotive cybersecurity standards and regulatory frameworks. - Proven ability to influence technical decisions across multiple teams without direct authority. Preferred Qualifications - Experience working at or with an automotive OEM or Tier 1 supplier. - Familiarity with functional safety (ISO 26262) and its interaction with cybersecurity. - Hands-on experience with threat modeling methodologies and security architecture design. - Professional certifications (e.g., CISSP, CISM, CSSLP, GIAC) are a plus. Key Competencies - Strategic and systems-level thinking. - Deep technical credibility and problem-solving ability. - Strong communication skills for both technical and executive audiences. - Ability to navigate complex, matrixed organizations. - High integrity and commitment to safety and customer trust. Benefits - Immediate medical, dental, vision and prescription drug coverage. - Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more. - Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more. - Vehicle discount program for employees and family members and management leases. - Tuition assistance. - Established and active employee resource groups. - Paid time off for individual and team community service. - A generous schedule of paid holidays, including the week between Christmas and New Year’s Day. - Paid time off and the option to purchase additional vacation time.


