Fractional IT Cybersecurity Lead
JAKTOOL is seeking an experienced, hands-on Fractional IT & Cybersecurity Lead to provide senior technical leadership for our IT infrastructure, cybersecurity program, and NIST/CMMC compliance efforts. This role will work closely with company leadership and internal and/or external IT resources to establish and maintain a secure, reliable, and scalable technology environment appropriate for a growing engineering and manufacturing organization.
The Fractional Director will serve as the senior technical resource for the organization, providing oversight, guidance, and escalation support to those responsible for day-to-day IT operations and user support. A key objective of this position is to ensure JAKTOOL has the appropriate systems, processes, documentation, technical resources, and security controls necessary to operate effectively and meet applicable cybersecurity requirements.
KEY RESPONSIBILITIES
IT Strategy & Architecture
- Develop and maintain an IT and cybersecurity roadmap aligned with company growth and business objectives.
- Troubleshoot and address errors with software and hardware systems.
- Oversee IT operations, system administration, and user/technical support teams to ensure system reliability and IT compliance.
- Evaluate current systems to determine areas for enhancement and improvement.
- Assist management with IT budgeting and technology lifecycle planning.
Cybersecurity
- Own and oversee the company's cybersecurity program, including:
- Identity and access management
- Multi-factor authentication
- Privileged and administrative access
- Endpoint Protection and EDR
- Vulnerability management
- Patch management
- Email and Microsoft 365 security
- Network security
- Security logging and monitoring
- Backup and disaster recovery
- Incident response
- Security awareness training
- Vendor and third-party security
- Data protection
- Cybersecurity policies and procedures
- Regularly assess the organization's security posture and communicate significant risks and recommended actions to management.
- Lead the company's technical and operational efforts related to applicable cybersecurity requirements, including NIST SP 800-171 and CMMC.
- Maintain awareness of evolving cybersecurity threats, technologies, industry practices, and regulatory or contractual requirements, and proactively advise management of changes that may impact JAKTOOL.
IT Resource Leadership & Development
- Provide technical leadership, mentoring, and guidance to internal and/or external resources supporting the company's IT and cybersecurity functions.
- Help establish appropriate roles and responsibilities for routine administration, implementation, and user support.
- Support development of internal capabilities where appropriate and identify when specialized external expertise or resources are needed.
Vendor Management
- Evaluate and oversee technology vendors and service providers, where applicable
- Ensure that vendors have clearly defined responsibilities, service expectations and security requirements.
Backup, Disaster Recovery & Business Continuity
- Evaluate and improve the organization's ability to recover from system failures, ransomware, cyber incidents, and other disruptions.
Documentation & Reporting
- Maintain appropriate IT/security documentation
- Support the development of project plans, timelines, budgets, and resource needs to ensure effective delivery of IT services
- Provide company leadership with a concise monthly IT and cybersecurity report covering: IT Operations, Cybersecurity, NIST/CMMC Compliance, Risks
EDUCATION/EXPERIENCE
- Bachelor's degree in Information Technology, Computer Science, or related.
- At least 10 years of experience in technology leadership roles.
- Comprehensive knowledge in enterprise software systems architecture, data management, software engineering, and IT governance.
- Strong knowledge of cybersecurity practices and NIST/CMMC compliance regulations
- Strong communication, leadership, and problem-solving skills.
- Ability to manage conflicting and complex priorities.
- Experience supporting regulated, government contracting, engineering, manufacturing, or similar environments preferred.
- Previous experience in a data and analytics environment.
- Understanding of cloud-based technologies and related applications.
- An up-to-date understanding of security policies and emerging threats.
- Demonstrated ability to proactively identify risks and needs, develop practical solutions, and provide clear recommendations to leadership.