Director of Cybersecurity Compliance

Post Date

Jul 20, 2026

Location

Austin,
Texas

ZIP/Postal Code

78741
US
Sep 24, 2026 Insight Global

Job Type

Perm

Category

Security Engineering

Req #

DGO-ac19159c-3502-4d75-bcfa-2b0ad5e1a8cd

Pay Rate

$150k - $200k (estimate)

Job Description

Insight Global is looking for Manager or Director of Cybersecurity Compliance to work on site in Austin, TX and support the strategy and introduction of products based on unique and highly differentiated capabilities of a preeminent foundry for semiconductor systems and defense electronics companies. Their mission is to advance the state-of-the-art in critical semiconductor domains such as advanced packaging, and in the process to help restore U.S. leadership in semiconductor manufacturing. They are developing cutting-edge semiconductor manufacturing technology that will define future roadmaps of semiconductor devices including logic, memory, 3D packaged devices, including thermal management, etc. The Director of Cybersecurity Compliance will lead the strategic development, implementation, and continuous improvement of the organization's cybersecurity compliance program supporting Controlled Unclassified Information (CUI), regulated manufacturing environments, and federal contract requirements. This individual will oversee the governance, risk, and compliance (GRC) framework for semiconductor manufacturing operations, research laboratories, engineering systems, operational technology (OT), and enterprise infrastructures.

The ideal candidate possesses deep expertise in CMMC 2.0, NIST SP 800-171, NIST 800-53, RMF, and semiconductor manufacturing cybersecurity requirements. The Director will partner with executive leadership, engineering, manufacturing, facilities, IT, and government stakeholders to ensure compliance while enabling business growth, intellectual property protection, and operational resilience.

Responsibilities:
Responsible for ensuring information systems follow government and their internal regulations while meeting program demands and operating in an accredited state.
Assist in daily IT governance, risk management, and compliance function.
Providing oversight of compliance assurance, for the daily administration of information security measures in compliance with the NIST SP 800-171, CMMC level 2, and other relevant system security requirements to include those under the Risk Management Framework (RMF).
Responsible for assisting in ensuring that controlled unclassified information systems meet the Risk Management Framework goals required by their government clients
Responsible for drafting detailed reports of compliance and self-inspections outcomes, for upper management review.
Other related functions as assigned.

Key Responsibilities:

Cybersecurity Compliance Leadership:
Establish and execute enterprise-wide cybersecurity compliance strategies supporting CUI environments and federal contracts.
Serve as the senior compliance authority for CMMC, NIST SP 800-171, NIST SP 800-53, NIST Cybersecurity Framework (CSF), DFARS, and related regulatory requirements.
Lead organizational readiness efforts for CMMC Level 2 and future certification assessments.
Develop governance frameworks, policies, standards, and procedures supporting secure handling of CUI and other sensitive information assets.
Brief executive leadership and government stakeholders on cybersecurity risks, compliance posture, remediation activities, and audit readiness.

CUI & Government Program Security:
Maintain compliance across all CUI information systems, enclaves, cloud environments, and engineering platforms.
Oversee CUI boundary definition, system scoping, data-flow mapping, and asset inventories.
Ensure secure storage, transmission, retention, and destruction of CUI in accordance with federal requirements.
Collaborate with program teams supporting DoD, DARPA, and other government initiatives.
Guide implementation of security controls and POA&M management activities.

Semiconductor Manufacturing & Operational Technology Security:
Provide cybersecurity governance for semiconductor fabrication, packaging, testing, and R&D environments.
Partner with manufacturing engineering, facilities, automation, and MES teams to implement secure OT practices.
Establish security requirements for:
Manufacturing Execution Systems (MES)
Equipment automation platforms
SCADA and industrial control systems
Cleanroom operational infrastructure
Supply chain and vendor connectivity
HPC and engineering compute environments
Develop cybersecurity standards for semiconductor tools, vendor integrations, and production networks.

Risk Management & Audit Oversight:
Lead enterprise risk assessments and control evaluations.
Direct internal and external cybersecurity audits.
Manage remediation programs, vulnerability assessments, and control validation activities.
Track security metrics, compliance KPIs, and regulatory obligations.
Oversee third-party risk management and supplier cybersecurity reviews.

Security Operations & Continuous Monitoring:
Partner with Security Operations to establish continuous monitoring programs.
Oversee compliance-related vulnerability management, configuration management, and endpoint security initiatives.
Ensure audit logs, monitoring tools, and evidence repositories support compliance objectives.
Guide incident response activities involving regulated systems and CUI assets.

Team Leadership:
Build and lead a high-performing cybersecurity compliance and GRC organization.
Mentor cybersecurity professionals, ISSOs, auditors, and compliance analysts.
Manage budgets, compliance roadmaps, staffing plans, and external consulting engagements.
Foster a culture of cybersecurity awareness and accountability throughout manufacturing operations.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Required Skills & Experience

Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering, Information Systems, or a related discipline.
10+ years of cybersecurity experience with at least:
5+ years leading cybersecurity compliance or GRC programs.
3+ years supporting regulated or government-contracted environments.
Demonstrated expertise implementing:
CMMC 2.0
NIST SP 800-171
NIST 800-53
NIST Cybersecurity Framework
Risk Management Framework (RMF)
Experience managing audits, assessments, and accreditation activities.
Experience developing and managing Plans of Action and Milestones (POA&Ms).
Strong understanding of identity management, vulnerability management, incident response, and secure architecture principles.
Experience presenting technical and compliance risks to executive leadership.
Semiconductor or Defense Manufacturing background

Certifications (One or More Preferred):
CISSP
CISM
CISA
CRISC
CGRC (formerly CAP)
Security+
CCSP
Certified CMMC Professional (CCP)
Certified CMMC Assessor (CCA)

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.