Back to search
Matrix Pointe Software Linkedin · Posted 19d ago

Director of Information Security and Compliance

Cleveland

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Location: Cleveland, Ohio (hybrid)


Company Description Matrix Pointe Software is a rapidly growing entrepreneurial Cleveland-based software company that provides enterprise software tailored for federal, state and local government agencies across the justice system, such as prosecutor’s offices, law enforcement agencies, administrative bodies, and civil law departments. Committed to delivering innovative technology solutions, we focus on connecting justice partners, streamlining workflows, and enhancing outcomes through our robust platforms.


Role Description This is a full-time, hybrid role based in Westlake, OH for a Director of Information Security and Compliance. The individual in this role will lead our organization’s information security structure and ensure adherence to regulatory standards. As a hands-on player-coach, this role involves developing comprehensive security frameworks, managing risk assessments, overseeing compliance programs, and guiding a talented team dedicated to safeguarding our IT infrastructure. The Director owns Matrix’s overall security strategy, regulatory compliance posture, and executive-level risk reporting.


Matrix serves prosecutors, courts, law enforcement, and state agencies in highly regulated environments. The Director is the senior leader accountable for ensuring Matrix continues to meet – and exceed – the security expectations of those clients, the auditors who certify our systems, and the standards (CJIS, NIST 800-53, SOC 2, GovRAMP, FedRAMP, and emerging state and federal requirements) that govern them.

To be successful, you should bring both strategic vision and hands-on technical depth. You should be comfortable presenting risk and roadmap to executive leadership one day and executing a control implementation, audit response, or incident response the next. You should have excellent judgment, strong written and verbal communication, and a willingness to build a function from the ground up.


This position reports to the Chairman and Chief Software Architect. The Director is expected to build and lead a dedicated security team as the function matures.


Responsibilities

  • Develop, own, and execute Matrix’s information security strategy and multi-year roadmap.
  • Lead Matrix’s SOC 2 audit program end-to-end, including scoping, evidence collection, auditor coordination, control testing, and remediation.
  • Manage Matrix’s NIST 800-53 program and maintain ongoing alignment with the applicable baseline and any client-driven control overlays.
  • Maintain Matrix’s CJIS Security Policy compliance and serve as the senior point of contact for state and federal CJI compliance matters.
  • Define, measure, and report security KPIs, risk posture, and program progress to executive leadership on a recurring cadence.
  • Maintain Matrix’s security policy library, including access control, incident response, vulnerability management, vendor risk, change management, and data handling.
  • Lead vulnerability management, penetration testing, threat modeling, and security review for both cloud and on-premise customer deployments.
  • Own incident response planning, tabletop exercises, live response coordination, post-incident review, and required notifications.


Qualifications

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related discipline, or equivalent experience
  • CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or equivalent certification required
  • Six or more years of cybersecurity and/or information security experience required
  • Hands-on experience implementing and maintaining NIST 800-53 controls; familiarity with the moderate baseline
  • Demonstrated ownership of SOC 2 (Type II) audits, including audit coordination, evidence management, and remediation
  • Proven experience developing system security plans, managing enterprise cybersecurity programs within complex IT environments, and securing AWS cloud environments and Windows-based application stacks
  • Experience implementing programs using GRC platforms such as Vanta or Drata
  • Track record of building, maturing, or significantly upgrading a security function.
  • Comfortable operating as a player-coach: setting strategy at the executive level while still performing hands-on technical work
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search