Vice President, Cyber Security & GRC at Overwatch Mission Critical | Austin, TX, US | Rezi

Vice President, Cyber Security & GRC at Overwatch Mission Critical

Vice President, Cyber Security & GRC

Overwatch Mission Critical · Austin, TX, US

Yesterday

Vice President, Cyber Security & GRC

Overwatch Mission Critical · Austin, TX, US

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Vice President, Cyber Security & GRC role.

Rezi rewrites your resume against Overwatch Mission Critical's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Vice President, Cyber Security & GRC posting at Overwatch Mission Critical — free, in seconds.

About the Role

This is a build role, not a caretaker role. You will be the first executive dedicated to security and to Technology Governance, Risk, and Compliance (GRC) at Overwatch, owning the security program, the GRC program with oversight authority, and the security architecture and governance of our SaaS platform estate. In your first year, you will deliver a SOC 2 Type II examination, bring security capability in-house from a managed service partner, and establish identity, data classification, and third-party risk management. You will report to the SVP, Technology, sit on the executive reporting cadence, and chair a cross-functional security and compliance steering committee, with the authority to inspect, issue findings, require remediation, and escalate.

Responsibilities

  • Develop and execute enterprise cybersecurity strategy, roadmap, and architecture.
  • Manage identity as the primary security control plane, including single sign-on, conditional access, and privileged access.
  • Oversee detection and response capability, vulnerability management, endpoint hardening, and encryption enforcement.
  • Lead incident response planning, exercising, and execution.
  • Develop and deliver security awareness and role-based training.
  • Manage the end-to-end policy framework, including drafting, approval, attestation, exceptions, and review.
  • Maintain the enterprise technology risk register, including scoring methodology, treatment plans, and escalation.
  • Oversee the control framework and testing calendar, mapped across SOC 2 Trust Services Criteria and NIST CSF.
  • Deliver SOC 2 Type 1 and Type 2 examinations, manage examiner relationships, and handle findings.
  • Maintain a register of security and privacy obligations from contracts, attestations, and applicable law.
  • Provide quarterly reporting to the executive team and annual reporting to the board.
  • Manage security architecture and acquisition control across the SaaS estate.
  • Oversee data classification and handling across collaboration platforms, data warehouse, and reporting layers.
  • Develop and manage a tiered third-party risk program and oversee managed service partners.
  • Govern enterprise AI tooling, including permitted use, data boundaries, and approval workflows.

Requirements

  • Ten or more years in information technology, with at least seven in information security.
  • At least four years leading a security function or a substantial security program.
  • End-to-end ownership of a SOC 2 examination & ISO Certification.
  • Ownership of a GRC function or program, including policy framework, risk register, control testing, exception management, and executive-level risk reporting.
  • Deep working expertise in Microsoft 365 and Entra ID security.
  • Demonstrated experience securing a multi-platform SaaS estate, including identity federation and lifecycle automation.
  • Practical incident response leadership, including executive and outside party communication during live events.
  • Experience overseeing outsourced control operators, reviewing provider evidence and testing it.
  • Ability to write a board-ready memo and present risk and investment trade-offs to a non-technical audience.
  • A bachelor’s degree in a related field, or equivalent demonstrated experience.
  • Availability outside standard hours for security incidents and defined escalation windows.
  • Pass a background check and periodic re-screening.

Skills

  • Microsoft 365 security
  • Entra ID security
  • Conditional access
  • Identity protection
  • Privileged identity management
  • Data loss prevention
  • Retention
  • Tenant configuration
  • Identity federation
  • Lifecycle automation
  • Incident response
  • SOC 2 examination
  • ISO Certification
  • GRC program management
  • Policy framework development
  • Risk register maintenance
  • Control testing
  • Exception management
  • Executive risk reporting
  • Board-ready memo writing
  • Risk and investment trade-off presentation
  • CISSP
  • CISM
  • CCISO
  • CRISC
  • CISA
  • NIST SP 800-171
  • CMMC
  • ISO 27001 implementation
  • Azure security
  • Snowflake security
  • Modern data platform security

Location

  • Bee Caves Road, Austin, TX 78737

Work Type

  • Full-time
  • On-site

Experience Level

  • Ten or more years in information technology
  • At least seven years in information security
  • At least four years leading a security function or program

Education Level

  • Bachelor’s degree in a related field, or equivalent demonstrated experience

Benefits

  • Competitive salary
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • 401(k) retirement plan
  • Paid time off
  • Relocation assistance

About the Company

  • Overwatch is a service-disabled Veteran-owned small business (SDVOB) certified through the National Veterans Business Development Council (NVBDC).
  • Delivers construction professional services, talent acquisition, and general contractor solutions within the mission-critical infrastructure industry.
  • Focuses on the construction and management of state-of-the-art data centers.
  • Deploys talent needed to bring complex infrastructure to life.

Equal Opportunity

  • Committed to creating a diverse work environment.
  • Proud to be an Equal Opportunity Employer.
  • Considers candidates regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.