Security Risk & Operational Resilience Lead
Construction ResourcesAbout the role
<p></p> <p>Security Risk & Operational Resilience Lead</p> <p>Role Overview</p> <p>The Security Risk & Operational Resilience Lead is responsible for designing, operationalizing, and continuously improving Construction Resources’ enterprise security governance, risk, and incident readiness programs.</p> <p>This role serves as the program owner for GRC, incident readiness, and control effectiveness, ensuring that security policies, controls, and response processes are not only defined—but measurable, tested, and consistently executed across the organization.</p> <p>The position operates as a bridge between cybersecurity engineering, IT operations, and executive leadership, aligning stakeholders while maintaining clear separation from direct ownership of security tools or infrastructure. The ideal candidate is a strategic, hands-on leader who can translate security requirements into operational execution and measurable outcomes across a complex, growing enterprise.</p> <p> </p> <p>Key Responsibilities</p> <p>Governance, Risk & Compliance (GRC) Program</p> <p>• Develop, implement, and continuously mature Construction Resources’ enterprise GRC program, including risk management, control frameworks, compliance monitoring, and reporting.</p> <p>• Maintain alignment with industry standards and regulatory requirements, including NIST CSF, ISO 27001, SOC 2, and PCI-DSS.</p> <p>• Lead enterprise risk assessments and manage a central risk register, including prioritization, ownership assignment, and remediation tracking.</p> <p>• Build and deliver security metrics, dashboards, and executive reporting to support informed decision-making at the leadership and Board level.</p> <p> </p> <p>Security Program Execution & Control Effectiveness</p> <p>• Define and implement a control validation and assurance program to verify security controls are operating effectively across identity, endpoint, network, and data domains.</p> <p>• Establish standardized methods for collecting control evidence, validation results, and remediation tracking, leveraging enterprise tools such as Jira Service Management (JSM).</p> <p>• Partner with cybersecurity engineering and IT operations to ensure controls are embedded into operational workflows, not treated as standalone compliance activities.</p> <p>• Drive measurable improvement in control effectiveness, coverage, and time-to-remediation metrics across the organization.</p> <p>• Lead enterprise cybersecurity auditing activities across frameworks and control areas (e.g., PCI-DSS, identity/access, network, and data security), ensuring audit readiness, evidence validation, gap identification, and timely remediation.</p> <p> </p>
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s