VP of Information Security - Maritime technology & defense
Pole StarAbout the role
Title: VP Information Security
Reports to: MD - Pole Star Defense
Based in: St. Petersburg, FL
Work Type: Hybrid (Ideally Commutable to St Pete but flexible for the right candidate to be remote with some travel to the office when it makes sense)
ABOUT THE COMPANY:
Pole Star Defense is a leading provider of maritime domain awareness, maritime security, and fisheries monitoring systems to the government sector. Since 1998, we have pushed the limits of innovation, mitigating growing threats to ships, supply chains, cargo, territorial waters and, most importantly, safety of lives at sea and beyond. Today, we continue to develop and implement pioneering intelligence technologies to protect customer vessels, people, maritime domain, and reputation.
POSITION DESCRIPTION:
Pole Star VP of Information Security will play an integral part in the organization’s success by managing, maintaining, and developing Pole Star's security strategy, programs and operational security requirements. With a remit for all Pole Star systems globally, this position must ensure to adopt, execute, maintain and publish security standards, processes, and procedures company-wide to ensure corporate posture is in line with the overall strategy and framework. You will be a hands-on leader with a history of working with a highly technical, rapidly growing organization that prioritizes cybersecurity strategies and goals to ensure Pole Star is secure at all times. The ideal candidate will be able to build strong partnerships with key stakeholders, act as a strategic thought leader, provide guidance, strategy, leadership, and direction on Information Security related topics. The success of this position will be attributed to a leader capable of understanding our environment and driving resources and actions necessary to mature our practices.
RESPONSIBILITIES:
Strategic Leadership
- Develop and execute the company’s information security strategy aligned with business goals, customer requirements (e.g., USCG, DoD, financial institutions), and regulatory obligations (e.g., NIST, CMMC, IMO).
- Serve as the principal advisor to the executive team on cyber risk, resilience, and emerging threats across the maritime domain.
Risk Management & Compliance
- Establish and oversee a risk-based governance framework covering companywide IT, cloud systems (e.g., AWS), and maritime-focused platforms (e.g., AIS, LRIT, NAIS).
- Ensure compliance with government and industry information security standards (e.g.,NIST 800-171/53, CMMC, ISO 27001, GDPR, IMO 2021 Maritime Cyber Risk Management guidelines).
Operational Security Oversight
- Lead all aspects of security operations, including threat detection, incident response, vulnerability management, and endpoint protection.
- Oversee internal audits, penetration tests, and red/blue team exercises.
Secure Architecture & DevSecOps
- Collaborate with engineering teams to design and maintain secure system architectures, emphasizing Zero Trust principles and containerized environments (e.g. Kubernetes, Istio)
- Drive implementation of DevSecOps practices in the software development lifecycle, including static/dynamic code analysis, CI/CD security gates, and supply chain security.
Customer & Mission Support
- Support customer security accreditation processes (e.g. ATOs for cloud-hosted solutions).
- Represent the company in security-related meetings with customers, auditors, and third parties.
Team Development & Leadership
- Build, lead, and mentor a high-performing security team, including analysts, engineers, and compliance personnel
- Foster a culture of security awareness across the organization through training and ongoing education
Vendor & Tool Management
- Evaluate, procure, and manage security tools and services (e.g. SIEM, IAM, endpoint protection)
- Maintain security incident SLAs with cloud vendors, MSPs, or SOC partners
Crisis & Incident Response
- Lead response to major security incidents, coordinating across internal stakeholders, customers, and government authorities.
- Own and regularly update the company’s incident response and disaster recovery plans
Stakeholder Reporting
- Provide regular briefings and reports to the executive team on cyber security posture, metrics, and strategic investments
- Contribute to proposal writing and security sections for RFPs and contract responses
Requirements
Technical Expertise
- Information Security Frameworks: Deep knowledge of FedRAMP, NIST, CMMC, ISO 27001.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s