- Salary
- $246k – $393k
- Location
- 900 Innovators Way, Simi Valley, CA, United States of America · Germantown, MD
- Type
- Full-time
- Department
- IT
- Seniority
- VP
- Experience
- 15+ years
- Education
- Master
- Clearance
- Required
- Source
- Workday
Description
Worker Type
Regular
Job Description
Summary
The “Vice President of Cybersecurity & Chief Information Security Officer (CISO)” is a senior executive responsible for establishing, implementing, and maintaining AV’s enterprise vision, strategy, and cybersecurity program to ensure the confidentiality, integrity, and availability of the organization’s information assets and technology resources.
The CISO provides strategic leadership for the organization’s cybersecurity function in support of both classified and unclassified defense programs. This role is responsible for ensuring compliance with Department of Defense (DoD) cybersecurity requirements, advancing the organization’s Cybersecurity Maturity Model Certification (CMMC) posture, implementing and maintaining alignment with National Institute of Standards and Technology (NIST) frameworks, and ensuring adherence to applicable federal laws, regulations, and contractual obligations. Additionally, the CISO will develop and execute cybersecurity strategies that support AV’s accelerated growth, acquisition, and integration initiatives.
Reporting to the Chief Information Officer (CIO), the CISO serves as the principal advisor to executive leadership and the Board of Directors on all matters related to cybersecurity, information security governance, cyber risk management, and the protection of Controlled Unclassified Information (CUI), classified national security information, and other sensitive organizational assets.
Position Responsibilities
Strategic Leadership & Governance
- Develop and implement comprehensive cybersecurity strategy aligned with business objectives and national security requirements
- Establish and maintain information security governance framework, policies, standards, and procedures
- Serve as primary liaison with government customers, Defense Contract Management Agency (DCMA), Defense Counterintelligence and Security Agency (DCSA), and other regulatory bodies
- Provide regular briefings to the Board of Directors, CEO, and executive leadership on security posture, risks, and initiatives
- Lead enterprise risk management activities related to cybersecurity and information protection
- Oversee cybersecurity budget planning, resource allocation, and investment prioritization
Compliance & Regulatory Management
- Ensure organizational compliance with NIST SP 800-171, CMMC 2.0, DFARS, ITAR, and other applicable regulations
- Lead and maintain Cybersecurity Maturity Model Certification (CMMC) readiness and certification efforts
- Manage System Security Plan (SSP) development, Plan of Action & Milestones (POA&M), and continuous monitoring programs
- Oversee NIST 800-53 control implementation for classified systems and Risk Management Framework (RMF) authorization processes
- Coordinate with Defense Industrial Base (DIB) Cybersecurity Program requirements
- Develop and execute insider threat detection and prevention programs
- Lead international cybersecurity compliance strategy, ensuring adherence to UK MoD DEFCON 658 / Def Stan 05-138, Cyber Essentials Plus, UK/EU GDPR, and applicable international data privacy and sovereignty regulations.
- Establish cross-border data transfer controls and security architectures supporting NATO, AUKUS, and Five Eyes allied defense initiatives.
Technical Security Operations
- Direct enterprise security operations including Security Operations Center (SOC), incident response, and threat intelligence
- Oversee implementation and management of security technologies including SIEM, EDR, DLP, IAM, and encryption solutions
- Ensure secure system development lifecycle practices and DevSecOps integration
- Manage vulnerability management, penetration testing, and security assessment programs
- Direct cloud security architecture and controls for classified and unclassified environments
- Oversee identity and access management programs including privileged access management
- Oversee cybersecurity governance for Special Access Programs (SAP/SAR), SCIF network operations, COMSEC, and TEMPEST compliance in coordination with Government Security/OPSEC teams.
Incident Response & Business Continuity
- Lead cyber incident response planning, coordination, and execution
- Ensure timely reporting of cyber incidents to DoD, FBI, and other required agencies per DFARS 252.204-7012
- Coordinate with legal, CIO along with executive teams during security incidents
- Oversee business continuity and disaster recovery planning for critical security systems
- Manage relationships with external incident response partners and forensic specialists
Third-Party & Supply Chain Security
- Establish and enforce third-party risk management and vendor security assessment programs
- Oversee supply chain security controls and acquisition security requirements
- Ensure subcontractor cybersecurity compliance flows down through contracts
- Manage security requirements for cloud service providers and managed service providers
Organization Leadership
- Build, lead, and mentor high-performing information security and cybersecurity teams
- Establish organizational structure spanning cybersecurity operations, governance/risk/compliance, security architecture, and program security
- Foster culture of security awareness and accountability throughout the organization
- Implement and maintain security education, training, and awareness programs for all personnel
- Develop succession planning and talent development strategies for security organization
Basic Qualifications (Required Skills & Experience)
Education
- Bachelor’s degree in computer science, Information Security, Cybersecurity, Engineering, or related technical field required
- Master's degree in related fields is strongly preferred
Experience
- Minimum 15 years of progressive experience in information security, with at least 10 years in senior leadership roles
- Extensive experience in defense contracting environment with classified programs
- Proven track record implementing and maintaining DoD cybersecurity compliance programs (NIST 800-171, CMMC, RMF)
- Demonstrated experience managing enterprise-wide security programs in complex, multi-site organizations
- Experience leading organizations through CMMC certification and FedRAMP authorization processes
- Strong background in both physical and cyber security operations
Security Clearance
- Active Top Secret/SCI security clearance required
- Eligibility for Special Access Programs (SAP) preferred
Certifications (Required)
- CISSP (Certified Information Systems Security Professional)
- One or more of the following: CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), CRISC (Certified in Risk and Information Systems Control)
Certifications (Preferred)
- GSLC (GIAC Security Leadership Certification)
- CCSP (Certified Cloud Security Professional)
- CGEIT (Certified in the Governance of Enterprise IT)
- CAP (Certified Authorization Professional)
- CMMC-AB Certified Professional or Provisional Assessor
Technical Knowledge & Skills
- Deep understanding of NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171
- Expertise in CMMC 2.0 requirements and assessment processes
- Knowledge of DoD Cloud Computing Security Requirements Guide (SRG) and FedRAMP
- Understanding of DFARS, FAR, ITAR, EAR, and related defense contracting regulations
- Proficiency with security technologies: SIEM, EDR/XDR, IAM, PAM, DLP, CASB, firewall/IDS/IPS
- Understanding of secure software development practices and DevSecOps methodologies
- Knowledge of zero trust architecture principles and implementation
- Familiarity with classified network operations and cross-domain solutions
Leadership Competencies
- Strategic thinking with ability to translate security requirements into business enablement
- Executive presence with proven ability to communicate complex security concepts to technical and non-technical audiences
- Strong risk management and decision-making capabilities under pressure
- Proven ability to influence and build consensus across organizational boundaries
- Experience managing and developing diverse, geographically distributed teams
- Budget management and financial acumen
Physical Demands
- Ability to work in an office environment (Constant)
- Required to sit and stand for long periods; talk, hear, and use hands and fingers to operate a computer and telephone keyboard (Frequent)
Working Conditions
- Position may require up to 25% travel to company facilities, customer sites, and industry events
- Occasional after-hours availability for incident response and maintenance windows
- Work in both office environments and Sensitive Compartmented Information Facilities (SCIFs)
- May require access to classified information and restricted areas
Special Requirements
- U.S. Citizenship Required.
Clearance Level
The salary range for this role is:
$245,500 - $393,000AeroVironment considers several factors when extending an offer, including but not limited to, the location, the role and associated responsibilities, a candidate’s work experience, education/training, and key skills.
ITAR Requirement:
This position requires access to information that is subject to compliance with the International Traffic Arms Regulations (“ITAR”) and/or the Export Administration Regulations (“EAR”). In order to comply with the requirements of the ITAR and/or the EAR, applicants must qualify as a U.S. person under the ITAR and the EAR, or a person to be approved for an export license by the governing agency whose technology comes under its jurisdiction. Please understand that any job offer that requires approval of an export license will be conditional on AeroVironment’s determination that it will be able to obtain an export license in a time frame consistent with AeroVironment’s business requirements. A “U.S. person” according to the ITAR definition is a U.S. citizen, U.S. lawful permanent resident (green card holder), or protected individual such as a refugee or asylee. See 22 CFR § 120.15. Some positions will require current U.S. Citizenship due to contract requirements.
Benefits: AV offers an excellent benefits package including medical, dental vision, 401K with company matching, a 9/80 work schedule and a paid holiday shutdown. For more information about our company benefit offerings please visit: http://www.avinc.com/myavbenefits.
We also encourage you to review our company website at http://www.avinc.com to learn more about us.
Principals only need apply. NO agencies please.
About AV:
AV isn’t for everyone. We hire the curious, the relentless, the mission-obsessed. The best of the best.
We don’t just build defense technology—we redefine what’s possible. As the premier autonomous systems company in the U.S., AV delivers breakthrough capabilities across air, land, sea, space, and cyber. From AI-powered drones and loitering munitions to integrated autonomy and space resilience, our technologies shape the future of warfare and protect those who serve.
Founded by legendary innovator Dr. Paul MacCready, AV has spent over 50 years pushing the boundaries of what unmanned systems can do. Our heritage includes seven platforms in the Smithsonian—but we’re not building history, we’re building what’s next.
If you're ready to build technology that matters—with speed, scale, and purpose—there’s no better place to do it than AV.
We are proud to be an EEO/AA Equal Opportunity Employer, including disability/veterans. AeroVironment, Inc. is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Qualified applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, protected veteran status, genetic data, sexual orientation, gender identity or other legally protected status.
ITAR
U.S. Citizenship required