OVERWATCH Logo

OVERWATCH

Vice President, Cyber Security & GRC

Posted 6 Days Ago
Be an Early Applicant
In-Office
Austin, TX, USA
Expert/Leader
In-Office
Austin, TX, USA
Expert/Leader
Leads the company’s cybersecurity and GRC functions end to end, including security strategy, identity, incident response, risk management, policy, control testing, SOC 2 examinations, third-party risk, SaaS governance, and AI tooling oversight. The role builds the security function, transitions capabilities in-house, reports risks to executives and the board, and chairs a cross-functional security steering committee.
The summary above was generated by AI
About Overwatch Mission Critical
Overwatch is a service-disabled Veteran-owned small business (SDVOB) certified through the National Veterans Business Development Council (NVBDC), delivering construction professional services, talent acquisition, and general contractor solutions within the mission-critical infrastructure industry. Our focus is the construction and management of state-of-the-art data centers, executed with the precision and reliability this industry demands. From high-end engineers to seasoned field professionals, we deploy the talent needed to bring complex infrastructure to life. At Overwatch, it's more than a job — it's purpose.

The Opportunity: 

Roll your sleeves up, this is a build role, not a caretaker role. Reporting to the SVP of Technology, you will be the first executive dedicated to security and to Technology Governance, Risk, and Compliance at Overwatch, and you will own the function end to end: the security program, the GRC program with real oversight authority, and the security architecture and governance of our SaaS platform estate. 

In your first year you will deliver a SOC 2 Type II examination, bring security capability in-house from a managed service partner on a deliberate timeline, and put identity, data classification, and third-party risk on a footing that survives a doubling of the business. You will report to the SVP, Technology, sit on the executive reporting cadence, and chair a cross-functional security and compliance steering committee. You will have the authority to inspect, issue findings, require remediation, and escalate. 

If you want a large inherited team and a mature control set, this is a different challenge. If you want to design the function, choose the tooling, and be the person the executive team and our clients rely on when the security question gets hard, read on. 

What you will own:
 
Security 
  • Enterprise cybersecurity strategy, roadmap, and architecture across a hybrid, heavily field-deployed environment. 
  • Identity as the primary security control plane: single sign-on, conditional access, privileged access, joiner-mover-leaver automation, and access recertification. 
  • Detection and response capability, vulnerability management, endpoint hardening, and encryption enforcement. 
  • Incident response: planning, exercising, and serving as incident commander when it counts. 
  • Security awareness and role-based training measured on outcomes, not completion rates. 

Governance, Risk, and Compliance 
  • The policy framework end to end — drafting, executive approval, attestation, exceptions, and annual review. 
  • The enterprise technology risk register: scoring methodology, treatment plans with named owners, and escalation of overdue items. 
  • The control framework and testing calendar, mapped across SOC 2 Trust Services Criteria, NIST CSF, and additional frameworks as adopted. 
  • SOC 2 Type 1 and Type 2 delivery, examiner relationship, evidence library, and management responses to findings. 
  • A register of security and privacy obligations arising from client contracts, insurance attestations, and applicable law across US and EMEA operations. 
  • Quarterly reporting to the executive team and annual reporting to the board. 
 
Platforms and third-party governance 
  • Security architecture and acquisition control across the SaaS estate, including a written standard for how platforms are evaluated, integrated, monitored, and retired. 
  • Data classification and handling across collaboration platforms, the data warehouse, and reporting layers. 
  • SaaS rationalization and licensing strategy in partnership with Business Platforms & Intelligence. 
  • A tiered third-party risk program, oversight of our managed service partner, and the security terms in technology agreements. 
  • Governance of enterprise AI tooling — permitted use, data boundaries, approval workflow, and monitoring. 

What success looks like in year one: 

  • First 90 days. A documented view of our posture, control gaps, and platform estate. A live risk register with named owners. The steering committee chartered and running. Collaboration with IT Leadership for SOC II Type ! Certification early Q1 FY27 
  • Six months. SOC 2 Type 1 delivered on target. A control testing calendar in operation. Identity lifecycle automation resolved. A costed plan for the managed service transition. 
  • Twelve months. Type 2 underway. Single sign-on and conditional access at target coverage. Third-party risk program running. A standard client security response package in use. Quarterly GRC reporting accepted by the executive team. 

What we are looking for:
 
  • Ten or more years in information technology, with at least seven in information security and at least four leading a security function or a substantial security program. 
  • End-to-end ownership of a SOC 2 examination & ISO Certification— scoping, control design, evidence production, examiner management, and report issuance. Not coordination of someone else’s audit. 
  • Ownership of a GRC function or program: policy framework, risk register, control testing, exception management, and executive-level risk reporting. 
  • Deep working expertise in Microsoft 365 and Entra ID security — conditional access, identity protection, privileged identity management, data loss prevention, retention, and tenant configuration. 
  • Demonstrated experience securing a multi-platform SaaS estate, including identity federation and lifecycle automation. 
  • Practical incident response leadership, including communicating with executives and outside parties during a live event. 
  • Experience overseeing outsourced control operators — reviewing provider evidence and testing it rather than accepting assertions. 
  • The ability to write a board-ready memo and present risk and investment trade-offs to a non-technical audience. 
  • A bachelor’s degree in a related field, or equivalent demonstrated experience. 

Also valued 
  • CISSP, CISM, or CCISO. CRISC or CISA is specifically relevant to the GRC mandate. 
  • Experience in construction, engineering, staffing, logistics, or another distributed, field-heavy workforce. 
  • Government-contracting or defense-adjacent exposure, including NIST SP 800-171 or CMMC. 
  • Private-equity or venture-backed company experience with board-level security reporting. 
  • Cross-border operations, including EMEA data protection obligations. 
  • ISO 27001 implementation or certification experience. 
  • Azure, Snowflake, or modern data platform security experience. 
 
Working here 
  • Full-time on-site at our Bee Caves Road, Austin, TX 78737 office. This role is not hybrid and not remote. 
  • Up to 20% travel, including project sites, data center locations, and periodic travel to Europe. 
  • Availability outside standard hours for security incidents and defined escalation windows. 
  • Background check and periodic re-screening consistent with company policy and client requirements. 

Benefits:
Overwatch offers a competitive salary and benefits package, including health insurance, dental insurance, vision insurance, life insurance, 401(k) retirement plan, paid time off, and relocation assistance available.

OVERWATCH is committed to creating a diverse work environment and is proud to be an Equal Opportunity Employer. OVERWATCH considers candidates regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status.
HQ

OVERWATCH Austin, Texas, USA Office

Austin, TX, United States, 78738

Similar Jobs

3 Hours Ago
Hybrid
Internship
Internship
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Build and prototype AI-powered solutions, intelligent agents, automated workflows, data models, and Power BI dashboards for People Analytics. Extract and transform HR data using tools such as Power Query, Dataflows, Snowflake, and SQL. Apply Python, prompt engineering, and generative AI tools to improve HR insights, data access, decision-making, and employee experience while collaborating across HR and analytics teams.
Top Skills: Azure Ai FoundryChatgptClaudeCopilot StudioDataflowsGeminiGlean Work AiLarge Language ModelsMicrosoft CopilotPower BIPower QueryPythonSnowflakeSnowflake CortexSnowflake CoworkSQL
3 Hours Ago
In-Office
Expert/Leader
Expert/Leader
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Leads global commercial strategy for Ericsson Enterprise Wireless Solutions, overseeing pricing, subscription economics, portfolio profitability, value propositions, business-model innovation, and commercial governance. Partners with executive, product, sales, channel, finance, supply chain, and operations leaders to improve recurring revenue, win rates, margins, and customer value. Builds a global commercial management organization, develops scalable tools and processes, drives competitive intelligence, supports strategic deal shaping, and establishes enterprise standards for negotiation and price management.
Top Skills: Cloud ComputingSaaSTelecommunications
3 Hours Ago
In-Office
Expert/Leader
Expert/Leader
Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Leads Ericsson’s Americas Automation Enablement function, defining AI, automation, data, and reporting roadmaps. Oversees a geographically dispersed team, prioritizes AI initiatives, scales proofs of concept into secure production services, and establishes governance for data quality, documentation, monitoring, responsible AI, and lifecycle management. Partners with global teams, suppliers, and matrixed stakeholders to improve network operations, profitability, tools strategy, and organizational transformation.
Top Skills: AIAi/MlAutomationDashboardsData ManagementNatural-Language InsightsReporting PlatformsWorkflow Automation

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account