Quick Summary
Role Summary Revamp is seeking a Director of IT & Cybersecurity to serve as the firm's senior information security leader and technical authority for IT architecture.
Revamp is seeking a Director of IT & Cybersecurity to serve as the firm's senior information security leader and technical authority for IT architecture. You will own the information security program and the firm's identity, endpoint, networking, backup, and cloud environment, and you'll be accountable for technology risk across the business.
You will report to the VP of Finance & Operations and have a direct line to the internal governance committee on security and technology risk. You will also work transparently with clients, their auditors, and outside providers so the business can make balanced, informed decisions. The scope of the role and its team will grow with the firm.
Our engineers design utility-scale solar, storage, and power systems projects that advance the energy transition. You will make sure our engineers and partners have secure, reliable access to the tools they need, and that clients can trust how we protect their data.
Responsibilities
~1 min read- →Serve as the firm's technical authority for information security and IT architecture across on-premises and cloud environments, including secure design of internal tools and automations; set the standards others are held to and approve architecture, control, and change decisions against them.
- →Define the firm's AI security posture, including the technical controls that protect firm and client data and security diligence on AI vendors.
- →Administer and harden the security environment, including identity, endpoint management and protection, networking, and backup and recovery.
- →Assess the program against the NIST Cybersecurity Framework (CSF) 2.0, define Revamp's target profile and risk tolerance, and own the maturity roadmap, executing the highest-priority remediation directly.
- →Build, document, and test disaster recovery, business continuity, and incident response plans, including approved recovery time and recovery point objectives (RTO/RPO), verified restores, and tabletop exercises; serve as the hands-on incident lead.
- →Draft and implement core security policies and standards, including access control, data classification and handling, and acceptable use; approve exceptions where business need and risk warrant them; and run security awareness training.
- →Perform essential duties including meeting deliverables and deadlines.
- →Perform additional related duties as assigned or directed.
- Commission independent security assessments, audits, and penetration tests; prioritize findings and approve remediation closure.
- Ensure the program meets industry, jurisdictional, and client-specific requirements, and represent Revamp in client security reviews and third-party diligence.
- Advise firm leadership and the internal governance committee on technology risk with costed options and a recommendation, and report program metrics on a regular cadence.
- Keep staff informed, in plain language, about the firm's technology strategy, roadmap, and changes that affect how they work.
- Own the two-to-three-year IT strategic plan and IT and security budget inputs, including a 6–12-month capacity forecast for storage, compute, licensing, and hardware.
- Lead strategic technology procurement and manage IT and security vendors, including scoping, selection, commercial terms in partnership with Finance, and accountability to contracted service levels.
- Direct outside IT providers day to day, develop the resourcing plan for in-house IT and security capability, and hire and lead that team as it grows.
- Own staff technology experience, including onboarding and offboarding, equipment, and end-user support.
- Maintain authoritative documentation and an inventory of systems, licenses, vendor contracts, and administrative control, and remove single points of dependency on any one person or provider.
Requirements
~2 min read- Bachelor's degree in information security, computer science, information systems, engineering, or a similar field, or equivalent applicable work experience.
- 10 or more years of professional experience in information technology, with recent years concentrated in information security, security architecture, or infrastructure leadership.
- Exceptional written and verbal communication, with a demonstrated ability to explain technical strategy and risk in plain language to executives and non-technical staff and to translate business context into program priorities.
- Current, hands-on depth in on-premises and cloud architecture, including the ability to configure and troubleshoot identity, endpoint, networking, and backup systems personally.
- Direct experience owning or building an information security program, including policy, control design, independent assessment, and executive reporting, and leading the response to real security incidents.
- Working command of NIST CSF 2.0 and the judgment to apply a framework proportionately to a growing firm's size and risk profile.
- Experience directing managed service providers as the client and evaluating the technical quality of their work.
- Comfort working as a player-coach in a growing organization: doing the work first, then building and leading the team that does it.
- Ability to work on-site at the Oakland office 3–5 days per week.
- Professional certifications such as CISSP, CISM, or equivalent.
- Experience building an IT or security function from an early stage, or scaling one through rapid growth, including hiring and developing technical staff.
- Familiarity with the NIST AI Risk Management Framework or ISO/IEC 42001.
- Experience administering an enterprise identity and productivity platform, including licensing and tenant ownership at the organizational level.
- Experience supporting environments with substantial engineering compute requirements, such as advanced CAD, modeling tools, geospatial data, or similar.
- Experience supporting client security reviews or third-party diligence in a professional services or project-based business.
What We Offer
~1 min readFounded in 2016, Revamp is the premier employee-owned engineering design firm dedicated to advancing large-scale renewable energy projects. Our team is united by a shared commitment to accelerating the global energy transition and creating a workplace where talented people can make a tangible impact in the fight against climate change.
As employee-owners, we take pride in building a culture of collaboration, innovation, and accountability where every individual's contribution drives both company success and personal growth. Revamp engineers have supported the design of more than 10% of the utility-scale solar generation capacity in the US since 2020, contributing directly to the renewable energy transformation.
So much more than just an engineering firm; we are a diverse, international team of artists, singers, dancers, pastry chefs, outdoor enthusiasts, animal lovers, travelers and problem-solvers who bring curiosity and creativity to everything we do. For more information, visit www.revamp-eng.com.
Employment with Revamp Engineering Inc. may be subject to background checks that are permitted by applicable law and relevant to the position. Any such checks will be conducted in compliance with all legal requirements, including providing notice, obtaining consent where required, and allowing candidates to access and correct personal information as permitted by law.
Revamp Engineering Inc. is an equal opportunity employer committed to creating an inclusive workplace. We provide equal employment opportunities without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, veteran status, or any other status protected by applicable law. We value diversity and encourage candidates from all backgrounds to apply. Revamp Engineering Inc. is committed to providing reasonable accommodations for candidates with disabilities. If you require an accommodation during the application or interview process, please contact us.
Automated Hiring Technology Notice.
Revamp uses an automated application-review feature within BreezyHR, our applicant tracking system, to help our recruiting team organize and prioritize applications. It compares the information you submit (your resume or CV and your answers to application questions) against criteria our recruiting team sets for the role. The feature does not reject or advance candidates; all employment decisions are made by our recruiting team and hiring managers. A summary of BreezyHR's most recent independent bias audit of this feature is available at https://trust.warden-ai.com/breezy-hr/applicant-insight/nyc. Revamp retains application information indefinitely to consider candidates for future opportunities. For more information or to request a reasonable accommodation, contact our hiring team via the chatbot on this page. This notice is current as of 10/05/2026 and will be updated to reflect material changes in our process or applicable law.
Location & Eligibility
Listing Details
- First seen
- October 5, 2026
- Last seen
- October 5, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 58%
- Scored at
- October 5, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.