bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesConstruction ResourcesSecurity Risk & Operational Resilience Lead

Security Risk & Operational Resilience Lead

Construction Resources · 196 Rio Circle, Decatur, GA, 30030, · Hybrid · Active · Greenhouse

Job facts

FieldValue
CompanyConstruction Resources
TitleSecurity Risk & Operational Resilience Lead
Normalized title-
Department / teamConstruction Resources
LocationDecatur, GA, United States
Work modelHybrid / Hybrid
Employment type-
Salary-
Statusactive
ATS providerGreenhouse
Posted / first seen2026-06-23 / 2026-06-23
Changed / last seen2026-06-23 / 2026-06-23

Related slices

PageWhat it containsOpen
Company jobsActive postings from Construction Resources.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through Greenhouse.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in Decatur.Open
Department jobsActive postings in Construction Resources.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyConstruction Resources
Source38828fd8-bf4d-4f0b-97cf-aa6795413732
ATS providerGreenhouse

Description

Security Risk & Operational Resilience Lead Role Overview The Security Risk & Operational Resilience Lead is responsible for designing, operationalizing, and continuously improving Construction Resources’ enterprise security governance, risk, and incident readiness programs. This role serves as the program owner for GRC, incident readiness, and control effectiveness, ensuring that security policies, controls, and response processes are not only defined—but measurable, tested, and consistently executed across the organization. The position operates as a bridge between cybersecurity engineering, IT operations, and executive leadership, aligning stakeholders while maintaining clear separation from direct ownership of security tools or infrastructure. The ideal candidate is a strategic, hands-on leader who can translate security requirements into operational execution and measurable outcomes across a complex, growing enterprise. Key Responsibilities Governance, Risk & Compliance (GRC) Program • Develop, implement, and continuously mature Construction Resources’ enterprise GRC program, including risk management, control frameworks, compliance monitoring, and reporting. • Maintain alignment with industry standards and regulatory requirements, including NIST CSF, ISO 27001, SOC 2, and PCI-DSS. • Lead enterprise risk assessments and manage a central risk register, including prioritization, ownership assignment, and remediation tracking. • Build and deliver security metrics, dashboards, and executive reporting to support informed decision-making at the leadership and Board level. Security Program Execution & Control Effectiveness • Define and implement a control validation and assurance program to verify security controls are operating effectively across identity, endpoint, network, and data domains. • Establish standardized methods for collecting control evidence, validation results, and remediation tracking, leveraging enterprise tools such as Jira Service Management (JSM). • Partner with cybersecurity engineering and IT operations to ensure controls are embedded into operational workflows, not treated as standalone compliance activities. • Drive measurable improvement in control effectiveness, coverage, and time-to-remediation metrics across the organization. • Lead enterprise cybersecurity auditing activities across frameworks and control areas (e.g., PCI-DSS, identity/access, network, and data security), ensuring audit readiness, evidence validation, gap identification, and timely remediation. Security Policy & Standards Management • Own the lifecycle of security policies, standards, and procedures, ensuring they are current, actionable, and aligned with business and regulatory requirements. • Drive adoption and operationalization of policies across technology and business teams. • Conduct periodic policy reviews, gap assessments, and effectiveness evaluations to ensure policies result in real-world security improvements. Incident Response Program & Readiness • Own the Incident Response (IR) program framework, including governance, policies, and playbooks aligned to industry best practices. • Define and maintain incident classification, escalation, and communication models integrated with enterprise operational systems. • Serve as Incident Commander for high-severity events, coordinating cross-functional response efforts while partnering with engineering leads responsible for technical containment and recovery. • Lead post-incident reviews, root cause analysis governance, and corrective action tracking to ensure continuous improvement. • Conduct regular tabletop exercises with executives, technical teams, and business leaders to validate response readiness. Security Operations Integration • Establish and maintain integration between security programs and operational systems, including ticketing, monitoring, and collaboration platforms. • Define standardized security workflows for detection, escalation, and major incident handling, ensuring consistent routing, ownership, and visibility. • Partner with cybersecurity engineering and IT operations to improve incident triage, escalation consistency, and response effectiveness across business units. Mergers & Acquisitions (M&A) Security Integration • Lead cybersecurity due diligence for acquisitions, including risk assessments and evaluation of security posture. • Define and execute standardized integration playbooks (Day 1, Day 30, Day 90) to onboard acquired entities into CR’s security program. • Track integration risks and remediation activities through formal governance and reporting structures. • Prioritize integration of identity, endpoint protection, network segmentation, and compliance alignment. Cross-Functional Leadership & Collaboration • Serve as a trusted advisor to senior leadership on security risk, compliance, and operational readiness. • Build strong relationships with business units to embed security into operational processes and strategic initiatives. • Partner closely with Technology, Legal, Privacy, Internal Audit, and Corporate Development teams. • Over time, support the development and mentorship of GRC and security program resources as the function scales. Scope Boundaries & Collaboration Model This role is responsible for program ownership, governance, and operational readiness, and collaborates closely with technical and operational teams. This role does not directly own: • Security tool administration (e.g., SIEM, EDR, network security platforms) • Infrastructure, network, or endpoint engineering Instead, the role partners with: • Cybersecurity engineering leadership for design and implementation of technical controls • IT operations teams for execution of remediation and system-level changes Qualifications • 10+ years of progressive experience in Information Security, GRC, or related fields • 5+ years of experience leading security programs or cross-functional initiatives • Strong knowledge of security frameworks (NIST CSF, ISO 27001) and regulatory requirements (PCI-DSS preferred) • Proven ability to develop and operationalize enterprise GRC and incident response programs • Experience driving measurable outcomes through metrics, reporting, and governance • Strong collaboration and communication skills across technical and business audiences • Relevant certifications preferred (CISSP, CISM, CRISC or equivalent) Work Location Hybrid – This role may work remotely but is expected to attend meetings and work from Construction Resources offices as needed. BENEFITS Medical Dental Vision Employer Paid Basic Employee Life and AD&D Insurance Employer Paid Long Term Disability Flexible Spending Accounts Voluntary Short-Term Disability Voluntary Life and AD&D Insurance Voluntary Accident Insurance Voluntary Critical Illness Insurance EEO At Construction Resources, our people are the driving force behind everything we do. Construction Resources is an equal opportunity employer that aspires to be the best in the business by building an associate experience that celebrates growth, development, and purpose. PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee is regularly required to speak or hear. The employee is frequently required to sit for extended periods of time, stand, walk, climb stairs, use hands to finger, handle or feel, and reach with hands and arms. Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception and ability to adjust focus. POSITION TYPE/EXPECTED HOURS OF WORK This is a full-time position that requires overtime as business needs dictate. OTHER DUTIES Please note: this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time, with or without notice. PRIVACY NOTICE We value your privacy and want to ensure transparency regarding the collection and processing of your personal data. As part of our recruitment process, we require your explicit consent to collect, store, and process your personal information, including but not limited to your resume, contact details, professional experience, and other relevant data. This data will be used solely for recruitment and hiring purposes in accordance with our privacy policy and applicable data protection regulations. Your information will be stored securely and will not be shared with third parties without your consent. By submitting your application, you agree to the collection and processing of your personal data for the purposes stated above. You may withdraw your consent at any time by contacting us at [email protected].

Full job record

Job IDffb27f0eb4c0af92e081560226fad694e0f62f92
Org IDd21b2480-a207-4b60-9365-9af00d4f23c8
Source ID38828fd8-bf4d-4f0b-97cf-aa6795413732
Board ID38828fd8-bf4d-4f0b-97cf-aa6795413732
Providergreenhouse
Provider Job Key5276012008
TitleSecurity Risk & Operational Resilience Lead
Normalized Title
Statusactive
Activeyes
Location Text196 Rio Circle, Decatur, GA, 30030,
DepartmentConstruction Resources
Team
Employment Type
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionGA
CityDecatur
Salary Raw
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://job-boards.greenhouse.io/constructionresources/jobs/5276012008
Apply URLhttps://job-boards.greenhouse.io/constructionresources/jobs/5276012008
First Seen At2026-06-23 07:33:04Z
Last Seen At2026-06-23 07:33:04Z
Last Checked At2026-06-23 07:33:04Z
Last Changed At2026-06-23 07:33:04Z
Inactive At
Source Posted At2026-06-23 00:05:28Z
Source Updated At2026-06-23 00:05:28Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=greenhouse/board=constructionresources/date=2026-06-23/2026-06-23T07-33-03-989Z-68485171524d98d927c790d64092705dffe89daf8ccfb03df0c71e45e9d5c9c1.json
Event Fields
{
  "content_hash": "4cc169e432a1f16db0a9c482db3d83767ea46cf3f2f0d4c6b8fc56369ab8666d",
  "source_hash": "f808f86eb95e0229ff8da4d11ae31c6171c80712db91ce064c1249b836c1ef14",
  "last_changed_at": "2026-06-23T07:33:04.288Z",
  "active_status": "active"
}
Parsed Structured
{
  "dedupe": null,
  "language": "en",
  "location": {
    "raw": "196 Rio Circle, Decatur, GA, 30030,",
    "city": "Decatur",
    "region": "GA",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.9
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-23T07:33:04.278Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "196 Rio Circle, Decatur, GA, 30030,",
      "city": "Decatur",
      "region": "GA",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "title": "Security Risk & Operational Resilience Lead",
  "offices": [
    {
      "id": 4033348008,
      "name": "CR Corporate - Decatur",
      "location": "196 Rio Circle, Decatur, GA, 30030,",
      "child_ids": [],
      "parent_id": 4032351008
    }
  ],
  "language": "en",
  "location": {
    "name": "196 Rio Circle, Decatur, GA, 30030,"
  },
  "metadata": [],
  "updated_at": "2026-06-22T20:05:28-04:00",
  "departments": [
    {
      "id": 4037829008,
      "name": "Construction Resources",
      "child_ids": [
        4067632008
      ],
      "parent_id": null
    }
  ],
  "company_name": "Construction Resources",
  "requisition_id": 4489088008,
  "first_published": "2026-06-22T20:05:28-04:00",
  "application_deadline": null
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/ffb27f0eb4c0af92e081560226fad694e0f62f92?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/d21b2480-a207-4b60-9365-9af00d4f23c8JSON
GET https://api.bluedoor.sh/job-postings/v1/sources/38828fd8-bf4d-4f0b-97cf-aa6795413732JSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/ffb27f0eb4c0af92e081560226fad694e0f62f92/eventsJSON