
GENERAL STATEMENT OF RESPONSIBILITY: Responsible for leading and continuously maturing the organization's cybersecurity program through governance, risk management, compliance, AI governance, and strategic security initiatives. Develops and maintains security policies, standards, procedures, and technical baselines while representing the organization during customer security reviews, regulatory audits, and third-party assessments. Provides strategic oversight of enterprise security capabilities by partnering with IT and business leaders to strengthen the organization's overall security posture.
ESSENTIAL FUNCTIONS:
• Lead the development, implementation, and continuous improvement of the enterprise cybersecurity program.
• Develop, maintain, and govern cybersecurity policies, standards, procedures, and technical baselines.
• Establish and maintain security governance aligned with recognized frameworks (NIST CSF, CIS Controls, HIPAA, SOC 2, ISO 27001, and contractual obligations as applicable).
• Develop and maintain the enterprise cybersecurity roadmap and security maturity strategy.
• Conduct enterprise risk assessments and oversee risk remediation, exception management, and mitigation activities.
• Represent the organization during customer security reviews, audits, regulatory assessments, and due diligence activities.
• Coordinate responses to customer security questionnaires and contractual security requirements.
• Maintain security evidence repositories supporting audits, certifications, cybersecurity insurance renewals, and customer requests.
• Participate in enterprise AI governance, including acceptable use standards, risk management, security controls, and evaluation of emerging AI technologies.
• Lead security reviews for new applications, infrastructure, cloud services, AI initiatives, and third-party solutions.
• Provide governance and strategic oversight for vulnerability management, identity security, endpoint security, cloud security, network security, data protection, and security monitoring.
• Ensure designated security product owners maintain effective operational management of assigned security technologies.
• Develop cybersecurity metrics, dashboards, and executive reporting to communicate organizational risk and program effectiveness.
• Lead third-party and vendor security risk assessments.
• Coordinate security awareness, education, and organizational security communications.
• Partner with Infrastructure, Development, Database Administration, Compliance, Legal, PMO, and business leaders to integrate security into enterprise initiatives.
• Drive continuous improvement through documentation, standardization, automation, and operational maturity.
• Remain current on cybersecurity threats, technologies, regulations, AI developments, and industry best practices.
• Provide leadership, mentorship, and strategic direction for the cybersecurity team while fostering accountability, collaboration, continuous improvement, and professional development.
• Maintain professional and technical knowledge by attending educational training forums/workshops; reviewing professional publications; establishing personal networks, participating in professional societies.
• Maintain team performance by evaluating, hiring, training, coaching, disciplining and motivating; initiating disciplinary action when appropriate.
• Set department schedules and work assignments to expedite workflow.
• Establish and maintain department SOP’s and ensure compliance.
• Be proactive in bringing ideas to management’s attention to improve recruiting, productivity, service, quality, policies and procedures, cost savings, and utilization of company resources.
• Ensure concerns are raised to the appropriate level of management.
• Maintain and protect the confidentiality of all CRL, CRL subsidiaries, legal entities and client information.
• Be able to comply with all applicable federal, state, and local safety and health regulations that would apply to this job.
• Other duties as assigned.
JOB QUALIFICATIONS:
EDUCATION:Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent professional experience
EXPERIENCE:
SKILLS & ABILITIES:
PHYSICAL REQUIREMENTS: The physical demands described here are representative of those that must be met to successfully perform the essential functions of this job.Reasonable accommodations may be available to enable qualified individuals with disabilities to perform the essential functions.
This position requires the necessary physical attributes for office work such as:
• Sitting for extended lengths of time
• Close vision requirements due to computer work
• Repetitive use of hands, fingers, wrists and elbows for operating a computer and telephone
• Light lifting, up to 10 pounds
EQUIPMENT: PC, midrange systems, and communications equipment.
OTHER: Flexible work schedule; work outside of normal business hours, including weekends, may be required; this is an on-call position requiring use of wireless phone for after-hours contact
The employer shall, in its discretion, modify or adjust this position to meet the company’s changing needs.
This job description is not a contract and may be adjusted as deemed appropriate in the employer’s sole discretion.
To perform this job successfully, an individual must be able to perform each essential job duty satisfactorily. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform essential job functions.
An Equal Opportunity Employer
Pay Range: $110,000 - $245,000
Starting Pay Range: $110,000 - $150,000
Benefits for Full Time Employees:

CRL was originally founded as Enzyme Technologies in 1979 with our focus on clinical research and development. The name was changed to Clinical Reference Laboratory in 1983 when we began to offer commercial lab testing. Today, CRL has become one of the largest privately held clinical testing laboratories in the U.S., performing hundreds of thousands of tests every day for clients large and small. Our staff works around-the-clock to process and report results seven days a week.
We are driven each day to provide the useful insights people need to live healthy, safe, and productive lives. We serve insurers, employers, healthcare providers and their patients, colleges and universities, as well as federal, state, and local government agencies through a broad array of corporate and personal wellness programs, drugs of abuse testing programs, insurance risk assessment, and molecular diagnostics testing.
Together with FormFox, the nation’s leading provider of ECCF and electronic workflow solutions, we provide integrated solutions for workplace drugs of abuse testing, occupational health testing, and clinical lab testing services. CRL’s industry-leading turnaround times and state-of-the-art equipment and technology, paired with FormFox’s data management and digital workflow solutions, seamlessly connect all participants.
Our mission isn’t to be the most recognized lab, but to be the most trusted laboratory partner by providing personalized service, accurate testing, rapid turnaround time, and innovative systems and solutions. We conduct research, advance our test menu, pursue collaborations, discover new applications for existing data, and hold ourselves to the highest level of quality and client support standards, uniquely positioning our partners to achieve the best possible outcomes. And we do it all with a human touch.