Director, Information Security
Pepperdine UniversityAbout the role
The Director of Information Security oversees the promotion of digital security across the University. This includes enabling our community to take proactive security measures, monitoring and assessing the environment, and managing security efforts in both academic and administrative areas. The role involves drafting, consulting on, and recommending information security policies in collaboration with key executives, management, and policy committees. We also partner with University stakeholders to identify and mitigate security risks through effective programs and procedures. The office leads the adoption of tools, procedures, and standards to proactively protect the institution's network, systems, services, and data.
Duties
- LEADERSHIP AND ADMINISTRATION: Exercises University-wide leadership in developing, improving, and promoting the University information security program. Provides strong leadership to the Information Security Office, including vision and philosophy in support of academic, research, and administrative information systems and technology. Sets departmental goals and objectives, reviews the goals and objectives of the Information Security team, and aligns projects with the strategic goals of Information Technology (IT) and the University. Delegates tasks with appropriate guidance or mentorship. Empowers staff to take ownership of duties, projects, and problems; to work collaboratively in flexible teams with strong camaraderie; to provide excellent, compassionate customer service; to gather and analyze metrics for team and area success; to work with high integrity to maintain the trust of the University community; to manage time, information, and resources responsibly for excellent stewardship and productivity. Holds teams, individuals, departments, other University departments, and external vendors accountable for following procedures/practices and representing the University well through word and deed. Serves as a member of the IT senior team and IT Leadership Council. Reviews and submits regular, timely, and complete paperwork and processes, such as status reports, bi-weekly or monthly timesheets, financial activities, assessments for mid-year and annual reviews, and other routine IT and University practices. Keeps personal and shared workspaces clean and organized.
- SECURITY POLICY, STANDARDS, AND MEASUREMENT: Leads the establishment, development, and implementation of effective and mission-friendly University policy, standards, guidelines, and best practices that secure various classes of data, support information security, and ensure compliance with laws and regulations. Establishes annual and long-range security and compliance goals, defines security strategies, metrics, reporting mechanisms, and program services. Contributes security architecture input for all new IT projects and offers ideas for efficient security improvement of IT systems. Coordinates all information security related audits including scope of audits, targets, timelines, auditing agencies, and outcomes. Works with University assurance and risk departments and auditors as appropriate to keep audit activities in scope, maintain excellent relationships with audit entities, and provide a consistent perspective that continually strengthens the University's trust and reputation. Provides guidance, evaluation, and advocacy on audit responses. Leads the collection of security outcomes data and promulgation of security program results.
- OUTREACH, EDUCATION, AND TRAINING: Convenes the Information Security Task Force as appropriate to obtain input and buy-in for new and improved security programs. Outreaches to consult for business process reengineering that promotes secure work processes and improves efficiency. Leads development of education and awareness programs and advises operating units at all levels on security issues, best practices, and vulnerabilities. Works with University technical groups to build awareness and a common practice around security. Pursues student information security initiatives to build practical skills and promote a secure campus experience.
- RISK REDUCTION AND INCIDENT RESPONSE: Leads implementation of security controls systems and supervises the team administering technical security tools. Provides direction in the operation and improvement of the suite of security services and tools to mitigate security risk via defense-in-depth. Exercises leadership, direction, and guidance to assess and evaluate information security risks and monitor compliance with security standards and policies. Provides leadership for incident management, breach response, and notification actions for the University. Acts as a primary control point during significant information security incidents.
- COMMUNICATIONS AND RELATIONSHIPS: Promotes professionalism across the d
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s