Director of Cybersecurity Risk Management - University Information Services - Georgetown University
Georgetown UniversityAbout the role
Located in a historic neighborhood in the nation's capital, Georgetown offers rigorous academic programs, a global perspective, exciting ways to take advantage of Washington, D.C., and a commitment to social justice. Our community is a tight knit group of remarkable individuals interested in intellectual inquiry and making a difference in the world.
Requirements
Director of Cybersecurity Risk Management - University Information Services - Georgetown University
Job Overview
The Director of Cybersecurity Risk Management is responsible for the development, enforcement, and general management of the university’s cybersecurity risk management, vulnerability management, policies, and audit activities. They support the Georgetown University information security program through ownership of policy development and enforcement.
They run the vulnerability management program, to include ensuring that system owners and system managers keep all systems up to date with current patches and reducing, eliminating, or mitigating vulnerabilities; and lead the cybersecurity awareness and training program to include education, outreach, and performing phishing training campaigns.
In a Senior-level position within the UISO, the Director represents the Office of the Chief Information Security Officer (CISO) on cybersecurity risk and vulnerability management across GU; serves point-of-contact for the security posture concerns related to departments and organizations outside UIS, the alternate representative of the organization’s security presence to external parties, and the alternate contact point for external auditors and agencies; and ensures compliance with current and emerging regulatory requirements related to cyber security.
Work Interactions and Work Mode Designation
Reporting to the Deputy Chief Information Security Officer, the Director of Cyber Risk Management has interactions with - and may impact - University senior executives, administrators, faculty, alumni, staff, and students, as well as technical staff and IT managers throughout the entire University.
They necessarily communicate effectively and professionally through verbal and written interactions with multiple groups and are self-directed based upon input from the CISO and other appropriate University leadership.
As well, they supervise Security Analysts as assigned to assist with the execution of designated responsibilities.
And in a position of trust, the Director has access to University data or information that may be highly sensitive or confidential in nature.
This position has been designated as Remote. Please note that work mode designations are regularly reviewed in order to meet the evolving needs of the University. Such review may necessitate a change to a position’s mode of work designation.
Complete details about Georgetown University’s mode of work designations for staff positions can be found on the Department of Human Resources website:
https://hr.georgetown.edu/mode-of-work-designation.
Requirements and Qualifications
- Related technical certification or equivalent combination of education (minimum of Bachelor’s degree) and experience required (with solid technical understanding of multi-platform / hosted environments and their operational/security considerations)
- 7 years or more of information security and/or IT compliance and assurance experience – with at least 2 years in a supervisory / lead role - preference for higher education industry experience
- Firm understanding and experience addressing key IT compliance regulations & obligations - including HIPAA, PCI, FERPA, GLBA, and others as identified
- Track record of risk assessment, problem identification, analytical problem solving, and issue resolution
- Ability to learn quickly with strong foundation in understanding and assessing processes and controls
- Excellent written/verbal communication skills with the ability to regularly present to groups
- Availability and willingness to work outside of usual business hours of Georgetown University - including potential on-call responsibilities or to provide assistance for security incidents
Technical Responsibilities/Qualifications
- Understanding of governance and compliance and the ability to enforce policies
- Understanding of threat landscape and ability to manage risk across a dispersed portfolio
- Familiarity with Cyber S
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s