Director of Security Operations
Tennessee Board of RegentsAbout the role
Job Title: Director of Security Operations
Campus Location: Morristown Campus (Employees are assigned to a “home” location but may occasionally or regularly be required to work at other WSCC locations.
Job Purpose: This position guides and maintains the college’s information security program. They are responsible for all matters of IT security, compliance, auditing, risk mitigation, and policy. This position works to strengthen the college’s security posture and minimize risks from external and internal security threats. The position holistically oversees governance, standards, compliance, security policies, risk assessments, incident response, audits, security architecture, security programs, security controls, security monitoring, third-party relationships, security training, phishing campaigns, security documentation, GLBA, PCI, table-top exercises, security tools, industry trends, etc.
Duties include incident monitoring, metrics gathering, generating security-focused reports and performing security-related audits as needed. The position is responsible for the operation and maintenance of the security infrastructure, evaluating, recommending, and implementing new approved technologies and innovations. This position holds responsibility for the troubleshooting and resolution of reported information security issues. This position works in conjunction with organizational departments across the college to ensure employees are aware of cybersecurity issues, are trained in good cybersecurity practices, and are practicing safe/secure data collection, data transfers and storage, and use of social media, mobile devices, apps, etc.
Essential Job Functions:
- Manages and oversees security operations, security engineering, and compliance of information systems and services across the enterprise. Maintains awareness of the college’s security posture and exposure. Articulates any security issues to constituents, IET, and college leadership. Monitors, troubleshoots, isolates, and otherwise mitigates critical vulnerabilities. Develops controls, detects trends, and minimizes exposure to security vulnerabilities. Responsible for troubleshooting, responding, and resolving information security issues. Performs analysis of activities and threats as a means of investigation, including digital forensics. Develops, implements, and refines solutions for security monitoring, detection, and response on college technology systems. Performs high-level analysis of complex systems, networks, data storage, and other technology systems. Authors and edits security incident reports for documentation.
- Manages the college’s Information Security Program. Promotes information systems reliability and accessibility, while protecting and defending against unauthorized access to systems, networks, and data; lead the planning, design, development, integration, testing, documentation, training, implementation and maintenance of IT security systems and products; oversees ongoing activities related to the development, implementation, and improvement of the information security program in compliance with applicable federal and state laws and regulations and college security policies. Primary areas of focus: security risk assessments; risk management; education and awareness; advising personnel on managing effective security practices; developing and maintaining strong working relationships to collaborate and partner with key stakeholders and external solution providers to advocate for appropriate security practices; planning, designing, enforcing, and auditing security policies and procedures which safeguard the integrity of and access to college systems.
- Develops, delivers, documents, and manages IT security standards, policies, procedures, best practices, etc. to enhance the overall security architecture. Ensures that IT security audits are conducted periodically or as needed; collaborates with internal, TBR, and state auditors during regular audit cycles. Maintains disaster recovery and business continuity plans. Ensures technology systems protect sensitive information through encryption and other security tools. Maintains knowledge of IT risks through the review of various email lists, security websites, and professional publications; researches technology security trends; proactively identifies threats to the college and recommends protective actions. Analyzes new federal and state statutory requirements, TBR and state policies, and other security initiatives to determine changes necessary for adoption/compliance and makes appropriate recommendations to IT management.
- Develop security awareness training programs; penetration testing timelines; security standards metrics and other security-related tools for distribution and impleme
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s