Jobs and Careers
SA

Director, Information Security

Saint Joseph's University
Philadelphia, United Statesfull_timeVerifiedPosted 22 Jul 2024

About the role

Position Title:

Director, Information Security

Time Type:

Full time

Position Summary and Qualifications:

The Director, Information Security assists the CISO in developing an information security vision and strategy that is aligned to organizational priorities.

They will manage the day to day operations and staff of the Information Security department. This area focuses on identity and access management, GRC (governance, risk and compliance) as well as network security/operations.

They will assist the CISO in the management and coordination of security standards, along with implementation and execution to ensure compliance to security standards and policies and provide expertise in managing audits, vulnerability remediation and incident response.

They will assist in managing the University information security awareness program and promote best practices in security and compliance management.

Note to applicants: In the Resume/CV upload field, please submit a resume, a cover letter, and 3 references that can speak to your direct experience in information security and management

Essential Duties & Responsibilities

  •  Manages the day to day operations and staff of the Information Security department.   This area focuses on identity and access management, GRC (governance, risk and compliance) as well as network security/operations.

  • Assists the IAM Analyst with the management of the security awareness program to ensure that there is an appropriate awareness of information security and safe computing practices across the University.

  • Provides support in managing vendor relationships pertaining to information security, including the formal review of university contracts which have technology components.  Using a vendor questionnaire, assesses each vendor’s overall capabilities including infrastructure, controls, security practices, regulatory compliance, ability to protect University information assets, etc. Issue a security opinion on the suitability of each vendor.

  • Provides support in investigating and assessing security incidents in collaboration with technology managers in IT, and in partnership with the Office of General Counsel.  Responds to alleged policy violations and complaints received from external parties.  Documents findings via a formal security incident report.  

  • Serves as the backup point of contact for security threats, potential breaches, and privacy issues, including matters involving law enforcement. Works with internal and external auditors and agencies on security and compliance matters, including incident response.   

  • Assists the IT Audit Analyst in developing a strategy for addressing audits, assessments and compliance efforts.

  • Assists the CISO in establishing annual and long term security and compliance goals. Creates and implements security strategies, metrics, and reporting processes.

  • Develops, maintains, promotes and enforces data management and information security policies, standards, guidelines, and procedures, including those for end users, system and application administrators, service providers, and legal/regulatory compliance.

  • Assists in developing communication and education initiatives around the awareness of information security risks as well as mitigation strategies and protections that are in place at the university.

  • Understands and interacts with IT advisory councils, administrative and academic units through committees, to ensure the development of and consistent application of policies and standards across technology projects, systems and services, including privacy, risk management, compliance and business continuity management.

  • Works collaboratively with others to conduct risk assessments and business impact analysis to identify vulnerabilities and risk exposure.

  • Where risks have been identified, provides recommendations on managing that risk, including acceptance, avoidance, transference, and mitigation techniques to minimize potential impact on the university.

  • Keeps current with emerging governmental regulatory initiatives and security alerts and issues which could have an impact on the university environment.

  • Provides guidance, planning, and monitoring for compliance with various industry requirements (e.g. FERPA, , HIPAA, PCI), which impact the way in which various systems are implemented.  Prepares and submits required reports to external agencies.  

  • Direct supervisor for: I

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Saint Joseph's University

View company profile →