Jobs and Careers
UN

Cybersecurity Awareness Training and Outreach Program Manager

University of Oregon
United Statesfull_timeVerifiedPosted 9 Dec 2024
💰 $90,000/yr($70,000/yr$90,000/yr)

About the role

Department: Information Services
Appointment Type and Duration: Regular, Ongoing
Salary: $70,000 - $90,000 per year
Compensation Band: OS-OA08-Fiscal Year 2023-2024
FTE: 1.0

Application Review Begins

July 22, 2024; position open until filled

Special Instructions to Applicants

To be considered for this position, please submit a complete application. Complete applications must include a cover letter and resume that address how you meet the minimum and preferred qualifications, as well as professional competencies.

We are interested in finding the best candidate for the position. We encourage you to apply, even if you don’t think you meet every one of our preferred qualifications--use your cover letter to let us know what is meaningful to you about the role and what transferable skills or other qualities you would bring.

Department Summary

Information Services (IS) is the central information technology organization at the University of Oregon, delivering a broad range of technology and services to the university. IS consists of four major functional areas, each led by a direct report to the VP-CIO: Customer Experience, which serves as the key contact point for interactions with campus clients and customers; Enterprise Solutions, which manages and supports applications, integration services, identity management and data management; Information Security, which helps protect virtual or physical information; and Technology Infrastructure, which provides engineering and support for research IT services and high-performance computing, networking, compute, storage, voice, data centers, audio-visual and classroom technologies, and UO staff supporting Link Oregon, Oregon’s state-wide research and education network.

IS has developed its IT governance practices to sustain alignment between university priorities and its values, resources, and measures of success. The IT Steering Committee, the highest governance entity, helps IS leadership continue to position the organization for optimal impact.

UO Information Security Office (ISO) -
ISO comprises four teams, each focusing on a set of principles and practices established by the NIST Cybersecurity Framework (v.1.1) that Information Services has established as the operational framework for the University’s approach to information security:

Information Security Services & Operations (ISSO) -
ISSO focuses on the identify, protect, and detect functions of the NIST cybersecurity framework. The ISSO deploys technologies to protect the university’s resources and communication channels. This team oversees the identification of institutional assets, updates their risk representation, and provides services to protect them. Programs managed by this function include vulnerability management, email security and phishing protection, threat defense tools like intrusion defense (IDS) and intrusion protection (IPS) systems, security incident event management (SIEM). The ISSO team works with the community to advise regarding the buildout and operation of secure infrastructure to support the university academic, research, and administrative missions.

Cyber Security Operations Center (CSOC) -
CSOC focuses on the detect, respond, and recover functions of the NIST framework. The CSOC manages the university threat-intelligence feeds for indications of compromise, threat hunting, starting incident-response functions, and guiding the recovery after an incident. The group is staffed using university students who rotate through three roles: a) CSOC Analyst, b) Incident Response Analyst and c) Compliance Analyst, during the time they are part of the group.

Information Security Risk & Compliance (ISRC) -
ISRC focuses on supporting all five functions of the NIST cybersecurity framework from the point of view of compliance and controls development. The ISRC works on the creation of policies, standards, controls, guidelines, and procedures that support the information security program. The group works with the university contracts management teams in performing risk and compliance capabilities assessments related to information security for third-party vendors and research contracts. In addition, the team manages UO’s cybersecurity awareness and training program and collaborates with compliance management for GLBA, HIPAA, FERPA, PCI, Red Flag, NIST, and other regulatory requirements relevant to the University.

Information Technology Disaster Recovery (ITDR) Program -
ITDR is a new function of the ISO created in 2022 as the result of one of the objectives identified during an internal information security program review. The ITDR function defines the set of procedures a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

University of Oregon

View company profile →