The Chief Information Security officer (CISO - an IT professional with strong expertise in IT, security Management, and IT enterprise architecture. Demonstrated expertise in establishing and implementing large information security programs, with knowledge and experience in the policy and regulatory environment of information security. Also, knowledge of computes and information security, network security issues, and security incident response and recovery in a higher education environment. Performed IT security evaluations and successfully implemented IT security systems to protect the availability, integrity and confidentiality of critical business information and information systems. In-depth end-to-end management experience helping customers quickly resolve critical problems and issues through innovative and practical solutions leveraging his wider techno-functional and managerial experience in IT-GRC, IT and Program, Stakeholder, Supplier and Contract Management and Service Delivery.
Key Responsibilities:
- Serve as CISO for organizations/institutions of Higher Education and others across the country.
- Responsible for the overall management, maintenance, improvement and effectiveness of client information security programs
- Responsible for the development and delivery of a comprehensive information security strategy to optimize client’s security posture based on risk, priorities and resources
- Lead the development, implementation, and monitoring of information security programs, and responsible for designing strategies to mitigate information security risks
- Responsible for risk management, performing a multitude of audits, assessments and exercises to proactively identify gaps, weaknesses and areas of opportunity for security planning, projects and initiatives
- Responsible for monitoring, tracking and meeting compliance with a multitude of laws, regulations and mandates (GLBA, PCI, HIPAA, GDPR, etc.)
- Responsible for the adoption and integration of various information security frameworks (NIST, ISO, CIS, CMMC, etc.)
- Lead information security governance efforts in order to build a comprehensive data program (data discovery, classification, stewardship and data protection)
- Lead efforts to internally assess, evaluate and make recommendations to management regarding the adequacy of the security controls for client’s information and technology systems, providing written reports, recommendations and other appropriate mitigation/action plans
- Manage security incidents and serve as primary contact during significant information security incidents, convening a Security Incident Response Team (SIRT) as needed, or requested, in addressing and investigating security incidents
- Responsible for Vendor Management performing security reviews of new and existing vendors utilizing HECVAT, SOC reports, Contracts, VPAT’s etc. in order to ensure Third Party/Vendor risk portfolios are tracked, maintained and monitored
- Provide client information security audits (NIST, CMMC, GLBA) in efforts to provide areas of improvement and opportunity for advancing and maturing cybersecurity posture
- Responsible for University wide Information Security Awareness Training efforts, including phishing campaign strategies, curriculum development, new-hire training and effective deployment strategies.
Experience:
- 15 - 20 years of experience
Qualifications:
- A four-year degree from an accredited institution, equivalent qualification or experience
- One or more security-specific certifications such as CISSP, CISM, CISA
- Proven experience as a higher education technology services leader
- Excellent knowledge of higher education IT systems, applications and security
- Superior analytical and problem-solving capabilities
- Excellent organizational and leadership skills
- Outstanding communication and interpersonal abilities
- A hands-on collaborative style of working is a must
Skills:
- Technical and cybersecurity competence (understands services, software, hardware)
- Experience of best practices within information security and risk management
- An understanding of legislation and regulations that impact information security
- An understanding of current and emerging threats and countermeasures and the organizational challenges to addressing these threats
- Proven relationship builder; internally and externally
- Previous higher education clients service experience
- Proven account management skills required in order to create, maintain and enhance customer relationships
- Extremely detail oriented
- Motivated, goal oriented, persistent and a skilled negotiator
- High level of initiative and works well in a team environment
- Excellent written and oral communication skills
- Handles stressful situations and deadline pressures well
- Plans and carries out responsibilities with minimal direction