Under the general direction of the CIO/Vice President for Information Technology, the Director of Information Security and Compliance leads LMU efforts to safeguard the university’s information assets and ensure compliance with relevant regulations and standards. The Director will be responsible for developing, implementing, and maintaining a comprehensive information security program that aligns with the university's mission, values, and goals. The Director will leverage partnerships and collaboration to ensure that LMU information assets and associated technology, applications, systems, infrastructure and processes are adequately protected. The Director will serve as the process owner of the appropriate second-line assurance activities not only related to confidentiality, integrity and availability, but also to the safety, privacy and recovery of information owned or processed by LMU in compliance with regulatory and university requirements. The Director will oversee the university’s compliance with applicable laws, regulations, and policies related to information security and privacy.
Position Specific Responsibilities/Accountabilities
Leadership and Strategy
Develop and execute a comprehensive information security strategy that aligns with LMU’s academic, research, and administrative goals.
Lead the Information Security and Compliance team, providing direction, mentorship, and professional development opportunities.
Collaborate with senior leadership, academic units, and administrative departments to promote a culture of security awareness and compliance across the university.
Plan, direct and participate in technology security assessment activities, program planning and reporting for LMU.
Interacts with Internal Audit, University Counsel and other internal control resources, as well as external civil and law enforcement authorities, to promote mutual cooperation.
Information Security Management:
Oversee the design, implementation, and management of security controls and measures to protect the confidentiality, integrity, and availability of university information systems and data.
Develop and enforce security policies, procedures, and standards in line with industry best practices and regulatory requirements.
Lead the university’s incident response efforts, including the identification, investigation, and mitigation of security breaches.
Conduct regular risk assessments, vulnerability assessments, and security audits to identify and address potential threats.
Collaborate with other ITS departments to ensure security is integrated into all technology projects and initiatives.
Operations
Compliance and Governance
Ensure the university’s information security practices comply with applicable laws, regulations, and standards, including FERPA, HIPAA, GDPR, CCPA, and PCI-DSS.
Develop and maintain a robust security awareness training program for faculty, staff, and students.
Oversee the university’s data governance efforts, ensuring that data is managed securely and in compliance with university policies and legal requirements.
Prepare and present reports on the university’s security posture and compliance status to senior leadership and relevant committees.
Collaboration and Outreach
Interact and coordinate with LMU administration, campus and department technology representatives, the University Technology Council and other technology governance structures, other LMU governance bodies, and external authorities as necessary.
Foster strong relationships with internal stakeholders, including academic units, administrative departments, and student organizations, to promote security best practices.
Represent LMU in external security and compliance forums, including higher education consortia and industry groups.
Collaborate with peer institutions to share best practices and address common security challenges.
Budget and Resource Management
Develop and manage the Information Security and Compliance budget, ensuring resources are allocated effectively to meet strategic goals.
Evaluate and procure security technologies and services that support the university’s security objectives.
Perform other related duties.
Loyola Marymount University Expectations
Exhibit behavior that supports the mission, vision, and values of the university. Communicate and employ interpersonal actions that model high standards of professional, responsible, accountable, and ethical conduct. Demonstrate a commitment to outstanding customer service.
Requisite Qualifications
Typically a Bachelor’s Degree from an accredited four-year institution in Computer Science, Information Technology, or Cybersecurity.
Seven years of experience in information security, with at least three years in a management role.
Experience in developing and implementing technology policy, especially in a University environment is desirable.
Professional certifications such as CISSP, CISM, or CISA are highly desirable.
Strong knowledge of information security frameworks, standards, and best practices (e.g., NIST, ISO 27001).
Experience with regulatory compliance requirements (e.g., GDPR, HIPAA, FERPA).
Demonstrated excellent verbal and written communication skills, as well as presentation skills. Writing samples may be required.
Excellent analytical, problem-solving, and decision-making skills.
Strong communication and interpersonal skills, with the ability to effectively collaborate with diverse stakeholders.
Demonstrated ability to lead and manage a team of security professionals.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of this position.
#HERC# #HEJ#
Staff Regular
Salary range
$143,100.00 - $200,300.00 Salary commensurate with education and experience.Loyola Marymount University, a Carnegie classified R2 institution in the mainstream of American Catholic higher education, seeks outstanding applicants who value its mission and share its commitment to inclusive excellence, the education of the whole person, and the building of a just society. LMU is an equal opportunity employer committed to providing an environment free from discrimination and harassment as defined by federal, state and local law. We invite all persons in the full diversity of their being, life experience, and beliefs to apply. (Visit www.lmu.edu for more information.)