Essential Qualifications:
- High ethical standards representative of Princeton University’s commitment to excellence.
- 6+ years of experience in IT audit, Information Security Operations, IT management, information security analysis, IT operations, research data security, and/or systems assurance.
- Demonstrated ability to analyze technology systems and processes with strong attention to detail, apply critical thinking skills, and use sound business judgment in the application of auditing principles, University policies, and business practices.
- Excellent project management skills and demonstrated ability to achieve audit objectives on multiple, complex, concurrent projects.
- Demonstrated ability to translate business requirements into achievable technical terms; effective communications and translation of requirements between technical and non-technical stakeholders across the University.
- Experience managing multiple project stakeholders (internal and external) in concurrently running engagements.
- Strong analytical, problem solving, time management, and interpersonal
- Excellent communication skills, including proven ability to prepare and present clear and concise reports to stakeholders and articulate complex and/or technical issues.
- Superior judgment, diplomacy, and discretion in handling sensitive information.
- Demonstrated technical skills and experience in some of the following:
- Information system testing techniques including the use of automated assessment tools.
- TCP/IP based network architecture and corresponding security design and enabling technologies such as next generation firewalls, IPS/IDS, routers, and switches.
- Microsoft Windows, Mac OS, and Linux operating systems, Active Directory, LDAP, Office 365/Exchange, SQL and Oracle Database, VMWare, and SharePoint.
- Configuration management and automation technologies such as Ansible Tower or Puppet.
- Third party cloud offerings such as Amazon Web Services and Microsoft Azure and software as a service vendor assessments and ongoing monitoring (e.g., System and Organization Control reports).
- Vulnerability assessment and/or penetration testing tools and concepts.
- Knowledge of one or more information security frameworks including the NIST Cyber Security Framework, NIST SP 800-171, CMMC (NIST SP 800-172), HITRUST, ISO 27000 series, and the CIS Controls.
- Self-motivation, initiative, and broad thinking.
- Current CISSP, CISA, CISM, CRISC, or other relevant certification, or a commitment to pursue.
- BA/BS or an advanced degree in information systems, business, or a related field.
Preferred Qualifications:
- 8+ years of quantifiable experience in IT and/or information security operations, effective client management, and service delivery.
- Advanced degree in information systems, business, or a related field.
- Knowledge of University operations and/or experience in higher education, especially focused on unique risks associated with academic departments, research, and techniques for effective risk management of non-centrally managed information technology.
- Experience assessing the implementation of privacy principles and relevant controls in information systems.
- Experience managing projects co-sourced with professional services firms.
- Knowledge of Large-scale ERP systems such as PeopleSoft, internal and external penetration testing tools and techniques, web application scanning/testing, social engineering, secure software development methodologies and enabling technology tools.
- Familiarity with Internet of Things (IoT) devices, industrial control systems (ICS) and supervisory control and data acquisition (SCADA).
This role is Princeton-based and does not require travel. The finalist will be required to successfully pass a background check.
Princeton University is an Equal Opportunity/Affirmative Action Employer and all qualified applicants will receive consideration for employment without regard to age, race, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability status, protected veteran status, or any other characteristic protected by law. KNOW YOUR RIGHTS