The Chief Information Security Officer (CISO) Project-Based Consultant is a senior business leader who will oversee all aspects of data privacy, compliance, and security for Higher Education institutions. You will leverage your expertise in cybersecurity and familiarity with established frameworks like NIST and CIS and regulations such as FERPA and GLBA to implement institution-aligned security, compliance, and data privacy programs. The CISO will facilitate a team approach to daily operations in support of these frameworks, providing strong risk management, control procedures, and incident response support for institutional operations. The successful candidate will form close relationships with executive leaders to determine acceptable levels of business risk and will foster strong working relationships with IT staff and business stakeholders to work collaboratively to improve an institution's security compliance and privacy posture.
Responsibilities
- Work with campus leadership to develop, implement, and monitor strategic, comprehensive, enterprise information security and IT risk management programs.
- Work with the information technology staff and other cybersecurity professionals in overall technology planning and define information security programs.
- Conduct security and privacy risk assessments to identify areas of unexpected risk to business and technology operations.
- Build and periodically test incident response programs based on business risk analysis.
Qualifications & Requirements
- 5 or more years of experience in a combination of risk management, information security, and IT roles.
- Minimum of 5 years of experience in a senior IT leadership role.
- Experience in Higher Education is strongly preferred.
- Successful track record of implementing security, privacy, and governance programs.
- Professional certifications such as CISSP, CISM, CISA, or GIAC certifications may be preferred or required.
- Deep and demonstrable knowledge of common information security management frameworks, such as SOC 2, ISO/IEC 27001, and NIST.