> Markdown version of [/jobs/ext/1281048-executive-director-information-security](https://www.wearedevelopers.com/jobs/ext/1281048-executive-director-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Executive Director, Information Security - **Company:** Chicago Public Schools - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Data Security, Information Security Management, Information Systems Security Architecture Professional, Network Security, PCI Data Security Standards, Software Security, Information Technology - **Published:** July 15, 2026 - **Apply:** https://cpsk12il.taleo.net/careersection/3/jobdetail.ftl?job=25000059 ## About the Role · Bachelor's degree from an accredited college or university in Computer Science, Information Systems, or other related field · Professional security management certification, such as Certified Information Systems Security Professional (CISSP), or similar credentials, preferred · Master's degree, preferred Experience Required: · Minimum of seven (7) years experience in the information technology field, including a minimum of five (5) years in an information security role · Minimum of three (3) years experience in large (>50,000 users) heterogeneous enterprise-level IT organization · Minimum of five (5) years of supervisory experience · Experience with contract and vendor negotiations · Experience designing and managing new and existing security systems Knowledge, Skills, and Abilities: · Proven track record and ability to develop information security programs, policies and procedures, including successful implementations in large enterprise environments · High degree of initiative, dependability; experience managing multiple, simultaneous, and high-profile information security initiatives and responses · High level of personal integrity, as well as the ability to professionally handle confidential matters, and show an appropriate level of judgement and maturity · Strong knowledge of common information security management frameworks, such as ISO/IEC 27001, COBIT, NIST, CSA and deep knowledge and understanding of relevant legal and regulatory requirements/standards, including but not limited to: Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act of 1996 (HIPAA), Children's Online Privacy Protection Act (COPPA), Payment Card Industry Data Security Standard (PCI DSS), Illinois School Student Records Act (ISSRA) · Ability to advise infrastructure and applications staff in securing their respective environments · Exhibit strong written and verbal communication skills, interpersonal and collaborative skills · Strong ability to convey security information to non-technical end-users in a way that inspires adoption and adherence to all IT and Board security policies and programs ## Description Reporting to the Chief Information Officer, the Executive Director, Information Security is responsible to establish and execute information security program directives, policy development, and policy enforcement as well as overseeing district's network security systems. The Executive Director, Information Security will develop mechanisms to best identify, evaluate, and mitigate district-wide information security risks in a manner that upholds compliance and regulatory requirements, and aligns with the risk posture of CPS. This role leads the information security and operations teams. This is a full-time exempt position that will be paid for time worked on a salary basis. This Job will be held accountable for the following responsibilities: · Establish and execute strategic, comprehensive enterprise information security program directives and plans, including any and all district-wide information security training efforts to ensure that the confidentiality, integrity, and availability of information is owned, controlled or processed in a manner compliant with the CPS Board Policy and relevant regulatory authorities · Develop and maintain information security policies, standards, guidelines and oversee the dissemination of security policies and practices; identify knowledge gaps to increase district awareness of relevant information security practices · Lead and develop the information security and operations teams · Provide leadership and guidance on information security topics, advising and collaborating on security processes, business continuity, and disaster recovery plans · Provide oversight to the architecture and engineering of new security systems; including the evaluation of technical designs · Ensure that system and application security design is in accordance with CPS Board Policy; consult with IT teams to ensure that security is factored into the evaluation, selection, installation, and configuration of hardware, applications and software · Lead investigations of any actual or potential information security violations and manage escalation of security events; assist with related legal matters associated with such events as needed and make recommendations to correct or prevent future incidents · Monitor external threat environment for emerging threats and advise relevant stakeholders on appropriate courses of action · Provide regular reporting on current state of information security program to the CIO and other senior managers as appropriate · Establish metrics and reporting framework to measure the efficiency, effectiveness, and maturity level of the program · Liaise with relevant CPS business units (such as Internal Audit, Law, Finance, Safety & Security, Risk Management, HR teams), and external agencies as needed to ensure that CPS maintains a strong security posture · Work with system administrators and application developers to audit, monitor and validate their environment's security, including conducting gap analysis and other comprehensive internal assessments of existing systems to improve the security infrastructure and mitigate risks · Other duties as assigned ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)