> Markdown version of [/jobs/ext/145693-chief-information-security-officer-ciso-director-of-information-security](https://www.wearedevelopers.com/jobs/ext/145693-chief-information-security-officer-ciso-director-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) / Director of Information Security - **Company:** University of New England - **Location:** Portland, ME, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Health Informatics, Business Process Modeling, Cloud Computing Security, Code Review, Cyber Security, Information Systems, Data Governance, Identity and Access Management, Information Security Management, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Network Security, PCI Data Security Standards, Performance Tuning, Phishing, Runbook, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Data Logging, Data Processing, Information Technology - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3e834d80cba8a48d ## About the Role Bachelor's in Cybersecurity, Computer Science, Information Systems, Business Administration or related field. * 5+ years in information security with progressive responsibility; 3+ years in a leadership or architect role. Direct experience in higher education and/or healthcare IT strongly preferred. * Demonstrated hands-on expertise with SIEM/EDR, IAM/PAM, vulnerability management, cloud security (Microsoft 365/Azure, Box), network security, scripting and automation, and incident forensics. * Regulatory frameworks (FERPA, HIPAA technical safeguards, GLBA, PCI DSS), NIST CSF/800-53, risk management, secure architecture. * Executive communication, stakeholder influence, vendor management, policy writing, clear documentation, and ability to operate independently while building future capability., * Master's Degree in Cybersecurity, Computer Science, Information Systems, Business, or related field. * CISSP, CISM, CRISC, CCSP; HCISPP or equivalent healthcare security credential or certifications. * Experience in higher education or a similarly complex, mission driven organization. * Experience standing up or maturing an information security office or information security management function. * Experience with information security tools and platforms and with service management practices. ## Description The Chief Information Security Officer (CISO) / Director of Information Security leads and manages the University's information security program across academic, administrative, and clinical IT environments. This role combines strategic leadership with hands-on execution, overseeing governance, risk management, security architecture, threat detection and response, and regulatory alignment (e.g., FERPA, GLBA, PCI DSS) while collaborating broadly across the University of New England. The Director of Information Security ensures IT systems and processes meet required security standards to support HIPAA and HITECH compliance. This in-person position is based on the University of New England's Portland, Maine campus and reports to ITS leadership. The Director partners closely with ITS, Research/IRB, Compliance & Privacy, Legal, HR, Finance, Academic and Student Affairs, Clinical Affairs/Health Services, Advancement, Risk, and external agencies and consortia (e.g., REN-ISAC/H-ISAC, law enforcement, regulators) to safeguard institutional data, systems, and institutional trust., Strategy, Governance and Policy * Define and maintain UNE's information security strategy, roadmap, and governance model aligned to NIST CSF/800-53 and higher-education best practices. * Develop university-wide security policies, standards, and procedures; ensure alignment with existing acceptable use and data handling and classification guidance. * Advise the VP/CIO and institutional leadership on information security risk posture, investment priorities, and incident trends. Information Security Risk Management and Compliance * Lead the enterprise information security risk register, control assessments, and remediation plans; oversee third-party and vendor security reviews for IT purchases and research and clinical tools. * Ensure IT security controls align with FERPA, HIPAA and HITECH technical safeguards, GLBA, PCI DSS, and UNE policies, partner with the HIPAA Compliance Officer for audits and incident coordination. * Prepare for and support internal and external audits; manage corrective actions and attestations related to IT security. Security Architecture and Engineering (Hands-On) * Design and implement security controls across on-prem, cloud (e.g. Microsoft 365/Azure, Box), and clinical IT systems; develop secure patterns for IAM, PAM, segmentation, encryption, logging, and backup and disaster recovery. * Operate or co-operate key platforms (e.g. SIEM, EDR/XDR, email security, WAF, CASB, vulnerability management, code scanning), including rule tuning, integrations, and automation and runbooks. Threat Detection, Incident Response and Forensics (Hands-On) * Stand up and run day-to-day monitoring, alert triage, and incident response, lead investigations, forensics, containment, recovery, and post-incident reviews. * Serve as UNE's primary security contact for external agencies (for example, state AG, FBI/InfraGard) and sector ISACs, coordinate breach notifications for IT security incidents in partnership with Compliance. Data Protection and Privacy (IT Scope Only) * Implement technical safeguards for regulated data; confirm IT practices support institutional obligations under HIPAA and HITECH, FERPA, and other frameworks. * Collaborate with Privacy and Compliance teams to embed security controls in academic systems, research, and clinical IT systems. Awareness, Training and Culture * Build and deliver targeted security awareness programs for faculty, clinicians, researchers, staff, and students; measure and improve behavior change (for example, phishing resilience campaigns). * Provide security onboarding for new systems and projects; publish concise playbooks and guidance aligned with UNE policies. Collaboration and Stakeholder Engagement * Maintain deep, proactive partnerships with ITS engineering and operations, Research, Clinical Affairs and Health Services, Compliance and Privacy, Legal, HR, Finance, Advancement, and Budget and Planning. * Participate in academic governance and research data committees; support grant and data-use reviews; advise on technology acquisitions and integrations. Liaison Responsibilities, Proactive Planning, and Cross ITS Collaboration * Serve as a primary ITS liaison to colleges and administrative units for security-related technology initiatives. * Assist institutional partners with proactive planning, including development of realistic timelines, dependencies, and coordination of delivery across teams. * Promote a culture of partnership between ITS and business units, ensuring that security considerations are co-designed with end users and stakeholders. * Provide clear, concise, and regular updates to leadership and governance groups regarding security program status, risks, issues, and decision needs. Strategy, Governance, and Continuous Improvement * Partner with ITS leadership to develop multi-year security roadmaps and annual plans that align with institutional strategy. * Support technology and data governance processes, including prioritization, information security risk management, and investment decisions related to security. * Establish and track key performance indicators for security operations, vendor performance, incident response effectiveness, and training impact using pragmatic and sustainable approaches. * Identify opportunities to streamline processes, reduce duplication, and improve the overall experience of technology services and security delivery. People Leadership and Team Development * Lead and mentor a future information security team that may include analysts, engineers, and specialists. * Set clear performance expectations, provide regular feedback, and support professional growth and development. * Promote an inclusive, collaborative, and outcomes-focused culture within the team and across ITS. * Champion modern practices in cybersecurity operations, information security risk management, and continuous learning. Additional Responsibilities * Participate in special projects and perform other duties as assigned. Supervision Exercised: The Director leads a team that may include IAM specialists, threat analysts, and security engineers. The Director is responsible for setting clear performance expectations, developing and leading operational processes and procedures, delegating responsibilities appropriately, and supporting professional growth and development. The size and composition of the team will be determined based on institutional needs, portfolio requirements, and strategic priorities. ## Related Videos - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)