Director of Information Security

HOLMES STUDENT CTR GUEST ROOM
United States
16 days ago
Apply on employment.niu.edu
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$155,069.0
Working hours
Shift work

Tech stack

Software System Penetration Testing Cyber Security Information Systems Intrusion Detection and Prevention PCI Data Security Standards Security Information and Event Management Software Vulnerability Management Cloud Platform System Data Classification Cyber Threat Analysis Firewalls (Computer Science) Information Technology

Job description

The Director of Information Security plays a pivotal leadership role in safeguarding the confidentiality, integrity, and availability of university data, systems, and technology resources. This position is responsible for ensuring that the university’s information security program remains aligned with institutional priorities while adapting to an evolving threat landscape. Working collaboratively with the Information Security team, central and distributed IT teams, and key business units across the university, the Director provides strategic direction and operational oversight for the day-to-day execution of the information security program. The Director partners with Internal Audit, the Office of General Counsel, the Office of Ethics and Compliance, the Director of Privacy, and other university stakeholders to develop and implement security policies, standards, and procedures; conduct risk assessments; strengthen security awareness and compliance efforts; and lead the university’s response to security incidents and emerging cyber threats. Position Summary The Director of Information Security has direct management responsibility for the Information Security Office (ISO), Account Access, Business Continuity and IT Disaster Planning (BCDP) and IT physical security. Account Access, BCDP, ISO and IT Physical Security combine to represent a comprehensive umbrella of IT related security services and includes oversight and coordination of the NIU Information Security Policy and enforcement of the NIU Acceptable Use Policy and the Security Access Policy.

The functional aspects of these high level activities include: coordination with internal and external enforcement authorities as relates to IT criminal investigation activities, coordinating response to copyright infringement notices, coordination of data breach responses, directing internal IT forensic analyses for administrative purposes, assessing and responding to IT related threats, providing proactive education and awareness notification as relates to information protection, immediate IT threat response and interfacing with end-users who are not in compliance with applicable University policy.

Additionally, this position is responsible for informing and coordinating with distributed Lan-Administrators and is the point-of-contact for external auditor response regarding IT security related issues. This position is the published designee for University representation as the Digital Millennium Copyright Act and lnternet Abuse I security contact. Generally speaking, the incumbent performs duties and is responsible for issues that are consistent with the role of a Chief IT Security Officer.

Given the breadth of responsibility and accountability associated with leading the university’s information security program, this position requires a high degree of judgment, responsiveness, and availability, including the ability to address critical incidents and emerging issues outside of normal business hours., Managing Security Compliance Programs

  • Map security controls to systems based on data classification, regulatory requirements, and risk profile.
  • Ensure compliance with security regulations such as HIPAA, GLBA, and PCI DSS.
  • Work with Privacy, Ethics, and Risk Management to ensure appropriate controls are in place to meet privacy regulations.
  • Ensure vendor security management program is developed and maintained including participating in contract reviews
  • Ensure academic research follows required security controls.
  • Ensure that inventory and asset management practices adhere to security configuration and vulnerability management policies and procedures.
  • Develop and implement security awareness training for university employees and students.
  • Wins support for information security techniques even among those who are resistant.
  • Finds ways to spread good practices, both through formal and informal means.
  • Develop and manage budgets, Service Level Agreements, Reporting, Key Performance Indicators, and Critical Success Factors.
  • Serve as the primary manager of the vendor review program/process.
  • Understand SOC 2 reports (or other third-party security review documents) and how to work with the lines of business on issues.
  • Manage and mentor security analysts on the vendor review program/process.

Develop & Implement Security Policies & Procedures

  • Work with key stakeholders across the university to develop and maintain security policies and procedures that are aligned with the university’s goals while providing sufficient security to meet the organizations risk appetite
  • Review and update security policies and procedures on a regular basis to ensure they remain effective and relevant.
  • Ensure that security policies and procedures are communicated to all university employees, students, and third-party vendors. and objectives.
  • Work with other departments to ensure that security policies and procedures are understood and followed, and that compliance is documented and measured.
  • Implement processes to ensure that policies and procedures are reviewed and updated on a regular basis.

Conduct Risk Assessments & Penetration Testing

  • Participate in security industry groups, professional security organizations, and vendors to stay informed about emerging threats, vulnerabilities, and trends.
  • Identify potential risks and vulnerabilities to the university’s data and systems through regular risk assessments and vulnerability testing.
  • Analyze the results of risk assessments and vulnerability testing to develop and implement strategies to mitigate risks and vulnerabilities.
  • Develop, maintain, and implement a risk management plan that identifies critical systems and data, and establishes appropriate security controls.
  • Work with IT and business units to remediate identified vulnerabilities and risks.

Manage Security Incidents & Responses

  • Manage the response to security incidents and threats.
  • Coordinate with other departments as needed to resolve security incidents.
  • Develop and maintain incident response plans.
  • Develop and conduct tabletop exercises.
  • Conduct post-incident reviews to identify opportunities for process improvements and to refine incident response procedures.
  • Ensure disaster recovery plans are maintained and tested.
  • When appropriate, collaborate with NIU police, Office of General Counsel, the office Ethics and Compliance, Enterprise Risk, Internal Audit, and other offices as necessary in completing internal investigations and responding to external law enforcement.

Respond to Security Audits & Assessments

  • Respond to security audits and assessments from regulatory bodies or other external entities.
  • Coordinate with key stakeholders across the university to respond to audit requests and address any findings from security audits and assessments.
  • Develop and implement plans to address any gaps in security compliance that are identified through audits, assessments, or notifications.

Other Related Duties

  • Perform other related duties as assigned., In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. ADA Accommodation NIU remains committed to ensuring that its recruitment and application procedures include full opportunities for applicants with disabilities. Employment opportunities will not be denied to anyone because of the need to make accommodations for a person’s disability during either the application or interview process. An applicant who believes they require an accommodation to participate in the employment process due to a disability may request that accommodation through the Accommodation Request Form. For further assistance, please contact the office of Affirmative Action and Equal Opportunity (AAEO) at ada@niu.edu. Safety Information NIU provides annual reports on campus security and fire safety. Read the Annual Security and Fire Safety Report. Contact the Ethics and Compliance Office at 815-753-9364 for a hard copy.

Applicant Documents

Required Documents

  1. Resume/Curriculum Vitae
  2. Cover Letter
  3. List of at least 3 Professional References

Optional Documents

  1. Transcripts (unofficial with official required at hire)
  2. Other

Requirements

Knowledge, Skills, and Abilities (KSAs) (Civil Service), + Master’s degree in Computer Science, Information Systems, or a related field and two (2) years of work experience in information security or related field.

  • Bachelor’s degree in Computer Science, Information Systems, or a related field and six (6) years of work experience in information security or related field.
  • Associate’s degree in Computer Science, Information Systems, or a related field and seven (7) years of work experience in information security or related field.
  • At least nine (9) years of work experience in information security or related field. 2. At least three (3) years of supervisory experience.

Additional Requirements (SPS)

  1. Knowledge of security standards and risk management frameworks such as CIS, NIST, and others.
  2. Strong knowledge of security technologies, including common security tools, endpoint detection and response, SIEM, firewalls, intrusion detection and prevention systems, encryption, and others.
  3. Broad knowledge of IT infrastructure, operating systems, and cloud systems.
  4. Knowledge of the systems and operations used within the areas and departments of responsibility.
  5. Excellent verbal and written communication skills.
  6. Ability to oversee and coordinate activities of assigned staff.
  7. Ability to effectively communicate with other colleagues, supervisors, administrative staff, and other campus/agency units.
  8. Ability to identify and resolve technical and personnel problems.
  9. Ability to effectively communicate and professionally interact with all staff levels.

Preferred Qualifications (SPS)

  • At least seven (7) years of experience in information security, with three (3) years in a leadership role
  • Professional certifications such as CISSP, CISM, or other relevant security certifications are preferred.
  • Excellent leadership, communication, and analytical skills.
  • Experience with security compliance regulations such as HIPAA, GLBA, PCI DSS, and others.

Physical demands/requirements

  • Sitting for extended periods of time
  • Using computer/electronic equipment for extended periods of time
  • Occasional lifting and moving items weighing up to 40 lbs.

About the company

Northern Illinois University (NIU) is a world-class, research-focused public institution that attracts students from across Illinois, the country and the world and currently serves more than 16,000 students. NIU’s vision is to be an engine for innovation to advance social mobility; promote personal, professional and intellectual growth; and transform the world through research, artistry, teaching and outreach. Our mission is to empower students through educational excellence and experiential learning as we pursue knowledge, share our research and artistry, and engage communities for the benefit of the region, state, nation and world., In accordance with applicable statutes and regulations, NIU is an equal opportunity employer and does not discriminate on the basis of race, ethnicity, color, national origin, ancestry, sex, religion, age, disability (physical and mental), marital status, veteran status, sexual orientation, gender (identity and expression), political affiliation, or any other factor unrelated to professional qualifications, and will comply with all applicable federal and state statutes, regulations and orders pertaining to nondiscrimination, equal opportunity and affirmative action.

The following person has been designated to handle inquiries regarding the non-discrimination policies

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on employment.niu.edu
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

6:33 min

Integrating generative workflows for data classification and extraction

Christian Liebel Christian Liebel · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all