Executive Director of Cybersecurity and Privacy

Charlotte-Mecklenburg Schools
Charlotte, NC, United States
12 days ago
Apply on api.schoolspring.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Cyber Security Identity and Access Management Information Technology Security Auditing Security Information and Event Management Vulnerability Analysis

Job description

The executive director of cybersecurity and privacy, under minimal supervision, performs senior-level work with extensive decision-making discretion applying advanced subject matter knowledge and operational oversight of the district’s cybersecurity program and data privacy operations. Position develops, implements, and monitors security policies, procedures and controls; and ensures compliance with applicable laws, regulations, and industry standards. Oversees identity and access management, incident response, cybersecurity technologies, risk assessments, audits, and data privacy reviews to protect district information assets and systems. Employee performs advanced and supervisory work to carry out the Board of Education policies and procedures under the direction of the Cybersecurity Officer., * Adhere to all state, federal, and local laws, policies, and procedures

  • Adhere to all state, federal, and local laws, policies, and procedures
  • Lead, manage, supervise, and evaluate assigned programs/staff in the district
  • Collaborate on and support cybersecurity strategic planning, policy development, incident response planning, and threat and risk analysis
  • Oversee identity and access management security across the district’s identity platforms, including security monitoring and incident response, conditional access and privileged access controls, risk-based authentication, and account and session security
  • Conduct vendor data-privacy reviews and ed-tech application vetting to ensure compliance with student data privacy laws and district privacy standards
  • Investigate, analyze, and formulate methods for handling special projects and reports
  • Partner with the Cybersecurity Officer to develop and maintain district-wide cybersecurity policies, standards, and procedures aligned with Board policy and industry frameworks (e.g., NIST CSF)
  • Direct day-to-day execution of the district’s cybersecurity incident response plans and playbooks, including investigation, containment, remediation, and reporting
  • Oversee the day-to-day evaluation, piloting, and implementation of cybersecurity products and technologies (e.g., SIEM/SOAR, endpoint detection and response) identified through strategic planning
  • Oversee required cybersecurity audits, vulnerability assessments, and compliance reviews, including security control documentation and remediation tracking
  • Coordinate with other departments on disaster and contingency emergency management planning
  • Ensure adherence to security, privacy, and intellectual property laws across the cybersecurity program
  • Participate in the development and administration of the department budget
  • Oversee creation and maintenance of standard operating procedures, best practices, and playbooks across cybersecurity and privacy functions
  • Facilitate/participate in professional development and related meetings
  • Complete local, state, or federal surveys and reports accurately and promptly, including cybersecurity compliance reporting
  • Create an inclusive environment with positive communication/public relations
  • Perform related work as assigned or required

Requirements

To perform this job successfully, an individual must be able to perform each essential function satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions., * Comprehensive in-depth knowledge of cybersecurity principles, frameworks, threats, and best practices, and their application to incident response, risk management, and policy development

  • Comprehensive knowledge of enterprise IT infrastructure and identity and access management security controls sufficient to oversee day-to-day cybersecurity operations
  • Comprehensive knowledge of vendor data-privacy review and ed-tech application vetting, including compliance with student data privacy laws
  • Skilled in SIEM/SOAR technologies, incident response, and security audit and compliance processes
  • Ability to serve as a thought partner and subject matter expert to the Cybersecurity Officer on strategy, policy, and incident response planning, and to translate direction into day-to-day execution for cybersecurity office staff
  • Skilled in evaluating, selecting, and implementing cybersecurity and identity security technologies aligned with district goals
  • Ability to supervise cybersecurity office staff, manage a departmental budget, and ensure compliance with applicable laws and regulations
  • Strong judgment, problem-solving, and decision-making skills; ability to work independently under pressure
  • Effective communication and relationship-building skills, with the ability to maintain confidentiality and evaluate program effectiveness

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on api.schoolspring.com
Prepare application

Good distractions

Loading talks and stories from around this role…