Chief Information Security Officer (Ciso)

Montclair State University Montclair , NJ 07042

Posted 2 weeks ago

IMPORTANT APPLICATION INSTRUCTIONS:

  • Upload Resume or Curriculum Vitae for automatic population of information to the application.

  • The contact information, work experience, and education listed on your Resume/CV will be parsed and input into your Montclair application.

  • Review information and double-check all fields containing information that the system parsed - the software is intelligent, but you need to verify that the data is accurate.

  • In the "My Experience" section, you will find a Resume/CV upload option where you can submit your cover letter and all other supporting documents.

Note: If you have an expansive CV, we recommend that you apply manually and only include the positions you have held in the last ten (10) years. You will then be able to attach your Resume/CV, as well as all other supporting documentation in the "My Experience" section of your application.

Job Description

SUMMARY:

Reporting to the Vice President and CIO of Information Technology, the Chief Information Security Officer (CISO) is a member of the Information Technology (IT) leadership team and works closely with senior administration, academic leaders, and the campus community. The CISO is the lead advocate for the institution's information and cyber security needs and is responsible for the development and oversight of a comprehensive information security strategy intended to protect information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction and to provide confidentiality, integrity, and availability.

As a member of the IT leadership team the CISO leads the development, implementation and oversight of an information and cyber security program to protect campus-wide resources, facilitates information security governance, advises senior leadership on security matters and resource investments, and writes appropriate policies to manage information security risk. The CISO is responsible for recommending and coordinating the planning, implementation, enforcement, and troubleshooting activities that ensure the security and integrity of the University's overall information systems and data assets. The complexity of this position requires a leadership approach that is engaging, imaginative, and collaborative, with a sophisticated ability to work with University systems and campus leaders to optimize the information security posture of the University.

This position directly manages a team of information and cyber security staff and also has authority to create ad hoc working groups among other central and distributed IT staff as needed to ensure that the University's overall computing and network policies, procedures, and infrastructure design adhere to information security best practice principles. The CISO is a visible/communicative leader on campus, and off-campus by representing Montclair to the global higher education community.

PRINCIPAL DUTIES AND RESPONSIBILITIES:

University and Program Leadership

  • Provide guidance and counsel to the CIO and key members of the University leadership team regarding information security and privacy issues, risks, mitigation strategies and information security governance.

  • Develop a comprehensive information security program with annual and long-range security and compliance goals, metrics, reporting mechanisms and program services.

  • Develop and lead outreach, communication, and user education efforts to promote campus-wide information and cyber security awareness.

  • Collaborate with IT leadership on incorporating information security throughout the technology life cycle, risk management and audit compliance to provide adequate protections for campus hosted information resources.

  • Build positive relationships and foster goodwill towards efforts to improve overall security posture.

  • Review hardware, software, and services being considered for purchase or implementation by IT or other campus departments to assess potential security risks and ensure proper information security features are incorporated to address university requirements.

  • Maintain integrity and appropriate confidentiality of information security related matters.

  • Provide supervision for team resources, as well as budget development and management as needed.

Policy, Compliance and Audit

  • Develop, implement and oversee policies, standards and processes.

  • Serve as the University's primary point of contact in all audit, compliance, insurance, or legal matters related to information security.

  • Keep abreast of changes to the State, Federal, and industry regulations that can impact University operations such as HIPAA, PCI-DSS, EUGDPR, FERPA, Red Flags, and Gramm-Leach-Bliley. Make recommendations for changes or additions to university policies, procedures, or technology infrastructure to support compliance with these regulations from an information security perspective.

  • Create ad-hoc functional teams from among the various central and distributed IT units to research, recommend, and deploy new information security technologies or to implement changes to existing policies and procedures.

Risk Management and Incident response

  • Oversee IT security risk assessment processes. Coordinates annual or periodic information security risk assessment reviews as necessary or required for institutional auditing purposes.

  • Develop a roadmap to reduce high risks and sustain a well-controlled environment to protect information assets.

  • Oversee information security incident response, serving as incident coordinator and forming ad hoc incident response teams as necessary to respond to and recover from potential security incidents or data breaches.

  • Develop and lead new information security initiatives.

  • Communicate and coordinate with the Chief Information Officer and other campus leadership as appropriate during incident response activities. Escalate incidents, when appropriate, to executive team for determination of information security breach and notification.

  • Coordinate contracted relationships with external security service providers for a variety of needs including digital forensics investigations, e-Discovery, or other sensitive data analysis as requested by IT management, Legal Counsel, Human Resources, or appropriate University officials.

Outreach, Education and Training

  • Provide leadership in identifying, developing, implementing and maintaining information security awareness, as well as general and specialized training programs for the University.

  • Recruit, hire, train and mentor the Information Security staff and implement professional development plans for all members of the team as needed.

  • Oversee security operations related activities and manage the relationship with the MDR partner (Red Canary) including monthly review of reports and vulnerability mitigation strategies in the broader landscape.

QUALIFICATIONS:

REQUIRED:

  • A Bachelor's degree from an accredited college or university in a relevant information technology field.

  • A minimum of fifteen (15) years of progressively responsible IT experience with a minimum of ten (10) years of managerial experience.

  • Professional experience designing, implementing, and/or managing information security policies, procedures, and solutions.

  • Broad knowledge of computer security issues, requirements, and trends.

  • Strong interpersonal and communication skills, plus the ability to achieve goals through influence, collaboration and cooperation.

  • Demonstrated ability to work effectively with an array of constituencies in a community that is both demographically and technologically diverse.

  • Experience providing education and training programs on security policies and practices to a range of technical and non-technical constituents.

  • Experience evaluating and providing guidance on the information security elements of software and hardware acquisitions, IT services, cloud-based solutions, mobility, and other present and emerging aspects of IT solutions and services in a complex environment.

  • Referenceable integrity and high standards of personal and professional conduct.

PREFERRED:

  • Cyber security industry certifications from an established organization such as SANS.

  • A post-Baccalaureate degree or other relevant formal education.

  • Over ten years of experience in a higher education IT environment.

  • Ability to explain highly technical topics in terms that can be understood by a less technical audience.

  • Strong organizational skills and a successful track record of effective coordination, prioritization, collaboration, and project delivery.

  • An understanding of current legislation and regulations pertaining to higher education institutions (i.e. HIPAA, PCI-DSS, EUGDPR, FERPA, Red Flags, and Gramm-Leach-Bliley.)

  • Is professionally active by presenting at conferences and/or publishing/contributing to timely Information Security articles.

PROCEDURE FOR CANDIDACY

Applicants should include a resume and cover letter describing how their background, skills and education match the needs of the University. When applying, please take a moment to carefully read and follow the steps in the application instructions.

Department

Enterprise Technology Services

Position Type

Administrative

Contact Information:

For questions or concerns, please contact Human Resources' Workday Recruiting Support at 973-655-5000 (Option 2), or email talent@montclair.edu.

EEO/AA Statement

Montclair State University is an Equal Opportunity/Affirmative Action institution with a strong commitment to diversity.

Additional information can be found on the website at

www.montclair.edu/human-resources/about-us/eo-aa-and-diversity/

Title IX and 34 C.F.R. 106 Policy

Montclair State is required by Title IX and 34 C.F.R. 106 not to discriminate on the basis of sex or gender, and does not discriminate on the basis of sex or gender in the operation of education programs and activities. The requirement to not discriminate on the basis of sex or gender in the operation of education programs and activities extends to admission and employment. For further details, please visit: https://www.montclair.edu/human-resources/job-seekers/


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Deputy Chief Information Security Officer (Ciso)

Wayne State University

Posted 3 days ago

VIEW JOBS 6/27/2024 12:00:00 AM 2024-09-25T00:00 Deputy Chief Information Security Officer (CISO) Wayne State University is searching for an experienced Deputy Chief Information Security Officer (CISO) at it Wayne State University Detroit MI

Chief Information Security Officer (Ciso)

Montclair State University