Bachelor's degree or the equivalent in education and experience or a combination of relevant education, training, certifications, and work experience .
Minimum five years of relevant experience in information security or related field.
Experience working in higher education preferred.
Experience presenting complex security concepts to a variety of audiences or groups (e.g. end-user training, security conference presentations, executive-level briefings).
Familiarity with information security and data breach law, standards; and federal, state, and local regulations including PCI, FERPA, HIPAA, and NIST 800 series.
Knowledge of network and authentication protocols, encryption types, and information security technologies.
Experience with data networking, VPN, next-generation firewalls, network access controls, security information and event management (SIEM), authentication protocols, data encryption, and other relevant technologies CISSP, GIAC or similar certification(s) preferred.
Ability to work independently and as a member of a team, establish priorities, and work collaboratively as a member
Additional Information
Reporting to the chief information officer (CIO), the Information Security Officer (ISO) is responsible for the strategic and operational direction of Union's information security program. The ISO works collaboratively with campus leadership and stakeholder groups to build shared ownership of information security across the institution. The position develops and maintains programs including information security policy and standards; information security awareness and training; information security incident response and management; risk assessment and management; and information security-related information technology (IT) architecture. The ISO demonstrates a commitment to ensure that data in all forms, as well as the systems and networks used to transmit, store, and provide access to it are designed, configured, and operated in a manner that ensures security, integrity, privacy, and compliance with statutory and regulatory requirements.
Position Title: Information Security Officer
Pay Status and Classification: Exempt, Regular Full-Time
Supervisor: Chief Information Officer
Position Purpose: Reporting to the chief information officer (CIO), the Information Security Officer (ISO) is responsible for the strategic and operational direction of Union's information security program. The ISO works collaboratively with campus leadership and stakeholder groups to build shared ownership of information security across the institution. The position develops and maintains programs including information security policy and standards; information security awareness and training; information security incident response and management; risk assessment and management; and information security-related information technology (IT) architecture. The ISO demonstrates a commitment to ensure that data in all forms, as well as the systems and networks used to transmit, store, and provide access to it are designed, configured, and operated in a manner that ensures security, integrity, privacy, and compliance with statutory and regulatory requirements.
Essential Responsibilities and Duties:
Coordinate the College's information security program.
Establish and maintain information security programs in collaboration with the campus community including policy and standards.
Provide information security awareness and training; incident response and management; risk assessment and management; and relevant IT architecture to ensure the security of all sensitive data collected, processed, stored, and transmitted.
Develop and maintain the campus information security roadmap for ensuring the security of technology services, computer systems, data networks, and data.
Conduct and review ongoing vulnerability assessments of IT systems and coordinate periodic information security assessments at an organizational level.
Develop, maintain, and review security configuration data in security software and/or services.
Approve, review and audit firewall rules maintained by the network managed service vendor.
In collaboration with network managed service vendor, inspect system, network log, and event data for integrity and anomalies when necessary.
As a member of the ITS management team, participate in strategic planning and development of goals and objectives.
Collaborate with ITS staff to track and implement information security initiatives.
Facilitate the communication of policies, practices, and awareness to the College community.
Manage and coordinate incident response procedures to track and address information, system and network security incidents, alleged policy violations, and external requests or complaints.
Assist in vendor and/or product assessments to evaluate information security risks.
Perform additional duties as assigned; duties, responsibilities, and activities may change at any time with or without notice.