Position Summary
Assistant Director, Information Security Operations
Lead the strategic and tactical planning, implementation, and continuous monitoring of the information security program and technical compliance for all clinical and administrative technology services at the Student Health Center (Washington Square, Brooklyn, and select global sites). Acting as the primary technical authority and subject matter expert, this role defines, develops, maintains, and implements policies, security architectures, and operational processes that enforce rigorous cybersecurity standards. Drive a culture of security awareness to minimize risk and ensure the confidentiality, integrity, and availability of sensitive information (including ePHI) owned, controlled, and processed within the Student Health Center, working in close partnership with central NYU Information Technology Services.
Responsibilities
- Lead the planning, implementation, and ongoing monitoring of information security programs and technical compliance for clinical and administrative technology services.
- Define and maintain policies, security architectures, and operational processes that enforce cybersecurity standards.
- Promote security awareness to minimize risk and protect sensitive information across the organization.
- Collaborate with NYU Information Technology Services to align security initiatives with enterprise IT strategy.
Qualifications
Required Education
Bachelor's Degree in information technology, information systems, computer science, cybersecurity or relevant field.
Preferred Education
Master's Degree in information technology, information systems, computer science, cybersecurity or a relevant field.
Required Experience
- 7+ years of relevant professional level experience or equivalent combination.
- Experience managing information security operations, incident response, and risk management programs within a complex or regulated environment.
- Demonstrated experience with security toolsets (e.g., SIEM, DLP, vulnerability management), identity and access management solutions, and cloud-based technology platforms (e.g., Amazon/AWS VPC, other cloud services, Citrix Workspace).
- Budget projections, team leadership, building client relations, planning, developing, and implementing security policies, procedures, and projects; and supervising staff.
- Ability to communicate complex technical and security information effectively to non-technical staff, management, and leadership.
Preferred Experience
- 10+ years of overall relevant experience in an information security or technology capacity.
- Experience in a management position within health care delivery or higher education; leading cybersecurity, risk management, or compliance programs.
- Securing clinical systems and web applications; working in complex Windows and network environments; deploying modern identity, endpoint, and cloud-based security products (e.g., Entra, Intune, Workspace ONE, AWS).
- Advanced experience with vendor risk assessments, incident response, and adherence to regulatory frameworks (e.g., HIPAA, FERPA).
- 5+ years of previous management experience with increasing responsibility and scope.
Required Skills, Knowledge and Abilities
- Excellent analytical, organizational, communication, interpersonal, problem-solving and time management skills.
- Ability to develop creative security solutions and communicate them to both technical staff and clinical leadership.
- Ability to integrate rigorous security controls, risk management, and compliance requirements (e.g., HIPAA) across departments.
- Deep knowledge of cybersecurity frameworks, network security architecture, incident response, IAM, and emerging threat landscapes.
- Extensive knowledge of the information security field and aligning operations with the health center’s strategic goals.
- Skill in managing SIEM and IT service management systems; strong judgment and decision-making under pressure; solid project management skills.
Preferred Skills, Knowledge and Abilities
- Certification as CISSP.
- Programming skills in SQL, Python, and Powershell.
Additional Information
- In compliance with NYC's Pay Transparency Act, the annual base salary range for this position is USD $130,000.00 to USD $170,000.00.
- New York University considers factors such as scope and responsibilities, candidate experience, education/training, key skills, internal equity, market and organizational considerations when extending an offer. This pay range represents base pay only and excludes additional items such as incentives or bonuses.
- NYU aims to be among the greenest urban campuses in the country and carbon neutral by 2040. Learn more at nyu.edu/nyugreen.
- NYU is an Equal Opportunity Employer and is committed to a policy of equal treatment and opportunity in every aspect of its recruitment and hiring process.