Director, Cybersecurity and Risk

Arizona State University

Scottsdale (AZ)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work schedule
Tuition reductions
Medical, dental, and vision insurance
401(k) with matching

Job summary

Arizona State University seeks a Director of Cybersecurity and Risk to lead security risk reduction across enterprise platforms, third-party technology, and institutional initiatives. The role partners with governance, data teams, affiliates, and vendors to implement security expectations across Microsoft 365, Azure/Entra ID, Workday, Salesforce, and other critical systems.

You will own security posture, access governance including MFA, SSO, and privileged access, and drive incident readiness,

Qualifications

  • Bachelor's degree required or equivalent experience in cybersecurity, IT risk, or related field.
  • 8+ years of information security, technology risk, or related leadership roles.
  • Experience securing, governing, or assessing enterprise SaaS and cloud platforms.
  • Experience with vendor security reviews, incident response coordination, and risk communication.

Responsibilities

  • Lead security risk reduction across systems, vendors, processes, and technology initiatives.
  • Operationalize security controls with cross-functional teams across infrastructure, identity, data, endpoints, and applications.
  • Coordinate with governance/compliance to support audits, remediation tracking, and evidence collection.
  • Develop executive-ready risk narratives, dashboards, and ongoing program reporting.

Skills

Security risk management
Security controls
Incident response
Vendor security
Identity & access governance
Data protection
Communication
Project management

Education

Bachelor's degree in cybersecurity, information technology, risk management, information systems, or a closely related field

Tools

Microsoft 365
Azure/Entra ID
Google Workspace/Cloud Identity
Workday
Salesforce

Job description

Director, Cybersecurity and RiskSkip to main content#Director, Cybersecurity and Risk page is loaded## Director, Cybersecurity and RiskApplylocations: Scottsdale, AZtime type: Full timeposted on: Posted 2 Days Agojob requisition id: R1485# **Director, Cybersecurity and Risk**The Director, Cybersecurity and Risk leads ASU Enterprise Partners’ security risk reduction efforts across enterprise platforms, third-party technology, and institutional initiatives. Serving as the senior security and risk leader within Technology & Solutions, this role partners with Data Governance, OGC, systems and data teams, affiliates, and vendors to implement security expectations consistently across Microsoft, Google, Workday, Salesforce, and other critical systems. The position focuses on practical risk reduction, secure configuration, access governance, control maturity, data protection, and incident preparedness in close partnership with operational technology owners.## **What you’ll do*** **Security Risk and Control Leadership** + Lead security risk reduction efforts across systems, vendors, processes, and technology initiatives. + Implement and operationalize security controls in partnership with infrastructure, identity, endpoint, data, application, and business teams. + Partner with governance and compliance stakeholders to support security control alignment, audit readiness, remediation tracking, and evidence collection. + Track security remediation efforts, identify owners, communicate status, and escalate unresolved risks through appropriate governance or leadership channels. + Translate security risks, technical issues, and control gaps into clear business impact for technical and non-technical audiences. + Develop, update, and maintain security procedures, standards, implementation guidance, and operational documentation in collaboration with governance/compliance stakeholders.* **Enterprise Platform Security and Access Governance** + Own and mature the security posture of enterprise SaaS and cloud platforms, including Microsoft 365, Azure/Entra ID, Google Workspace/Cloud, Workday, Salesforce, and other business-critical applications. + Lead security oversight of identity and access controls, including MFA, conditional access, SSO, SAML, OAuth, privileged access, role-based access, service accounts, access reviews, and joiner/mover/leaver security processes. + Establish and maintain secure configuration standards and review processes for enterprise platforms, including tenant hardening, administrative role governance, external sharing controls, audit logging, data protection settings, and integration/API security. + Partner with platform, infrastructure, identity, endpoint, cloud, SaaS, data, and application teams to implement security controls consistently across environments. + Participate in design reviews, access reviews, release readiness conversations, and control reviews where security or risk considerations are relevant.* **Data Protection, Monitoring, and Incident Readiness** + Partner with data owners and platform teams to implement data protection controls, including data classification, DLP, secure sharing, access monitoring, retention-aligned safeguards, and protection of constituent, employee, financial, and business-sensitive information. + Define security logging, monitoring, alerting, and evidence requirements for enterprise platforms and partner with operational teams to ensure appropriate detection and response capabilities are in place. + Support the maintenance of information flow documentation, risk documentation, and safeguards for organizational, subsidiary, university, donor, prospect, and business-sensitive information. + Support incident response from a security risk and operational readiness perspective, including response plan maintenance, tabletop participation, documentation, escalation, and post-incident improvement. + Coordinate with Technology & Solutions, governance/compliance, legal, communications, business units, vendors, and leadership during security incidents as appropriate.* **Vendor, Third-Party, and Security Advisory Support** + Manage the vendor security review process, including security questionnaires, vendor documentation review, risk identification, and mitigation recommendations. + Partner with legal, finance, governance, and compliance stakeholders on vendor security requirements, contract considerations, data protection expectations, and remediation commitments. + Lead security architecture and risk reviews for major technology purchases, integrations, platform changes, data initiatives, SaaS implementations, and business process changes, ensuring risks are documented, mitigated, or escalated through appropriate channels. + Engage with business units to understand new initiatives, identify security risks, and recommend practical mitigation strategies. + Lead and actively participate in projects related to information security, security awareness, continuity planning, IT policies, control improvement, and risk mitigation.* **Leadership, Reporting, and Program Execution** + Develop security risk metrics, executive-ready reporting, remediation dashboards, and maturity updates that communicate control effectiveness, risk exposure, and progress against security priorities. + Lead and manage assigned security or risk-focused staff, including hiring, coaching, mentoring, prioritization, performance development, training, and accountability. + Clearly articulate deliverables, objectives, results, outcomes, milestones, and timelines for security and risk initiatives. + Represent Technology & Solutions and ASU Enterprise Partners professionally in discussions involving security, technology risk, vendor security, and institutional trust.## **What you'll need*** Strong understanding of security risk management, security controls, incident response readiness, vendor security, identity and access governance, data protection, and modern enterprise technology environments.* Ability to evaluate information security risk for new initiatives and recommend practical mitigation strategies.* Ability to define secure configuration expectations, access control requirements, monitoring needs, and remediation plans for enterprise platforms.* Working knowledge of Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, identity and access management, endpoint protection, SaaS governance, cloud security concepts, and data protection practices.* Ability to maintain a high degree of confidentiality and responsibility regarding information related to Enterprise Partners, its affiliates, university business, confidential constituent information, employee information, financial information, and other sensitive data.* Ability to communicate effectively and clearly with both technical and non-technical individuals, including executive, legal/procurement, governance/compliance, business, and vendor stakeholders.* Strong project management, reporting, documentation, and stakeholder communication skills.* Ability to develop executive-ready summaries, remediation dashboards, risk narratives, procedures, standards, and implementation guidance.* Ability to work both independently and as part of a team.* Team-oriented strategist able to effectively manage complex situations involving numerous and sometimes competing constituencies.* Applies strong knowledge of process and quality improvement.* Supports planning and management of security-related budgets, vendor spend, and resource needs.* Ability to represent the institution well.* Commitment to ASU Enterprise Partners' mission and ASU's vision as the New American University.* Attention to detail and thoroughness in completing assigned duties.* Highly organized and able to handle multiple projects.* Adept at navigating complex environments with evolving priorities and communication plans.## **Relevant qualifications*** Bachelor's degree in cybersecurity, information technology, risk management, information systems, or a closely related field, or an equivalent combination of education and experience.* At least eight (8) years’ experience in information security, technology risk, security operations, IT risk management, or related technology leadership roles.* At least four (4) years’ experience managing employees in a technical environment* Experience securing, governing, or assessing enterprise SaaS and cloud platforms such as Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, or comparable enterprise platforms.* Experience with identity and access management, access governance, privileged access, secure configuration, tenant hardening, data protection, or SaaS governance.* Experience working cross-functionally with technology, data, legal/procurement, governance/compliance, business, and vendor stakeholders.* Experience implementing security controls, managing remediation efforts, conducting security reviews, or supporting audit/evidence activities.* Experience with vendor security reviews, incident response coordination, and security risk communication.* OR any equivalent combination of experience and/or education from which comparable knowledge, skills, and abilities have been achieved## **Preferred education and experience*** Advanced degree in cybersecurity, information systems, risk management, business, privacy, or a related field.* Experience in higher education, nonprofit, SaaS/cloud, privacy-sensitive, financial, fundraising, or regulated environments.* Experience supporting SOC 2, NIST CSF, CIS Controls, internal controls, external assessments, or audit evidence activities.* Experience developing security procedures, security standards, control implementation guidance, risk summaries, or stakeholder-facing security materials.* Experience defining security monitoring/logging requirements.* Experience coordinating access recertifications, privileged access reviews, service account reviews, platform hardening initiatives, or SaaS security posture assessments.## **Preferred skills and abilities*** Relevant certifications such as CISSP, CISM, CISA, CRISC, Security+, Microsoft Security, Azure Security, Google Cloud Security, or similar security/risk credentials.* Willingness to complete relevant Microsoft, Google, cloud security, security operations, or risk-related certifications as appropriate to the role.**Benefits*** Hybrid work schedule. We work from home two days a week!* Comprehensive benefits package, including medical, dental, and vision insurance* 401(k) plan with matching employer contribution* 22 days of vacation time* 11 holidays, including your birthday* Parental leave* Significant tuition reductions* Professional development is highly valued at ASU Enterprise Partners, where employees are encouraged to look across the organization and nurture new areas of interest* $30 bi-weekly cell phone reimbursement
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director, Technology Operations & Service Excellence
Senior Director, Technology Operations & Service Excellence

Arizona State University • Scottsdale (AZ), Northern (KY)

Hybrid
USD 180,000 - 240,000
Hybrid work schedule
Medical, dental, vision insurance
401(k) with matching
+6
Associate Vice President, Finance
Associate Vice President, Finance

Arizona State University • Scottsdale (AZ)

Hybrid
USD 180,000 - 280,000
Hybrid work schedule
Tuition reductions
Medical, dental, vision insurance
Specialist, AI Enablement
Specialist, AI Enablement

Arizona State University • Scottsdale (AZ)

On-site
USD 60,000 - 80,000
Hybrid work schedule
Comprehensive benefits package
401(k) with employer matching
+3
Student Assistant - Data Science
Student Assistant - Data Science

Arizona State University • Scottsdale (AZ)

Hybrid
USD 16,000 - 22,000
Cell phone reimbursement
Professional development
LinkedIn Learning
+1
Senior Director, Technology Operations & Service Excellence
Senior Director, Technology Operations & Service Excellence

ASU Enterprise Partners • Scottsdale (AZ)

On-site
USD 180,000 - 260,000
Hybrid work schedule
Medical, dental, and vision insurance
401(k) plan with matching
+6
Senior Cybersecurity & Risk Leader
Senior Cybersecurity & Risk Leader

Arizona State University • Scottsdale (AZ)

On-site
USD 140,000 - 190,000
Hybrid work schedule
Tuition reductions
Medical, dental, and vision insurance
+1
Associate Director of Project Management
Associate Director of Project Management

Arizona-State-University • Scottsdale (AZ)

Hybrid
USD 100,000 - 115,000
Healthcare
Retirement
Tuition Reduction
+1
Senior Director Information Security
Senior Director Information Security

EverCommerce • Denver (CO)

Hybrid
USD 180,000 - 240,000
Wellness stipend
Udemy training
401k with company match
+2
LMS Tier 2 Admin
LMS Tier 2 Admin

Arizona-State-University • Tempe (AZ)

On-site
USD 42,000 - 58,000
Senior Microsoft Security Engineer
Senior Microsoft Security Engineer

University of Maryland Global Campus • Adelphi (MD)

On-site
USD 90,000 - 120,000
Tuition remission for staff and dependents after two years
Inclusive working environment
Employee accommodations available