Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
ASU Enterprise Partners is seeking a Director of Cybersecurity and Risk to lead security risk reduction across enterprise platforms and third-party technology. You will partner with Data Governance, OGC, and vendors to implement security controls in Microsoft, Google, Workday, Salesforce, and other critical systems.
The role emphasizes practical risk reduction, secure configuration, access governance, incident preparedness, and program execution across the organization and its affiliates.
The Director, Cybersecurity and Risk leads ASU Enterprise Partners’ security risk reduction efforts across enterprise platforms, third-party technology, and institutional initiatives. Serving as the senior security and risk leader within Technology & Solutions, this role partners with Data Governance, OGC, systems and data teams, affiliates, and vendors to implement security expectations consistently across Microsoft, Google, Workday, Salesforce, and other critical systems. The position focuses on practical risk reduction, secure configuration, access governance, control maturity, data protection, and incident preparedness in close partnership with operational technology owners.
Security Risk and Control Leadership
Enterprise Platform Security and Access Governance
Data Protection, Monitoring, and Incident Readiness
Vendor, Third-Party, and Security Advisory Support
Leadership, Reporting, and Program Execution
Strong understanding of security risk management, security controls, incident response readiness, vendor security, identity and access governance, data protection, and modern enterprise technology environments.
Ability to evaluate information security risk for new initiatives and recommend practical mitigation strategies.
Ability to define secure configuration expectations, access control requirements, monitoring needs, and remediation plans for enterprise platforms.
Working knowledge of Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, identity and access management, endpoint protection, SaaS governance, cloud security concepts, and data protection practices.
Ability to maintain a high degree of confidentiality and responsibility regarding information related to Enterprise Partners, its affiliates, university business, confidential constituent information, employee information, financial information, and other sensitive data.
Ability to communicate effectively and clearly with both technical and non-technical individuals, including executive, legal/procurement, governance/compliance, business, and vendor stakeholders.
Strong project management, reporting, documentation, and stakeholder communication skills.
Ability to develop executive-ready summaries, remediation dashboards, risk narratives, procedures, standards, and implementation guidance.
Ability to work both independently and as part of a team.
Team-oriented strategist able to effectively manage complex situations involving numerous and sometimes competing constituencies.
Applies strong knowledge of process and quality improvement.
Supports planning and management of security-related budgets, vendor spend, and resource needs.
Ability to represent the institution well.
Commitment to ASU Enterprise Partners’ mission and ASU’s vision as the New American University.
Attention to detail and thoroughness in completing assigned duties.
Highly organized and able to handle multiple projects.
Adept at navigating complex environments with evolving priorities and communication plans.
Bachelor’s degree in cybersecurity, information technology, risk management, information systems, or a closely related field, or an equivalent combination of education and experience.
At least eight (8) years’ experience in information security, technology risk, security operations, IT risk management, or related technology leadership roles.
At least four (4) years’ experience managing employees in a technical environment
Experience securing, governing, or assessing enterprise SaaS and cloud platforms such as Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, or comparable enterprise platforms.
Experience with identity and access management, access governance, privileged access, secure configuration, tenant hardening, data protection, or SaaS governance.
Experience working cross-functionally with technology, data, legal/procurement, governance/compliance, business, and vendor stakeholders.
Experience implementing security controls, managing remediation efforts, conducting security reviews, or supporting audit/evidence activities.
Experience with vendor security reviews, incident response coordination, and security risk communication.
OR any equivalent combination of experience and/or education from which comparable knowledge, skills, and abilities have been achieved
Advanced degree in cybersecurity, information systems, risk management, business, privacy, or a related field.
Experience in higher education, nonprofit, SaaS/cloud, privacy-sensitive, financial, fundraising, or regulated environments.
Experience supporting SOC 2, NIST CSF, CIS Controls, internal controls, external assessments, or audit evidence activities.
Experience developing security procedures, security standards, control implementation guidance, risk summaries, or stakeholder-facing security materials.
Experience defining security monitoring/logging requirements.
Experience coordinating access recertifications, privileged access reviews, service account reviews, platform hardening initiatives, or SaaS security posture assessments.
Relevant certifications such as CISSP, CISM, CISA, CRISC, Security+, Microsoft Security, Azure Security, Google Cloud Security, or similar security/risk credentials.
Willingness to complete relevant Microsoft, Google, cloud security, security operations, or risk-related certifications as appropriate to the role.
Benefits
Hybrid work schedule. We work from home two days a week!
Comprehensive benefits package, including medical, dental, and vision insurance
401(k) plan with matching employer contribution
22 days of vacation time
11 holidays, including your birthday
Parental leave
Significant tuition reductions
Professional development is highly valued at ASU Enterprise Partners, where employees are encouraged to look across the organization and nurture new areas of interest
$30 bi-weekly cell phone reimbursement
About ASU Enterprise Partners
ASU Enterprise Partners is a nonprofit organization whose mission is to provide an ecosystem of services to create solutions and generate resources to extend Arizona State University’s reach and advance its charter. ASU Enterprise Partners supports ASU and several affiliates, including the ASU Foundation for a New American University, ASU Outreach Hub, ASURE, NEWSWELL, Skysong Innovations and University Realty.
ASU Enterprise Partners is home to several Centers of Excellence whose purpose is to provide professional services to its affiliates. The Centers of Excellence include Finance, General Counsel, Investments, Public Relations and Strategic Communications, Human Resources, Facilities and Operations, Data Analytics and Insights Planning, Budgeting and Strategy, and Technology and Solutions.
At ASU Enterprise Partners
We serve
ASU and one another with integrity, trust and compassion
We engage
step up, own it, collaborate
We innovate.
continuously, fearlessly, make decisions and take risks
We care
that everyone feels respected and valued for who they are
ASU Enterprise Partners is an Equal Opportunity Employer