Director of Cyber Security

Oakland Community College

Auburn Hills (MI)

On-site

USD 120,000 - 170,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Oakland Community College seeks a strategic Cybersecurity Leader to direct risk management, security operations, and program improvements, reporting to the Director of Technology Infrastructure & Security.

The role balances leadership with hands‑on depth, driving security controls, incident response, compliance, training, and collaboration across departments to safeguard students, staff, and data.

Qualifications

  • Bachelor’s degree in Information Systems, Cybersecurity, or related field.
  • Six years of progressively responsible information security experience; leadership experience preferred.
  • Experience with vulnerability management (Tenable), EDR (CrowdStrike), and Fortinet firewalls preferred.
  • Higher education experience preferred; cross-cultural environment experience valued.
  • Experience with IAM, cloud security, and data protection technologies preferred.

Responsibilities

  • Develop and lead execution of the College’s cybersecurity strategy and roadmap.
  • Manage risk assessments, policies, standards, and controls aligned with frameworks.
  • Direct security operations: SIEM, EDR, email and network security.
  • Oversee vulnerability management, risk-based remediation, and reporting.
  • Lead incident response, containment, and post-incident reviews.
  • Plan third-party/vendor risk assessments and remediation tracking.
  • Establish security awareness/training across faculty, staff, and students.
  • Collaborate with Legal, HR, and Registrar on data privacy and FERPA-related needs.
  • Develop security metrics and dashboards for leadership and governance.

Skills

Leadership & supervision
Cybersecurity frameworks (NIST CSF/800
Security operations
Vulnerability management
Incident response
Regulatory/compliance
IAM & cloud security
Data protection & encryption
Project management
Communication
Professional certifications

Education

Bachelor’s degree in Information Systems/Cybersecurity/CS

Tools

Tenable
CrowdStrike Falcon
Fortinet FortiGate

Job description

Provides leadership and management for the College’s cybersecurity program, protecting institutional information systems, data, and network infrastructure from threats and unauthorized access. Reporting to and partnering with the Director of Technology Infrastructure and Security, this role directs security operations, vulnerability and risk management, incident response, compliance, and security awareness, while supervising and developing cybersecurity staff.

The position balances strategic leadership with hands‑on technical depth, translating institutional risk and business needs into effective, sustainable security controls and program improvements. It serves as a senior escalation point and, as assigned, acts on behalf of the Director on security matters.

The role requires a strong commitment to service excellence within a multicultural and diverse environment, with a focus on continuous improvement, confidentiality, and effective communication across departments.This description is intended to indicate the types of duties and responsibilities requested of the employee assigned this title. It is not intended to be an exhaustive list of all the duties and responsibilities that may be required:

  1. Develop and lead execution of the College’s cybersecurity strategy and roadmap, translating institutional risk tolerance and business priorities into a multi‑year security program, in partnership with the Director of Technology Infrastructure & Security.
  2. Develop, implement, assess and mitigate risk, and maintain security policies, standards, procedures, and controls aligned with recognized frameworks (e.g., NIST Cybersecurity Framework, NIST 800‑53, CIS Controls, ISO, etc.).
  3. Direct security operations, including continuous monitoring, threat detection, alert triage, and escalation across SIEM, endpoint, email, and network security platforms.
  4. Own and mature the vulnerability management program overseeing scanning, risk‑based prioritization, remediation coordination, and reporting.
  5. Oversee endpoint detection and response and network security operations, including next‑generation firewalls ensuring effective configuration, tuning, and coverage.
  6. Lead the College’s incident response program, coordinating detection, containment, eradication, and recovery, and directing post‑incident reviews and executive reporting.
  7. Plan and conduct risk assessments and third‑party/vendor risk reviews, tracking findings and remediation to closure and reporting residual risk to leadership.
  8. Establish processes to assess security risk and implement mitigations for emerging technologies (e.g., AI)
  9. Ensure compliance with applicable regulations and standards (e.g., FERPA, GLBA, PCI‑DSS, HIPAA where applicable), and support internal and external audit activities.
  10. Establish and manage the College security awareness and training program, including phishing simulations and role‑based education for faculty, staff, and students.
  11. Evaluate, recommend, and manage security technologies and other vendors; provide input to the security budget; and support procurement, contract, and renewal decisions.
  12. Develop and report security metrics, dashboards, and posture assessments to IT leadership, executive stakeholders, and governance committees.
  13. Support business continuity and disaster recovery planning and testing as it relates to security controls, data privacy and resilience.
  14. Partner with Legal, Registrar, and Human Resources to maintain data privacy policies and standards, including data classification, retention, and handling of PII and FERPA‑protected data, and lead security’s role in incident response for data privacy events.
  15. Lead investigations into electronic activity at the request of HR or Legal exercising independent judgment in scope and methodology while maintaining defensible documentation and chain of custody
  16. Collaborate across the College to embed security into projects, systems, new solutions, and processes, and serve as a senior point of escalation for security matters.
  17. Maintain current knowledge of the evolving threat and cyber landscape, emerging technologies, and industry best practices, and adjust the security program accordingly.
  18. Supervise, mentor, and develop cybersecurity staff and broader IT, including hiring, goal setting, and professional development.
  19. Performs other related duties, as assigned.
  20. Ability to work additional hours, as needed, including during active security incidents.
  • Demonstrated leadership and supervisory ability, including the capacity to build, develop, and retain a high‑performing security team.
  • In‑depth knowledge of security frameworks and risk management practices, including the NIST Cybersecurity Framework, NIST 800‑53, and CIS Controls.
  • Strong command of security operations, including SIEM, endpoint detection and response (EDR), vulnerability management, and network security.
  • Experience with enterprise vulnerability management platforms, Tenable (Nessus, Tenable.sc, or Tenable.io) preferred.
  • Experience with endpoint detection and response solutions, CrowdStrike Falcon preferred.
  • Experience with next‑generation firewalls, Fortinet (FortiGate/FortiManager) preferred.
  • Proven ability to lead incident response, including coordination, decision‑making under pressure, and clear communication with technical and executive audiences.
  • Working knowledge of regulatory and compliance requirements relevant to higher education (e.g., FERPA, GLBA, PCI‑DSS) and experience supporting audits.
  • Working knowledge of identity and access management (IAM/PAM), cloud security posture (SaaS/IaaS), data protection and encryption standards, and email security controls.
  • Strong project management, planning, and organizational skills, with the ability to manage multiple priorities and initiatives concurrently.
  • Excellent verbal and written communication skills, including the ability to translate technical risk into business terms for leadership and stakeholders.
  • Sound judgment, integrity, and a strong commitment to confidentiality, ethical conduct, and continuous improvement.
  • Relevant industry certifications such as CISSP, CISM, GIAC, or equivalent preferred.
EDUCATION:

Bachelor’s degree in Information Systems, Cybersecurity, Computer Science, or related field required; Relevant, position‑related experience may substitute for education on a year‑for‑year basis.

EXPERIENCE:

Six (6) years of progressively responsible experience in information security or cybersecurity, including at least two (2) years in a lead, supervisory, or team leadership capacity. Experience with vulnerability management (Tenable), endpoint detection and response (CrowdStrike), and Fortinet firewalls preferred. Experience with identity and access management, cloud security, and data protection technologies preferred. Experience in higher ed preferred. Experience with multi‑cultural students and staff preferred.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director - Cybersecurity Officer
Director - Cybersecurity Officer

Sam Houston State University • Huntsville (TX)

On-site
USD 80,000 - 110,000
Security Administrator Cyber Defense
Security Administrator Cyber Defense

Compunnel, Inc. • Midland (TX)

On-site
USD 90,000 - 120,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Ampcus Inc • Washington

On-site
USD 90,000 - 120,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
Cybersecurity Director
Cybersecurity Director

10xTalents • Newark (NJ)

On-site
USD 140,000 - 180,000
Cybersecurity Operations Director
Cybersecurity Operations Director

Pearl Companies • United States

Remote
USD 130,000 - 160,000
Full Time Faculty - CIS - Cybersecurity (10 month, tenure, permanent position)
Full Time Faculty - CIS - Cybersecurity (10 month, tenure, permanent position)

Henry Ford College (MI) • Dearborn (MI)

Hybrid
USD 65,000 - 90,000
Senior Information Security Analyst
Senior Information Security Analyst

UMass Amherst • Amherst (MA)

Hybrid
USD 120,000 - 150,000
Director, Cybersecurity
Director, Cybersecurity

Asset Living • United States

On-site
USD 150,000 - 190,000
Incident Response Manager and Security Operations Team Lead
Incident Response Manager and Security Operations Team Lead

University of Connecticut • Storrs (CT)

On-site
USD 95,000 - 124,000
Defined contribution with employer 401
Excellent healthcare options
35 hour work week
+2