Stand out for this role — generate a tailored resume and cover letter in about a minute.
Jobtailor is seeking a senior Information Security and Compliance leader to oversee ISPCR and align policies with industry standards. You will drive risk assessments across campus infrastructure, cloud environments, and vendors, delivering mitigation strategies and governance that inform leadership decisions.
With 6+ years in GRC, you will mentor colleagues, communicate complex risk to diverse stakeholders, and advance security maturity across university operations.
Own and operate the university’s Information Security and Privacy Control Requirements (ISPCR)
Map institutional policies and controls to industry standards and regulatory requirements, including NIST SP 800-53, NIST SP 800-171, CIS Benchmarks, HIPAA, FERPA, GLBA, PCI-DSS, CIS Controls, ISO/IEC 27001, and SOC 2
Develop, refine, and implement compliance practices, processes, maturity models, and key performance metrics
Lead complex, large-scope risk assessment initiatives
Scope, execute, and oversee Tier 1, Tier 2, and Tier 3 risk assessments across campus infrastructure, cloud environments, third-party vendors, and research data environments
Provide technically sound mitigation strategies to system owners, researchers, and technical teams
Provide guidance, mentorship, and technical oversight to less experienced colleagues
Communicate complex or sensitive risk information to technical and non-technical stakeholders and leadership
Facilitate dialogue and persuade stakeholders to adopt secure practices and consider alternative risk-treatment options
Demonstrates expertise in Information Security Governance, Risk, and Compliance (GRC) with a strong focus on NIST SP 800-53, HIPAA, and risk assessment methodologies. Capable of developing and implementing compliance practices while effectively communicating complex risk information to diverse stakeholders.