Cybersecurity Governance Lead
The position leads enterprise cybersecurity governance, risk management, compliance, and third-party risk activities while supporting alignment with institutional, state, and federal requirements. This position serves as a senior subject matter expert, providing strategic guidance, leading complex assessments, and promoting risk-informed decision-making across the university.
Responsibilities include leading enterprise IT and cybersecurity risk assessments, maintaining the enterprise IT risk register, leading third-party vendor risk assessments, coordinating audit readiness activities, assessing and validating technical, administrative, and operational controls against compliance requirements, supporting the University's data privacy program, developing cybersecurity policies, collaborating with internal stakeholders to evaluate IT controls, supporting governance, compliance, risk management, and security and privacy requirements associated with sponsored research, and developing metrics, dashboards, and executive reports that communicate cybersecurity risk, compliance status, trends, and program effectiveness to leadership.
Required qualifications include a bachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/or experience, and five (5) years of professional experience supporting governance, risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.
Preferred qualifications include relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation, an advanced degree from an accredited institution of higher education in a related field such as Information Technology, Cybersecurity, Information Systems, Business Administration, or Risk Management, experience in higher education or regulated environments, and experience with GRC platforms such as ServiceNow GRC, RSA Archer, OneTrust, Apptega, or similar systems.