| Job Summary |
The Center for Information Technology (CIT) invites qualified applicants for the position of Director of Information Security, a strategic leadership role responsible for advancing Oberlin College & Conservatory’s enterprise cybersecurity program. This is a full-time, on-campus leadership position based in Oberlin, Ohio, requiring regular in-person engagement to lead cybersecurity initiatives and collaborate with campus stakeholders.
This role joins Oberlin at a pivotal moment as the College undertakes a significant digital transformation, including implementation of Workday, modernization of enterprise systems, expansion of cloud technologies, and the responsible exploration of artificial intelligence (AI). The Director of Information Security will provide the strategic vision, operational leadership, and technical expertise necessary to protect the College’s information assets while enabling innovation, academic excellence, research, and institutional success.
Reporting to the Chief Information Officer (CIO), the Director is responsible for leading the College’s cybersecurity strategy, governance, security operations, risk management, incident response, regulatory compliance, and cyber resilience initiatives. Serving as the principal advisor on cybersecurity, privacy, AI risks governance, and emerging technologies, the Director ensures that security is integrated into institutional planning, technology modernization, and enterprise decision-making.
Working collaboratively with CIT members, the Office of General Counsel, Human Resources, Finance, Academic Affairs, faculty, staff, students, and external partners, the Director develops and leads a modern, risk-based cybersecurity program that safeguards institutional data, technology resources, research, and digital services while supporting Oberlin’s mission of teaching, learning, creativity, and service. |
| Responsibilities |
See Below: |
| Essential Job Functions |
Strategic Leadership & Governance
- Serve as a member of the CIT Leadership Team and contribute to the College’s technology strategy, digital transformation, and institutional planning.
- Develop, implement, and continuously evolve the College’s enterprise cybersecurity strategy, roadmap, governance framework, policies, standards, and procedures.
- Advise on cybersecurity risks, AI risks governance, privacy, regulatory compliance, enterprise risk management, and emerging technologies.
- Present cybersecurity strategy, institutional risk posture, program maturity, and security metrics to executive leadership and governance committees.
- Establish meaningful cybersecurity performance metrics and executive dashboards that demonstrate institutional risk reduction and program effectiveness.
Cybersecurity Operations & Technology
- Lead the College’s enterprise cybersecurity operations, including security monitoring, threat detection, identity and access management (IAM), endpoint detection and response (EDR), cloud security, network security, email security, vulnerability management, incident response, and security architecture.
- Develop, implement, and continuously improve a comprehensive cybersecurity program focused on preventing, detecting, responding to, and recovering from cyber threats.
- Ensure cybersecurity is integrated into enterprise infrastructure, cloud platforms, identity services, Workday, Google Workspace, Microsoft 365, and other enterprise applications throughout their lifecycle.
- Lead enterprise vulnerability management, threat hunting, ransomware protection, malware prevention, detection engineering, and remediation of security risks across on-premises and cloud environments.
- Direct continuous monitoring and improvement of the College’s external security posture through attack surface management, security ratings, and operational performance metrics.
- Lead cyber incident response, cyber crisis management, business continuity, disaster recovery planning, tabletop exercises, and post-incident reviews.
- Evaluate, implement, and optimize cybersecurity technologies and security controls, including security automation, email authentication (SPF, DKIM, DMARC), anti-phishing technologies, and emerging security capabilities.
Risk Management, Compliance & Legal Partnership
- Lead the College’s enterprise cybersecurity risk management program and ensure compliance with applicable regulatory requirements and industry frameworks, including FERPA, HIPAA, GLBA, PCI DSS, NIST Cybersecurity Framework, and CIS Controls.
- Partner closely with the Office of General Counsel on cybersecurity, privacy, technology contracts, records preservation, breach response, litigation readiness, and regulatory compliance.
- Oversee third-party and vendor cybersecurity risk assessments and participate in technology procurement and contract reviews.
- Support cybersecurity audits, cyber insurance renewals, and institutional risk assessments.
Data Protection & AI risks Governance
- Lead institutional initiatives related to data classification, data protection, data loss prevention (DLP), and information governance.
- Develop and support policies for the responsible, secure, and ethical use of artificial intelligence.
- Assess cybersecurity and privacy risks associated with AI and other emerging technologies while enabling responsible innovation.
Leadership & Collaboration
- Build strong partnerships across academic and administrative units to promote cybersecurity as a shared institutional responsibility.
- Develop and oversee a comprehensive cybersecurity awareness and education program for faculty, staff, and students, including phishing simulations, role-based training, and executive awareness initiatives.
- Partner with faculty, research leadership, and grant administrators to protect research systems and data while supporting applicable research security and compliance requirements.
- Develop and manage the Information Security operating and capital budgets, prioritizing investments based on institutional risk and strategic priorities.
- Recruit, lead, mentor, evaluate, and develop cybersecurity professionals while fostering a collaborative, service-oriented, and high-performing culture.
- Build trusted relationships with executive leadership, faculty, staff, students, and external partners while effectively communicating cybersecurity risks in business terms.
- Represent Oberlin in higher education cybersecurity organizations and maintain awareness of emerging threats, evolving regulations, and industry best practices.
|
| Marginal Job Functions |
|
| Required Qualifications |
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Five (5) years of progressively responsible cybersecurity experience, including leadership of enterprise information security programs and direct responsibility for cybersecurity strategy, operations, and risk management.
- Experience working in a higher education environment or a similarly complex, mission-driven organization with diverse stakeholder groups and shared governance.
- Demonstrated hands-on experience in cybersecurity operations, including security architecture, governance, risk management, cloud security, identity and access management, vulnerability management, incident response, and enterprise security technologies.
- Demonstrated experience securing hybrid and cloud environments, including Microsoft 365, Azure, Google Workspace, identity platforms, and enterprise SaaS applications.
- Demonstrated ability to lead complex, cross-functional cybersecurity initiatives and technology transformation projects.
- Experience collaborating across technical and non-technical teams and effectively communicating cybersecurity concepts to executive leadership, faculty, staff, and institutional stakeholders.
- Strong knowledge of cybersecurity frameworks and standards, including NIST Cybersecurity Framework, CIS Controls, Zero Trust principles, and applicable regulatory requirements.
-
CISSP certification required (or the ability to obtain certification within one year of hire).
|
| Desired Qualifications |
- Master’s degree in Cybersecurity, Information Technology, Computer Science, Business Administration, or a related field.
- Experience supporting cybersecurity programs in higher education.
-
CISM, CRISC, GIAC, or similar advanced cybersecurity certifications.
- Experience securing Google Workspace, Microsoft 365, Azure, Workday, and other enterprise SaaS platforms.
- Experience implementing Zero Trust architecture, identity governance, cloud security technologies, and modern security operations.
- Experience leading cybersecurity programs through enterprise digital transformation initiatives, including cloud modernization.
|
| Quick Link for Posting |
https://jobs.oberlin.edu/postings/17689 |
| Compensation |
Salary will commensurate with qualifications and experience. |
| Special Instructions to Applicants |
Commitment to Equal Opportunity and Inclusive Excellence:
Oberlin College is committed to creating and sustaining a vibrant, welcoming community where all individuals are treated with dignity and respect, and where every member has an equal opportunity to learn, work, and contribute based on their talents, skills, and merit. We value a campus environment that draws on a wide range of backgrounds, experiences, perspectives, and ideas to enrich education, scholarship, and daily interactions. The College adheres strictly to all applicable federal and state civil rights laws, including Title VI, Title VII, Title IX, the Equal Protection Clause, and related regulations. We do not discriminate on the basis of race, color, national origin, sex, disability, age, religion, sexual orientation, gender identity, or any other protected characteristic in employment, admissions, or educational programs. Hiring and advancement decisions are made based on qualifications, experience, and job-related criteria. We encourage candidates from all backgrounds who share our dedication to academic excellence, free inquiry, respectful dialogue, and equal opportunity under the law to apply. The Office for Institutional Equity plays a key role in supporting a fair, compliant, and inclusive workplace and learning environment for the entire Oberlin community. |