Maintain and execute the Cybersecurity, risk and compliance program. Responsible for the
development, establishment, and communication of security policies, standards, and
guidelines as well as the education and awareness of these requirements. Responsible for the
ongoing enhancement of the security risk assessment processes and procedures ensuring
alignment with establishing industry standard security metrics.
Essential Functions and Responsibilities
20%: Gain understanding of customer IT environment, focusing on IT assets / applications / accounts critical to business operations
10%: Review existing security policies and procedures
10%: Review LU compliance requirements, Identify and document existing security controls, Make recommendations to IT Executive staff regarding security policy best practices and standards (ISO, NIST, PCI-DSS, CIS, etc.)
10%: Assist with creation roadmap for the development of a comprehensive information security policy framework
10%: Draft security policy and procedure templates
10%: Customize security policies and procedures in accordance with business requirements
5%: Identify methods for policy/procedure compliance, distribution, training and awareness strategies
5%: Establish and maintain LU information security policies, standards, and procedures in alignment with Leadership. Identify and prioritize security gaps
5%: Identify new security compliance requirements, emerging threats and cyber risks to incorporate into the Cybersecurity, Risk and Compliance Programs
5%: Work with outside auditors and agencies to address questions in Cybersecurity audits
5%: Work in collaboration with IT Application Development to coordinate and architect a culture of Security by Design within our Software Products
5%: Oversee the annual planning and execution of all Cybersecurity certification and compliance programs, including PCI-DSS, FERPA and others
Qualifications, Credentials, and Competencies
A bachelor's degree in Computer Science, Information Security, Information Systems, or related field required. 2+ years' experience in security controls across all security domains, information security compliance, and supporting compliance programs within the technology space required. In-depth experience of data security frameworks and regulatory standards, experience developing and submitting audit and compliance reports to governing bodies or legal entities, and certifications in one or more of the following areas preferred: CISSP, CISA, CISM, GISO, GCIIH, CIPP. Experience assessing security risk for large scale organizations and in processes for assessing and designing internal controls for large scale organizations preferred.
This is a home-based work position. Employee's home work environment must be free of
distractions and arranged to maximize Employee's efficiency in performing work tasks and
must include a reliable, high-speed internet connection. Effective communication both verbally and in writing. Ability to intuitively reason, analyze information and events, and apply judgment in order to solve problems of both a routine and complex nature. Excellent computer and organizational skills. Proof of a valid Virginia driver's license, an acceptable DMV record, and liability insurance is required.
Target Hire Date2025-12-01
Time Type
Full time
Location
Remote Location
The University is an Equal Opportunity Employer. We believe it is our moral and legal obligation to meet the responsibility of ensuring that all management practices regarding employees are conducted in a nondiscriminatory manner. In compliance with Title VII of the 1964 Civil Rights Act, and other applicable federal and state statutes, all recruiting, hiring, training, and promoting for all job classifications will be administered without regard to race, color, ancestry, age, sex, national origin, pregnancy or childbirth, disability, military veteran status or other applicable status protected by law, including state of employment protected classes. It is, therefore, our policy and intention to evaluate all employees and prospective employees strictly according to the requirements of the job. All personnel related activities such as compensation, benefits, transfers, job classification, assignments, working conditions, educational assistance, terminations, layoffs, and return from layoffs, and all other terms, conditions and privileges of employment will be administered without regard to race, color, ancestry, age, sex, national origin, pregnancy or childbirth, disability, military veteran status or other applicable status protected by law, including all applicable state of employment protected classes. The University is a Christian religious-affiliated organization; and as such, is not subject to religious discrimination requirements. The University's hiring practices and EEO discrimination practices are in full compliance with both federal and state law. Federal law creates an exception to the "religion" component of the employment discrimination laws for religious organizations (including educational institutions), and permits them to give employment practice preference to members of their own religious beliefs.