Director, Cybersecurity Governance, Risk and Compliance

University of ArkansasFayetteville, AR
305d

About The Position

The Director, Cybersecurity Governance, Risk, and Compliance (GRC) is a leadership position responsible for overseeing the university's cybersecurity governance, risk management, and compliance programs and associated staff. Reporting to the Chief Information Security Officer (CISO), the GRC Director ensures that the university's information security practices align with regulatory requirements, industry standards, and best practices. This role involves developing and implementing policies, conducting risk assessments, managing compliance initiatives, and fostering a culture of security awareness across the university. Other duties as assigned. Regular, reliable, and non-disruptive attendance is an essential job duty, as is the ability to create and maintain collegial, harmonious working relationships with others.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • At least five years of experience in cybersecurity governance, risk management, and compliance.
  • Minimum of three years in a leadership and management role.
  • Professional certifications such as CISSP, CISM, CRISC, CGRC, or CISA.
  • Strong knowledge of information security frameworks, standards, and best practices.
  • Experience with risk assessment methodologies and compliance management.
  • Excellent communication and interpersonal skills.

Nice To Haves

  • Master's degree in a related field.
  • Experience working in a higher education environment.
  • Additional certifications such as CGEIT, CIPT, or CIPM.
  • Experience with cloud security and privacy.
  • Knowledge of data protection regulations such as GDPR, HIPAA, and FERPA.
  • Proven track record of successfully managing compliance initiatives and risk management programs.

Responsibilities

  • Oversee the university's cybersecurity governance, risk management, and compliance programs.
  • Ensure alignment of information security practices with regulatory requirements and industry standards.
  • Develop and implement cybersecurity policies.
  • Conduct risk assessments and manage compliance initiatives.
  • Foster a culture of security awareness across the university.
  • Maintain collegial and harmonious working relationships.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service