Director, IT Security & Technology

Catholic Charities of BaltimoreTimonium, MD
$158,000 - $163,000Hybrid

About The Position

Catholic Charities of Baltimore is seeking a Director, IT & Security, responsible for designing, implementing, and maintaining the Agency’s cybersecurity strategy. This role ensures the protection of enterprise technology architecture while supporting business goals. The position safeguards sensitive data, systems, and networks from cyber threats, ensures regulatory compliance, and implements best practices to protect data and maintain stakeholder trust. The director provides leadership to manage risk, ensuring alignment with business objectives, governance, and system availability, integrity, and confidentiality in coordination with IT functions, the Agency compliance committee, divisions, and departments. The work schedule is hybrid, Monday – Friday, 8:30 am – 4:30 pm, with 3 days in the office and 2 days at home.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or a related field (combination of education and experience may be considered).
  • 5+ years of work experience designing and delivering comprehensive security solutions.
  • 10+ years of work experience in IT, including infrastructure, cloud/hybrid environments, networking, and end-user computing.
  • Proven experience in an IT security technical leadership role with a track record of successfully implementing and managing IT security programs.
  • Strong knowledge of relevant regulations and standards (e.g., GDPR, HIPAA, ISO 27001).
  • Experience with risk management methodologies and frameworks.
  • Familiarity with project management principles and practices.
  • Excellent written and verbal communication skills.
  • Strong attention to detail and ability to prioritize and manage multiple tasks simultaneously.
  • Strong communication and interpersonal skills, with the ability to effectively communicate complex security concepts to both technical and non-technical stakeholders.
  • In-depth knowledge of IT security principles, best practices, and industry standards.
  • Excellent problem-solving and analytical skills, with the ability to identify and mitigate security risks.
  • Familiarity with security tools and technologies (e.g., firewalls, intrusion detection/prevention systems, encryption, antivirus software).
  • Strong knowledge of privacy and security frameworks.
  • Knowledge of network and system administration.
  • Proven skills with Microsoft Entra Domain Services, Microsoft 365, SAN, server, networking, VOIP, unified communication, virtualization, and end-user computing including endpoint device management.
  • Demonstrated knowledge of accounting, payroll, human resources, and information systems, healthcare applications.
  • Proficiency in conducting risk assessments and vulnerability testing.
  • Familiarity with regulatory requirements and industry standards related to IT security.
  • Proven working knowledge of technologies such as cloud computing, AI, cybersecurity, and data analytics.
  • Ability to act with discretion, tact, and professionalism.
  • Ability to utilize computer systems and software necessary to perform position functions.
  • Basic Windows PC, web browsing, and Microsoft Outlook skills required.
  • Other Microsoft Office application knowledge (Word, Excel, PowerPoint, Teams, OneDrive) desired.

Nice To Haves

  • Professional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) are highly desirable.
  • Experience implementing and managing CIS Top 20 controls a plus.
  • Demonstrated knowledge of Aruba Wireless, ClearPass, and Watchguard technologies a plus.
  • Other Microsoft Office application knowledge, such as Word, Excel PowerPoint, Teams, and OneDrive desired.

Responsibilities

  • Ensuring an adequate level of information security protection and risk management, including the confidentiality, integrity, and availability of Agency data and other information assets.
  • Regularly assessing security controls, ensuring compliance with policies, and holding stakeholders accountable for addressing vulnerabilities and maintaining appropriate safeguards.
  • Developing and managing frameworks, processes, and tools for IT to manage security risks and make informed, risk-based decisions.
  • Monitoring performance, assessing compliance, and holding stakeholders responsible for adhering to security protocols and mitigating risks.
  • Conducting regular risk assessments and vulnerability tests to identify potential security threats and develop mitigation strategies.
  • Managing, monitoring, and analyzing security incidents, investigating breaches, implementing corrective actions, and proactively addressing vulnerabilities.
  • Maintaining subject matter expertise of the latest industry trends, threats, and technologies.
  • Developing and managing the Agency's security policies and procedures.
  • Collaborating with Agency Programs to integrate security requirements into new systems and technologies.
  • Developing, implementing, and managing security awareness programs to educate employees and promote a security culture.
  • Managing relationships with external vendors and partners to ensure effective security control implementation and maintenance.
  • Leading the cybersecurity strategy and technology roadmap, assessing existing, new, and emerging technologies.
  • Overseeing the endpoint protection strategy for all Agency computing systems.
  • Managing Agency compliance for relevant data privacy regulations, changing laws, and industry standards (HIPAA, ISO27001, CISA, GDPR, PCI DSS).
  • Preparing and presenting regular reports to senior management on the Agency's IT security posture.
  • Leading IT disaster recovery initiatives, ensuring they are current and tested.
  • Developing effective disaster recovery policies and standards aligned with business continuity management goals.
  • Providing technical/security training, knowledge transfer, and mentorship to IT colleagues.
  • Co-leading technology architecture decisions across Agency application and network enterprise domains.
  • Performing other duties as assigned.

Benefits

  • Health/Dental/Vision
  • Vacation/sick/holiday pay
  • 403(b) Retirement Plan with a discretionary employer contribution
  • Tuition Advancement
  • Paid Parental Leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service