Senior Director of Information Security

Berklee College of Music
$160,000 - $180,000Onsite

About The Position

The Senior Director of Information Security serves as Berklee’s primary information security authority and hands-on technical leader. Operating in a high-impact, lean team environment, the Sr. Director balances strategic governance, policy development, and budget management with active technical leadership. Reporting to the VP & CIO, the Sr. Director directly supervises the Information Security Analyst and works collaboratively across IT operations to protect Berklee's digital assets, ensure regulatory compliance, and lead incident response efforts. The Sr. Director of Information Security possesses a strong technical background in risk management, threat mitigation, and technical controls. As a hands-on leader, they provide strategic vision and technical guidance both to the internal security function and to cross-functional IT operations and engineering teams to build a secure, scalable environment across Berklee’s global networks, applications, and systems. In partnership with executive leadership and the Office of General Counsel, this role develops, maintain, and enforces the College’s Information Security Policy, standards, and awareness programs to ensure compliance with relevant statutes and regulations. The Sr. Director oversees security system architecture, evaluates emerging technologies, and serves as the primary subject manager expert for enterprise security design. Additionally, the Sr. Director manages Berklee's overarching IT security strategy, roadmap, and budget. This role requires exceptional communication skills, including the ability to translate complex technical risks into clear concepts for leadership, faculty, staff, and external partners.

Requirements

  • 10+ years of progressive cybersecurity and IT experience, including 3+ years in a team lead or supervisor role.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or an equivalent combination of education and experience).
  • Demonstrated experience managing enterprise security solutions, SIEM systems, identity and access management (IAM), and cloud security architectures.
  • Direct experience leading incident response, threat detection, vulnerability management, and infrastructure risk remediation.
  • Proven ability to interpret, implement, and enforce compliance requirements and security standards (e.g., FERPA, PCI-DSS, 201 CMR 17.00, NIST).
  • Exceptional oral and written communication skills, including the ability to present security updates to executive leadership and lead vendor contract discussions.

Nice To Haves

  • CISSP, CISM, or equivalent professional cybersecurity credentials.
  • Master’s degree, MBA, or advanced degree in Information Assurance, Cybersecurity, or Technology Management
  • Experience working within higher education or a similarly decentralized, open-network institutional environment.
  • Familiarity with cybersecurity frameworks (ISO 27001, CIS Controls) and higher education security assessment tools (HECVAT).
  • Hands-on experience managing IT security budgets, forecasting costs, and negotiating software and service contracts.
  • Proficiency with Google Workspace, Rapid Identity, Microsoft 365, Active Directory, endpoint detection and response (EDR) solutions, and multi-OS platforms (Windows, Linux).

Responsibilities

  • Establish, monitor, and optimize security processes and technical controls to prevent unauthorized access to Berklee's networks, systems, and cloud environments.
  • Directly supervise, mentor, and manage the performance and professional development of the Information Security Analyst.
  • Implement security automation, orchestration, and streamlined workflows to maximize team efficiency and reduce repetitive manual tasks.
  • Partner with broader IT operations, networking, and engineering teams to provide hands-on security guidance, ensure proper protocol implementation, and promote security awareness across the division.
  • Develop, maintain, and enforce institutional IT security policies and programs in alignment with legal regulations (e.g., FERPA, PCI, GDPR, etc.) and higher ed standards.
  • Oversee IT security budget processes, forecast costs, negotiate vendor contracts, and manage security-related procurements to align with institutional goals.
  • Facilitate third-party security audits, risk evaluations, and vendor security reviews (including HECVAT assessments).
  • Actively participate in the IT division’s change management process to ensure new systems and configuration changes adhere to security baselines.
  • Oversee institutional security awareness and training programs for faculty, staff, and students.
  • Oversee threat monitoring across SOC tools and SIEM systems; direct vulnerability assessments, risk reviews, and penetration testing remediation plans.
  • Define security requirements and design policies governing Identity & Access Management (IAM), multi-factor authentication, single sign-on, and cloud connections.
  • Serve as the primary technical and escalation lead during potential or actual security incidents or data breaches and maintain transparent, proactive communication with IT leadership, executive stakeholders, and external partners regarding threat environments and security posture.
  • Lead project management for security initiatives from inception to rollout, ensuring alignment with institutional technology roadmaps.
  • Act as the primary security subject matter expert and advisor to the VP & CIO, executive leadership, and external partners.

Benefits

  • Exceptional health and dental plans
  • a 403(b) retirement system with matching institutional contributions
  • tuition benefits for you and your family
  • Extensive paid time off
  • observed holidays
  • a paid winter break
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service