What are the responsibilities and job description for the Director of Information Security position at Jenzabar?
Position Summary
We are seeking a highly skilled and experienced Director of Information Security to lead our information security initiatives. An exceptional candidate will play a critical role in developing, implementing, and managing our information security strategy, ensuring the protection of sensitive data, systems, and infrastructure. They will also serve as the internal and external face of Jenzabar’s information security posture and thought leadership.
Essential Tasks
- Drive strategic initiatives as an individual contributor while providing leadership and expert guidance to a high-performing team, fostering collaboration with all departments within the organization and ensuring the effective execution of the Information Security roadmap.
- Devise, implement, lead, and maintain an overarching information security strategy aligned with business objectives and compliance standards.
- Identify, assess, and mitigate cybersecurity risks and vulnerabilities across the organization. Conduct regular risk assessments and ensure the implementation of effective risk mitigation measures.
- Improve and automate existing vulnerability management lifecycle, along with scoping, scheduling, scanning, and ensuring identified vulnerabilities are remediated.
- Strategically identify, recruit, and onboard skilled professionals to fulfill key roles within the Information Security department, ensuring a well-rounded team capable of addressing all facets of cybersecurity—from risk management to incident response and compliance.
- Establish and enforce robust policies, standards, and procedures to safeguard company assets and customer data, ensuring compliance with regulations and fostering a secure operational environment.
- Ensure compliance with relevant industry regulations (e.g., TX-RAMP/StateRAMP, GDPR, FAFSA, HECVAT, PCI) and standards (e.g., ISO 27001, SOC 2, NIST). Stay updated on changing regulations and adapt security measures accordingly.
- Develop and implement comprehensive training programs to enhance organizational cybersecurity awareness by educating employees and customers about security policies, best practices, and emerging threats.
- Act as a key stakeholder in the vendor selection and Request for Proposal (RFP) processes, contributing expertise to evaluate and choose strategic security partners, fostering collaboration across teams to ensure alignment with organizational goals and cost-effective solutions for the Information Security department.
Required Certifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
Preferred Certifications
- Certified Information Systems Auditor (CISA)
- Certified Ethical Hacker (CEH)
- ISO/IEC 27001 Lead Auditor/Implementer
- Certified Cloud Security Professional (CCSP)
- Project Management Professional (PMP)
- ITIL Foundation Certification (ITIL 159)
- Certified Data Privacy Solutions Engineer (CDPSE)
- Certified in Risk and Information Systems Control (CRISC)
Preferred Skills and Experience
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- Minimum 12 years in information security, with at least 6 years in a leadership role and SaaS providers. Experience in the SaaS FinTech or EdTech industry is highly desirable.
- Proficiency in security technologies, network and application security, cloud security (e.g., AWS, IBM, Azure, Google Cloud), encryption methods, and identity and access management.
- Strong understanding of Microsoft 365 Security Suite including but not limited to; Microsoft Sentinel, Microsoft Defender including ATP, Microsoft Intune MDM & related policies, Azure SAML/SSO with MFA, Attack Simulation training, Microsoft Authenticator
- Strong understanding of data protection regulations, compliance frameworks, and privacy laws relevant to the education sector.
- Excellent leadership and communication skills to effectively collaborate with cross-functional teams, articulate complex security concepts to non-technical stakeholders, willing to be a hands-on leader and lead security initiatives.
The pay range for this position is $120,000-$175,000/year; however, base pay offered may vary depending on job-related knowledge, geographic location, skills, and experience. This position is eligible for an annual bonus in addition to a full range of benefits. This information is provided per the relevant state and local pay transparency laws for the location in which this position will be performed.
#LI-Remote
Salary : $120,000 - $175,000