Dutchess Community College - Poughkeepsie, NY
posted about 2 months ago
Under the direction of the President or designee, the Chief Information Security Officer (CISO) is responsible for the development and delivery of a comprehensive information security and privacy program. This program is college-wide and includes all formats of information communication for all authorized users. Protecting information and infrastructure from internal or external threats and ensuring the compliance of all statutory and regulatory requirements regarding information access, security, and privacy is of the utmost concern. The CISO is responsible for the development and implementation of information security policies, standards, and procedures to ensure the College is compliant with industry standards for information and cybersecurity. This includes performing ongoing security risk assessments, developing procedures for auditing and incident prevention and response, and serving as the official campus contact for information security and privacy along with law enforcement entities, external auditors, and agencies. The CISO also maintains breach insurance coverage policy and supporting information security policy, and is tasked with the development and delivery of an education and training program on security and privacy matters for the College. Additionally, the CISO maintains security devices such as routers, firewalls, and other networking hardware/software. The CISO provides oversight and direction of DCC's IT operations, which includes directing and approving the design of security systems and IT controls, developing and recommending policies and procedures to handle security incidents, ensuring that disaster recovery and business continuity plans are in place and tested, and developing and implementing security policies, controls, and cyber incident response planning. The CISO is also responsible for reviewing investigations after breaches or incidents, maintaining a current understanding of the IT threat landscape, ensuring compliance with changing laws and applicable regulations, scheduling periodic security audits, overseeing identity and access management, and managing all teams, employees, contractors, and third-party vendors involved in IT security. Furthermore, the CISO provides training and mentoring to security team members and develops a training plan for students, faculty, staff, and the community, including security awareness training. The role also involves monitoring and updating the cybersecurity strategy to leverage new technology and threat information, briefing the executive team on status and risks, and communicating best practices and risk management strategies to the campus community.