University of Oklahoma - Oklahoma City, OK

posted 5 days ago

Full-time - Senior
Oklahoma City, OK
Educational Services

About the position

The Information Security Services Director is responsible for developing, implementing, and monitoring a comprehensive enterprise cyber security and IT risk management program at the University of Oklahoma. This role ensures the security of the University’s information systems, manages risks, and aligns security strategies with business objectives while overseeing all production systems and infrastructure to support University customers and affiliates.

Responsibilities

  • Develops, maintains, and implements an information security program including policy and strategy development.
  • Responsible for information security related issues involving identity and access management, intrusion detection, forensics, incident management, risk management, and auditing.
  • Evaluates and provides guidance on information security software and hardware acquisitions, IT services, cloud-based solutions, and mobility.
  • Develops and manages an information security awareness and training program.
  • Responsible for information security and compliance related issues, including FERPA, HIPAA, copyright, and software piracy.
  • Manages and negotiates vendor contracts and agreements.
  • Manages a team that detects, diagnoses, reports, and troubleshoots server, network performance, and network access issues.
  • Audits systems and network resources for compliance with organizational security standards and policies.
  • Develops strategies based on trends, metrics, and desired business outcomes related to security.
  • Develops a business plan to achieve short-term and long-term goals.
  • Performs related duties as assigned to successfully fulfill the functions of the position.

Requirements

  • Bachelor's degree in a related field.
  • 120 months responsible management experience in information security, network administration, or related field, including 36 months supervisory/leadership experience.
  • Experience or a combination of education and related experience can be considered in lieu of a degree.

Nice-to-haves

  • Advanced knowledge of system auditing, vulnerability scanning and mitigation, intrusion detection systems, and how to properly secure servers and infrastructure devices.
  • Advanced knowledge of security assessment and testing tools.
  • Advanced knowledge of information risk concepts and principles as a means of relating business needs to security controls.
  • Advanced knowledge of HIPAA, FERPA, copyright, and software piracy.
  • Advanced knowledge of security architecture and operational principles.

Benefits

  • Inclusive culture of respect and civility, belonging, and access.
  • Equal Employment Opportunity policies ensuring non-discrimination.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service