Director of Information Security (4071)

Northern Illinois University
  • DeKalb, IL
  • $155,068.56 Per Year
17 days ago

Job Description

Position Information

Posting Detail Information

Working Position Title Director of Information Security (4071) Classification Director Position Number 00004071 Open Date 08/20/2026 Close Date Priority Review Date 09/16/2026 Employee Class Staff Full-Time/Part Time Full-Time FTE 1.00 Position Status Regular FLSA Exempt Job code 1330SPS03 Union Representation Non-Union Union Code N/A Unit/Department DoIT-Admin-Business-Finance College/Unit DoIT-Admin-Business-Finance Division Div Information Technology Location WL 2100 Link to Department Website or Custom Search Page https://www.niu.edu/doit/

Position Summary, Requirements, and Qualifications

Position Summary, Requirements, and Qualifications

Overview

Northern Illinois University (NIU) is a world-class, research-focused public institution that attracts students from across Illinois, the country and the world and currently serves more than 16,000 students. NIU's vision is to be an engine for innovation to advance social mobility; promote personal, professional and intellectual growth; and transform the world through research, artistry, teaching and outreach. Our mission is to empower students through educational excellence and experiential learning as we pursue knowledge, share our research and artistry, and engage communities for the benefit of the region, state, nation and world.

The Director of Information Security plays a pivotal leadership role in safeguarding the confidentiality, integrity, and availability of university data, systems, and technology resources. This position is responsible for ensuring that the university's information security program remains aligned with institutional priorities while adapting to an evolving threat landscape.

Working collaboratively with the Information Security team, central and distributed IT teams, and key business units across the university, the Director provides strategic direction and operational oversight for the day-to-day execution of the information security program. The Director partners with Internal Audit, the Office of General Counsel, the Office of Ethics and Compliance, the Director of Privacy, and other university stakeholders to develop and implement security policies, standards, and procedures; conduct risk assessments; strengthen security awareness and compliance efforts; and lead the university's response to security incidents and emerging cyber threats.

Position Summary

The Director of Information Security has direct management responsibility for the Information Security Office (ISO), Account Access, Business Continuity and IT Disaster Planning (BCDP) and IT physical security. Account Access, BCDP, ISO and IT Physical Security combine to represent a comprehensive umbrella of IT related security services and includes oversight and coordination of the NIU Information Security Policy and enforcement of the NIU Acceptable Use Policy and the Security Access Policy.

The functional aspects of these high level activities include: coordination with internal and external enforcement authorities as relates to IT criminal investigation activities, coordinating response to copyright infringement notices, coordination of data breach responses, directing internal IT forensic analyses for administrative purposes, assessing and responding to IT related threats, providing proactive education and awareness notification as relates to information protection, immediate IT threat response and interfacing with end-users who are not in compliance with applicable University policy.

Additionally, this position is responsible for informing and coordinating with distributed Lan-Administrators and is the point-of-contact for external auditor response regarding IT security related issues. This position is the published designee for University representation as the Digital Millennium Copyright Act and lnternet Abuse I security contact. Generally speaking, the incumbent performs duties and is responsible for issues that are consistent with the role of a Chief IT Security Officer.

Given the breadth of responsibility and accountability associated with leading the university's information security program, this position requires a high degree of judgment, responsiveness, and availability, including the ability to address critical incidents and emerging issues outside of normal business hours.

Essential Duties and Responsibilities

Managing Security Compliance Programs

  • Map security controls to systems based on data classification, regulatory requirements, and risk profile.
  • Ensure compliance with security regulations such as HIPAA, GLBA, and PCI DSS.
  • Work with Privacy, Ethics, and Risk Management to ensure appropriate controls are in place to meet privacy regulations.
  • Ensure vendor security management program is developed and maintained including participating in contract reviews
  • Ensure academic research follows required security controls.
  • Ensure that inventory and asset management practices adhere to security configuration and vulnerability management policies and procedures.
  • Develop and implement security awareness training for university employees and students.
  • Wins support for information security techniques even among those who are resistant.
  • Finds ways to spread good practices, both through formal and informal means.
  • Develop and manage budgets, Service Level Agreements, Reporting, Key Performance Indicators, and Critical Success Factors.
  • Serve as the primary manager of the vendor review program/process.
  • Understand SOC 2 reports (or other third-party security review documents) and how to work with the lines of business on issues.
  • Manage and mentor security analysts on the vendor review program/process.

Develop & Implement Security Policies & Procedures

  • Work with key stakeholders across the university to develop and maintain security policies and procedures that are aligned with the university's goals while providing sufficient security to meet the organizations risk appetite
  • Review and update security policies and procedures on a regular basis to ensure they remain effective and relevant.
  • Ensure that security policies and procedures are communicated to all university employees, students, and third-party vendors. and objectives.
  • Work with other departments to ensure that security policies and procedures are understood and followed, and that compliance is documented and measured.
  • Implement processes to ensure that policies and procedures are reviewed and updated on a regular basis.

Conduct Risk Assessments & Penetration Testing

  • Participate in security industry groups, professional security organizations, and vendors to stay informed about emerging threats, vulnerabilities, and trends.
  • Identify potential risks and vulnerabilities to the university's data and systems through regular risk assessments and vulnerability testing.
  • Analyze the results of risk assessments and vulnerability testing to develop and implement strategies to mitigate risks and vulnerabilities.
  • Develop, maintain, and implement a risk management plan that identifies critical systems and data, and establishes appropriate security controls.
  • Work with IT and business units to remediate identified vulnerabilities and risks.

Manage Security Incidents & Responses

  • Manage the response to security incidents and threats.
  • Coordinate with other departments as needed to resolve security incidents.
  • Develop and maintain incident response plans.
  • Develop and conduct tabletop exercises.
  • Conduct post-incident reviews to identify opportunities for process improvements and to refine incident response procedures.
  • Ensure disaster recovery plans are maintained and tested.
  • When appropriate, collaborate with NIU police, Office of General Counsel, the office Ethics and Compliance, Enterprise Risk, Internal Audit, and other offices as necessary in completing internal investigations and responding to external law enforcement.

Respond to Security Audits & Assessments

  • Respond to security audits and assessments from regulatory bodies or other external entities.
  • Coordinate with key stakeholders across the university to respond to audit requests and address any findings from security audits and assessments.
  • Develop and implement plans to address any gaps in security compliance that are identified through audits, assessments, or notifications.

Other Related Duties

  • Perform other related duties as assigned.

Minimum Required Qualifications (Civil Service)

N/A

Knowledge, Skills, and Abilities (KSAs) (Civil Service)

N/A

Specialty Factors (Civil Service)

N/A

Preferred Qualifications (Civil Service)

N/A

Minimum Required Qualifications (SPS)

  • One of the following:

  • Master's degree in Computer Science, Information Systems, or a related field and two (2) years of work experience in information security or related field.

  • Bachelor's degree in Computer Science, Information Systems, or a related field and six (6) years of work experience in information security or related field.

  • Associate's degree in Computer Science, Information Systems, or a related field and seven (7) years of work experience in information security or related field.

  • At least nine (9) years of work experience in information security or related field.

  • At least three (3) years of supervisory experience.

Additional Requirements (SPS)

  • Knowledge of security standards and risk management frameworks such as CIS, NIST, and others.
  • Strong knowledge of security technologies, including common security tools, endpoint detection and response, SIEM, firewalls, intrusion detection and prevention systems, encryption, and others.
  • Broad knowledge of IT infrastructure, operating systems, and cloud systems.
  • Knowledge of the systems and operations used within the areas and departments of responsibility.
  • Excellent verbal and written communication skills.
  • Ability to oversee and coordinate activities of assigned staff.
  • Ability to effectively communicate with other colleagues, supervisors, administrative staff, and other campus/agency units.
  • Ability to identify and resolve technical and personnel problems.
  • Ability to effectively communicate and professionally interact with all staff levels.

Preferred Qualifications (SPS)

  • At least seven (7) years of experience in information security, with three (3) years in a leadership role
  • Professional certifications such as CISSP, CISM, or other relevant security certifications are preferred.
  • Excellent leadership, communication, and analytical skills.
  • Experience with security compliance regulations such as HIPAA, GLBA, PCI DSS, and others.

Physical demands/requirements

  • Sitting for extended periods of time
  • Using computer/electronic equipment for extended periods of time
  • Occasional lifting and moving items weighing up to 40 lbs.

Appointment and Compensation Details

Appointment and Compensation Details

Anticipated Appointment Start Date April 1, 2023 Anticipated Appointment End Date Percent of Staff Year 1.00 Standard Hours Per Week 37.50 Working Hours Mon - Fri, 8:00am - 4:30pm; Some evenings and weekends may be required. Salary $155,068.56/annually; NIU offers a robust benefits package. Hourly or Semi-monthly Pay Rate/Range $6,461.19/semi-monthly Earn Type Salary

Application Procedure

Application Procedure

Application Procedure

For full consideration, please visit https://employment.niu.edu/postings/96024 to submit the following materials by 9/16/2026:

Required Documents:

  • Cover Letter - Please include your interest in employment with NIU and how your previous experiences position you for success in the role for which you are applying.
  • Current Resume
  • List of Three Professional References
  • Unofficial Transcripts (official transcripts will be required within 30 days of start date)

Applications submitted after 9/16/2026 are welcomed but will be considered as needed.

Special Instructions Quick Link to Applicant https://employment.niu.edu/postings/96024 Is Background Check Required? Yes EEO Statement Summary

In accordance with applicable statutes and regulations, NIU is an equal opportunity employer and does not discriminate on the basis of race, ethnicity, color, national origin, ancestry, sex, religion, age, disability (physical and mental), marital status, veteran status, sexual orientation, gender (identity and expression), political affiliation, or any other factor unrelated to professional qualifications, and will comply with all applicable federal and state statutes, regulations and orders pertaining to nondiscrimination, equal opportunity and affirmative action.

The following person has been designated to handle inquiries regarding the non-discrimination policies:

Ethics and Compliance Officer, Title IX Coordinator

Health Services Building Room 230

TitleIXCoordinator@niu.edu

815-753-5560

Visa Policy

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.

ADA Accommodation

NIU remains committed to ensuring that its recruitment and application procedures include full opportunities for applicants with disabilities. Employment opportunities will not be denied to anyone because of the need to make accommodations for a person's disability during either the application or interview process. An applicant who believes they require an accommodation to participate in the employment process due to a disability may request that accommodation through the Accommodation Request Form. For further assistance, please contact the office of Affirmative Action and Equal Opportunity (AAEO) at ada@niu.edu.

Safety Information

NIU provides annual reports on campus security and fire safety.

Read the Annual Security and Fire Safety Report.

Contact the Ethics and Compliance Office at 815-753-9364 for a hard copy.

Applicant Documents

Required Documents

  • Resume/Curriculum Vitae
  • Cover Letter
  • List of at least 3 Professional References

Optional Documents

  • Transcripts (unofficial with official required at hire)
  • Other

Supplemental Questions

Required fields are indicated with an asterisk (*).

Numbers & Facts

LocationDeKalb, IL

Skills

  • Academic Researchunmatched
  • Affirmative Actionunmatched
  • Analysis Skillsunmatched
  • Asset Managementunmatched
  • Budget Managementunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Contract Reviewunmatched
  • Cryptographyunmatched
  • Disaster Recoveryunmatched
  • Documentation Reviewunmatched
  • Endpoint Securityunmatched
  • External Auditunmatched
  • Federal Laws and Regulationsunmatched
  • Financial Trend Analysisunmatched
  • Firewallsunmatched
  • Forensic Scienceunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • ISO (International Organization for Standardization)unmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Intrusion Detection Systemsunmatched
  • Intrusion Detection and Prevention (IDP)unmatched
  • Inventory Managementunmatched
  • Law Enforcementunmatched
  • Leadershipunmatched
  • Lift/Move 40 Poundsunmatched
  • Local Area Network (LAN)unmatched
  • Maintain Complianceunmatched
  • Mentoringunmatched
  • Network Administration/Managementunmatched
  • Operating Systemsunmatched
  • Operational Strategyunmatched
  • Organizational Skillsunmatched
  • PCI-DSSunmatched
  • Penetration Testingunmatched
  • Performance Analysisunmatched
  • Performance Metricsunmatched
  • Physical Securityunmatched
  • Policy Implementationunmatched
  • Presentation/Verbal Skillsunmatched
  • Privacy Regulationsunmatched
  • Problem Solving Skillsunmatched
  • Procedure Implementationunmatched
  • Process Improvementunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Management Framework (RMF)unmatched
  • Security Analysisunmatched
  • Security Attacksunmatched
  • Security Auditingunmatched
  • Security Complianceunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Security Policyunmatched
  • Service Level Agreement (SLA)unmatched
  • State Laws and Regulationsunmatched
  • Strategic Planningunmatched
  • System Operationsunmatched
  • Technical Supportunmatched
  • Test Plan/Scheduleunmatched
  • Testingunmatched
  • Training/Teachingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • University/School Policiesunmatched
  • Vendor/Supplier Evaluationunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder