Jobs · Maryland

Director, IT Security & Technology

Catholic Charities of Baltimore · Baltimore, MD · 2 wk ago
$158k–$163k/yrFull-time

Salary: $158,000 – $163,000 per year

About the role

Catholic Charities of Baltimore is seeking a Director of IT & Security to design, implement, and maintain the Agency’s cybersecurity strategy. This senior-level role safeguards sensitive data, systems, and networks from cyber threats, ensures regulatory compliance, and implements best practices to protect data and maintain stakeholder trust. The Director provides leadership to manage risk, aligning IT security with business objectives, governance, and system availability, integrity, and confidentiality in coordination with IT functions, the Agency compliance committee, divisions, and departments.

The hybrid work schedule is Monday – Friday, 8:30am – 4:30pm (3 days in the office / 2 days at home).

Responsibilities

  • Ensure an adequate level of information security protection and risk management, including the confidentiality, integrity, and availability of Agency data and other information assets. Regularly assess security controls, ensure compliance with policies, and hold stakeholders accountable for addressing vulnerabilities.
  • Develop and manage the frameworks, processes, and tools necessary for IT to properly manage security risks and make informed, risk-based decisions. Monitor performance, assess compliance, and hold stakeholders responsible for adhering to security protocols.
  • Conduct regular risk assessments and vulnerability tests to identify potential security threats and develop strategies to mitigate them.
  • Manage, monitor, and analyze security incidents, investigate breaches, and implement corrective actions to prevent future incidents.
  • Maintain subject matter expertise on the latest industry trends, threats, and technologies to ensure the Agency's IT security measures are current and effective.
  • Develop and manage the Agency's security policies and procedures. Collaborate with Agency Programs to integrate security requirements into the design and implementation of new systems and technologies.
  • Develop, implement, and manage security awareness programs to educate employees about security best practices and promote a culture of security within the organization.
  • Manage relationships with external vendors and partners to ensure security controls are effectively implemented and maintained.
  • Lead the cybersecurity strategy and technology roadmap, assessing existing, new, and emerging technologies. Oversee endpoint protection strategy for all Agency computing systems.
  • Manage Agency compliance for relevant data privacy regulations, changing laws, and industry standards including but not limited to HIPAA, ISO27001, CISA, GDPR, and PCI DSS.
  • Prepare and present regular reports to senior management on the Agency's IT security posture, including insights, recommendations, and metrics.
  • Lead IT disaster recovery initiatives, ensuring they are current and tested as per the IT Disaster Recovery policy/procedures. Develop effective disaster recovery policies and standards aligned with business continuity management goals.
  • Provide technical/security training, knowledge transfer, and mentorship to IT colleagues.
  • Co-lead technology architecture decisions across Agency application and network enterprise domains, enforcing compliance with architectural standards, avoiding inefficiencies, and managing security risks.
  • Perform other duties as assigned.

Requirements

  • Bachelor's degree in Computer Science, Information Technology, or a related field. Combination of education and experience may be considered.
  • 5+ years of experience designing and delivering comprehensive security solutions, including technical and non-technical components.
  • 10+ years of experience in IT, including infrastructure, cloud/hybrid environments, networking, and end-user computing.
  • Proven experience in an IT security technical leadership role with a track record of successfully implementing and managing IT security programs.
  • Strong knowledge of relevant regulations and standards, such as GDPR, HIPAA, and ISO 27001.
  • Experience with risk management methodologies and frameworks.
  • Familiarity with project management principles and practices.
  • Excellent written and verbal communication skills.
  • Strong attention to detail and the ability to prioritize and manage multiple tasks simultaneously.

Qualifications

  • Professional certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CISA (Certified Information Systems Auditor) are highly desirable.

Skills

  • Strong communication and interpersonal skills, with the ability to effectively communicate complex security concepts to both technical and non-technical stakeholders.
  • In-depth knowledge of IT security principles, best practices, and industry standards.
  • Excellent problem-solving and analytical skills, with the ability to identify and mitigate security risks.
  • Familiarity with security tools and technologies, such as firewalls, intrusion detection and prevention systems, encryption, and antivirus software.
  • Strong knowledge of privacy and security frameworks. Experience implementing and managing CIS Top 20 controls is a plus.
  • Knowledge of network and system administration.
  • Proven skills with Microsoft Entra Domain Services, Microsoft 365, SAN, server, networking, VOIP, unified communication, virtualization, and end-user computing, including endpoint device management (PCs, tablets, smartphones, and other mobile devices) and helpdesk solutions.
  • Demonstrated knowledge of accounting, payroll, human resources, information systems, and healthcare applications is a plus.
  • Proficiency in conducting risk assessments and vulnerability testing.
  • Familiarity with regulatory requirements and industry standards related to IT security.
  • Demonstrated knowledge of Aruba Wireless, ClearPass, and Watchguard technologies is a plus.
  • Proven working knowledge of technologies such as cloud computing, AI, cybersecurity, and data analytics.
  • Ability to act with discretion, tact, and professionalism in all situations.
  • Ability to utilize computer systems and software necessary to perform position functions. Basic Windows PC, web browsing (e.g., Chrome, Internet Explorer), and Microsoft Outlook skills required. Knowledge of other Microsoft Office applications (Word, Excel, PowerPoint, Teams, OneDrive) is desired.

Physical Requirements & Work Environment

  • Sedentary work that primarily involves sitting/standing.
  • Remaining in a stationary position, often standing or sitting for prolonged periods.
  • Communicating with others to exchange information.
  • Adjusting or moving objects up to 15 pounds in all directions, regularly throughout the day.
  • Repeating motions that may include the wrists, hands, and/or fingers.
  • Assessing the accuracy, neatness, and thoroughness of the work assigned.

Benefits

  • Health/Dental/Vision coverage
  • Vacation/sick/holiday pay
  • 403(b) Retirement Plan with a discretionary employer contribution
  • Tuition Advancement
  • Paid Parental Leave

Similar jobs

Director, IT & Security

Equal Opportunity VenturesNew York, NY· 1 mo ago
Information Technology$200k–$250k/yrapply on jobs.eoventures.com

Director, IT & Security

TonalAustin, Texas Metropolitan Area· 1 mo ago
RemoteInformation Technologyapply on tonal.com