Jobs · Virginia

Senior IT Security and Compliance Manager

Virginia Tech Academy of Data Science · Blacksburg, VA · 1 wk ago
$90k–$110k/yrFull-time

Hybrid position based in Blacksburg, Virginia.

About the Role

Serve as the IT security expert helping to create a strong information technology security foundation for the President, Executive Vice President and Chief Operating Officer, and Executive Vice President and Provost senior management areas. Reporting to the Deputy Executive Director, Business and Management Systems, this position provides information security and compliance services to all supported departments. The role ensures that all workstations, server systems, applications, networks, databases, and data are properly secured from threats while meeting mission-critical production environment requirements and uptime. Serves as a departmental contact for any issues relating to information security or compliance with regulatory guidance. Shares responsibility for monitoring and maintaining systems, disaster recovery planning, incident response, and security assessments. Due to the criticality of this position and its support of a 24/7 unit, after-hours work may be required.

Responsibilities

  • Manage compliance with CIS IG2 throughout supported areas.
  • Manage Microsoft Defender for Endpoint for supported areas to prevent, detect, investigate, and respond to advanced cyber threats.
  • Coordinate and run security training programs for data protection and adherence to university standards and policies.
  • Run scripts and programs to provide vulnerability checks against department servers and web applications.
  • Assist in the design and implementation of appropriate access protection and audit control procedures.
  • Routinely monitor practices to ensure that user access, system access, resources, and information are secure.
  • Communicate threats, findings, and mitigation strategies effectively to supported areas when necessary.
  • Manage and participate in the procurement and departmental security review processes.
  • Provide guidance, tools, and subject matter expertise for departments performing IT risk assessments.
  • Lead, develop, and mentor employees involved in compliance and risk-related activities.
  • Serve as liaison between supported offices and the IT Security Office.
  • Author and improve documentation to support consistent and reliable procedures.
  • Work with and advise the Deputy Executive Director on IT security policies and standards.

Requirements

  • Bachelor’s degree in Business Information Technology, Computer Science, or a related field or equivalent experience.
  • Significant information security, audit, and/or compliance work experience, with experience measuring compliance against various regulations, industry standards, and/or policies.
  • Demonstrated ability to own and manage multiple projects and programs.
  • Demonstrated ability to effectively communicate, both written and oral, across a broad range of campus audiences.
  • Experience using appropriate security software, such as OWASP ZAP, nikto, and nmap, to perform vulnerability tests.
  • Ability to self-learn and maintain a strong proficiency in technical tools, countermeasures, and techniques.
  • Experience installing, securely configuring, and administering Unix/Linux, OSX, or Windows Server operating systems.
  • Ability to install and configure security software or hardware applications such as firewalls, intrusion detection systems, network mapping tools, and vulnerability scanners.
  • Ability to quickly understand technical concepts and determine the implications of relevant requirements and policies.
  • Strong analytical, organizational, and problem-solving skills.

Preferred Qualifications

  • Master's degree in Business Information Technology or a related field.
  • CISA, CISM, CRISC, or CISSP certification.
  • Experience supervising direct reports or mentoring employees as a team lead.
  • Experience in evaluating business processes and making recommendations for improvements.
  • Experience working in a higher education environment.
  • Experience working with Splunk and Defender for endpoints.
  • Experience working with Snort, Nessus, Rapid 7, OWASP ZAP, Burp Suite, Metasploit, OSSEC, OSSIM, or equivalent tools.

Pay

Salary range of $90,000 - $110,000.

Schedule

  • 40 hours per week.
  • Exempt: Not eligible for overtime.
  • After-hours work may be required due to the criticality of this position.

About Virginia Tech

Dedicated to its motto, Ut Prosim (That I May Serve), Virginia Tech pushes the boundaries of knowledge by taking a hands-on, transdisciplinary approach to preparing scholars to be leaders and problem-solvers. A comprehensive land-grant institution that enhances the quality of life in Virginia and throughout the world, Virginia Tech is an inclusive community dedicated to knowledge, discovery, and creativity. The university offers more than 280 majors to a diverse enrollment of more than 36,000 undergraduate, graduate, and professional students in eight undergraduate colleges, a school of medicine, a veterinary medicine college, Graduate School, and Honors College. The university has a significant presence across Virginia, including Blacksburg, the greater Washington, D.C. area, the Health Sciences and Technology Campus in Roanoke, sites in Newport News and Richmond, and numerous Extension offices and research institutes. A leading global research institution, Virginia Tech conducts more than $650 million in research annually.

Similar jobs