ASU Enterprise Partners logo
ASU Enterprise PartnersPosted 2 weeks ago

​​Director, Cybersecurity and Risk

On-siteScottsdale, Arizona, United States

Full TimeSenior LevelMedium

Job Summary

Lead security risk reduction efforts across enterprise platforms, third-party technology, and institutional initiatives by implementing controls, managing access governance, and translating technical risks into clear business impact. Own the security posture of Microsoft 365, Azure, Google Workspace, Workday, and Salesforce while overseeing incident readiness, vendor security reviews, and audit preparation. Develop security procedures, maintain remediation dashboards, and manage staff to ensure consistent control maturity across Technology & Solutions. Partner with governance, legal, and business units to drive practical risk mitigation and support ASU Enterprise Partners' mission to extend Arizona State University's reach.

Required Qualifications

  • Strong understanding of security risk management, security controls, incident response readiness, vendor security, identity and access governance, data protection, and modern enterprise technology environments
  • Ability to evaluate information security risk for new initiatives and recommend practical mitigation strategies
  • Ability to define secure configuration expectations, access control requirements, monitoring needs, and remediation plans for enterprise platforms
  • Bachelor's degree in cybersecurity, information technology, risk management, information systems, or a closely related field, or an equivalent combination of education and experience
  • At least eight (8) years' experience in information security, technology risk, security operations, IT risk management, or related technology leadership roles
  • At least four (4) years' experience managing employees in a technical environment
  • Experience securing, governing, or assessing enterprise SaaS and cloud platforms such as Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, or comparable enterprise platforms
  • Experience with identity and access management, access governance, privileged access, secure configuration, tenant hardening, data protection, or SaaS governance
  • Experience working cross-functionally with technology, data, legal/procurement, governance/compliance, business, and vendor stakeholders
  • Experience implementing security controls, managing remediation efforts, conducting security reviews, or supporting audit/evidence activities
  • Experience with vendor security reviews, incident response coordination, and security risk communication
  • Ability to maintain a high degree of confidentiality and responsibility regarding information related to Enterprise Partners, its affiliates, university business, confidential constituent information, employee information, financial information, and other sensitive data
  • Ability to communicate effectively and clearly with both technical and non-technical individuals, including executive, legal/procurement, governance/compliance, business, and vendor stakeholders
  • Strong project management, reporting, documentation, and stakeholder communication skills
  • Ability to develop executive-ready summaries, remediation dashboards, risk narratives, procedures, standards, and implementation guidance
  • Ability to work both independently and as part of a team
  • Team-oriented strategist able to effectively manage complex situations involving numerous and sometimes competing constituencies
  • Applies strong knowledge of process and quality improvement
  • Supports planning and management of security-related budgets, vendor spend, and resource needs
  • Ability to represent the institution well
  • Commitment to ASU Enterprise Partners' mission and ASU's vision as the New American University
  • Attention to detail and thoroughness in completing assigned duties
  • Highly organized and able to handle multiple projects
  • Adept at navigating complex environments with evolving priorities and communication plans
  • Willingness to complete relevant Microsoft, Google, cloud security, security operations, or risk-related certifications as appropriate to the role

Desired Qualifications

  • Advanced degree in cybersecurity, information systems, risk management, business, privacy, or a related field
  • Experience in higher education, nonprofit, SaaS/cloud, privacy-sensitive, financial, fundraising, or regulated environments
  • Experience supporting SOC 2, NIST CSF, CIS Controls, internal controls, external assessments, or audit evidence activities
  • Experience developing security procedures, security standards, control implementation guidance, risk summaries, or stakeholder-facing security materials
  • Experience defining security monitoring/logging requirements
  • Experience coordinating access recertifications, privileged access reviews, service account reviews, platform hardening initiatives, or SaaS security posture assessments
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, Security+, Microsoft Security, Azure Security, Google Cloud Security, or similar security/risk credentials

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce