What are the responsibilities and job description for the CISO Director and IT GRC Director position at Southern Illinois University Carbondale?
Description
The Chief Information Security Officer (CISO) and Director of IT Governance, Risk, and Compliance (IT GRC) is responsible for assessing and managing information security and risk operations across the enterprise. This role addresses the intersection of governance, security, and compliance with legislative and regulatory mandates. The position encompasses information security governance, risk management, and compliance as they relate to technology, operations, and strategy, striving to balance IT security concerns with compliance requirements. The ability to make sound decisions under pressure is essential.
As the campus CISO, the director develops and enforces policies and standards related to information security, compliance, business continuity, disaster recovery, IT governance, data management, change management, and project management. The role involves reviewing proposed projects to identify and address potential risks, classifying and evaluating enterprise data assets, and tracking the costs associated with risk management initiatives. The director is also responsible for assessing IT purchases and contracts to ensure they meet security and compliance requirements.
The director also leads efforts to streamline operations by overseeing the automation of internal controls and the centralization of logging and reporting processes, ensuring efficiency and regulatory compliance. A vital part of the role involves coordinating internal and external audits to confirm adherence to applicable regulations and standards. To enhance organizational resilience, the director conducts disaster recovery training, develops and executes risk mitigation initiatives, and creates tailored information security and risk awareness programs for the campus community.
Stakeholder engagement is a critical component of this role, particularly within the dynamic environment of higher education. The director works closely with a diverse array of campus stakeholders, including academic departments, administrative units, research organizations, IT teams, and external partners. This engagement ensures alignment of security and compliance initiatives with the institution’s academic, research, and operational objectives. The director facilitates regular communication with faculty and staff to raise awareness of evolving cybersecurity threats and compliance requirements, fostering a culture of shared responsibility for safeguarding institutional resources.
This role requires a strategic mindset, strong decision-making skills, and the ability to effectively integrate governance, risk, and compliance practices into enterprise operations while building meaningful and productive partnerships across the institution.
The target salary offer for this position is$8,333.00 - $10,417.00 monthly, the full pay range for this position is $100,000.00 - $125,000.00. Final salary offer will be determined by a thorough assessment of available market data, internal salary equity, candidate experience and qualifications, and budget constraints.
Examples of Duties
- Work with the CIO and campus leadership to align the IT organization with business unit security, compliance, and continuity needs.
- Serve as campus Chief Information Security Officer (CISO)
- Develop and institute continuity, security, and compliance goals and objectives.
- Create and enforce continuity, security and compliance policies and standards.
- Work closely with the system IT leadership to plan and align multi-campus initiatives, efforts, and shared services.
Establish guiding principles for flexible, yet holistic, programs for:
- Information security
- Compliance management.
- Business continuity and disaster recovery
- IT governance
- Work with campus leadership to mature third-party risk assessment practices and standards.
- Develop and maintain Change and Project management principles and practices for the IT organization.
- Review proposed projects and efforts to identify potential risks.
- Classify and valuate enterprise data assets.
- Project and track costs of risk management initiatives.
- Design a framework for dedicated security and compliance roles with segregation of duties as a fundamental factor.
- Identify and deploy standard risk assessment models or frameworks, such as CIS Controls.
- Select and deploy appropriate best practices governance frameworks, such as COBIT.
- Create and communicate strategies for risk mitigation.
Acquisition & Deployment
- Assess all IT purchases and contracts to ensure they support security and compliance mandates.
- Oversee the deployment of an integrated security and risk management framework and toolset.
o Develop a roadmap for framework and toolset deployment.
- Manage the budget and track costs associated with project, information security, and risk management initiatives.
Operational Management
- Track and measure the enterprise’s risk posture.
- Review day-to-day management of IT security operations to validate compliance
- Set standards for automation of internal controls and centralizing logging and reporting.
- Set standards for securing of all platforms and centralizing security event management.
- Coordinate internal and external audits, ensuring all campus compliance requirements are met and documented.
- Schedule and launch periodic audit reviews.
- Conduct periodic disaster recovery training and preparedness exercises.
- Plan and oversee risk mitigation and remediation projects.
- Develop and deliver security and risk awareness training for key staff and stakeholders.
- Develop and operate programs for stakeholder engagement, service delivery monitoring and continuous improvement.
Qualifications
- Bachelor's degree, preferably in Management, Management Information Systems, Computer Science, or related field by date of hire.
- Seven (7) years project management experience.
- Seven (7) years or more of progressive experience in Information Technology management positions
- Three (3) years GRC experience
- One (1) year of strategic planning experience in an IT environment
Preferred Qualifications:
- Master's degree preferably in Business Administration, Information Systems, or relevant advanced degree
- Leadership experience in Higher Education
- Progressive leadership experience in identifying and implementing GRC programs
- PMP Certification
Required Documents: Submit a letter of application, current CV, and three references.
Contact: Gail Odaniell, gailo@siu.edu
Supplemental Information
Southern Illinois University Carbondale is a Carnegie Doctoral Research University offering 200 undergraduate degrees, minors and specializations, 79 master’s degrees, and 40 doctoral degrees. Our main campus is 1,136 acres, with additional acreage in University Farms, Touch of Nature Outdoor Education Center, and other facilities. The university is an essential part of the city of Carbondale and an important contributor to the culture of the entire region. While Carbondale includes many of the amenities of urban life, it retains its small-town flavor. Cost of living is considerably lower in the region than similar areas elsewhere, and many employees commute from nearby counties.
The Southern Illinois region is distinct from the rest of the state, boasting considerable natural beauty including the Shawnee National Forest, many state parks, national wildlife areas, and several lakes beloved for recreation. Local foods are readily available in the area, with a variety of eateries and a growing specialized food truck presence. The area is home to the Shawnee Hills Wine Trail, an official wine appellation designation. The wineries extend the cultural reach of the community, hosting live music and continual art exhibits. The campus itself is a microcosm of the area, with a lake and forest on campus, as well as traditional collegiate architecture, quad, and residential halls. Students enjoy outdoor study areas as well as specialized computer labs scattered across campus, including in the three million volume Morris Library. To learn about employee benefits and find resources about Carbondale and the Southern Illinois region, visit: https://jobs.siu.edu/.
SIU Carbondale, member of the SIU System, is an anti-racist community that opposes racism, discrimination and inequity in any form, and embraces diversity, inclusion, equity, and justice for all people.
SIU Carbondale is an Affirmative Action/Equal Opportunity Employer of individuals with disabilities and protected veterans that strives to enhance its ability to develop a diverse faculty and staff and to increase its potential to serve a diverse student population. All applications are welcomed and encouraged and will receive consideration.
University employees may be eligible for a variety of State of Illinois benefits. These benefits are administered through the Illinois Department of Central Management Service (CMS). These benefits include: Health Insurance plans (HMOs, OAPs, QCHP and CDHP), Dental Insurance, Vision Plan, Life Insurance, Accidental Death & Dismemberment (AD&D), Supplemental Long Term Disability (LTD), Flex Spending Accounts, MCAP and DCAP, and 457(b) Deferred Compensation Plan.
Eligible employees are required to participate in the State Universities Retirement System (SURS). SURS is the retirement administrator for employees in public higher education in the State of Illinois.
Other benefits available to eligible employees include: Generous paid time-off, 403(b) Supplemental Retirement Plans, Employee Assistance Program and a Tuition Waiver Program.
For more information please visit: https://hr.siu.edu/benefits/Salary : $100,000 - $125,000