Director, Information Security

Brown University

Providence, RI, USA
**
Security engineering oversight
Security operations oversight
Information compliance & risk oversight
** Brown University is seeking a Director of Information Security to lead its cybersecurity program within the Office of Information Technology. The role requires extensive experience in IT security, leadership capabilities, and a thorough understanding of compliance and risk management. **

Job Summary

  • The Director provides strategic and operational oversight for three critical pillars of the University’s cybersecurity program: Security Engineering, Security Operations, and Information Compliance & Risk.
  • This role is responsible for translating institutional vision into actionable plans, ensuring that Brown’s digital assets are protected through robust engineering, that security incidents are managed with precision, and that the University maintains a rigorous posture regarding IT risk and regulatory compliance.
  • Acting as a key liaison between technical practitioners, University leadership, and administrative departments (including the Office of General Counsel and Brown Risk, Audit, and Compliance teams), the Director fosters a culture of continuous improvement and proactive risk management.

Matching Summary

Match Score: 75

** Brown University is seeking a Director of Information Security to lead its cybersecurity program within the Office of Information Technology. The role requires extensive experience in IT security, leadership capabilities, and a thorough understanding of compliance and risk management. **

Skills & Requirements

Must-have

  • Security Engineering oversight
  • Security Operations oversight
  • Information Compliance & Risk oversight
  • incident management
  • IT risk and regulatory compliance
  • technical subject matter expertise

Nice-to-have

  • fosters a culture of continuous improvement
  • proactive risk management
  • respond to alerts as appropriate

Key Requirements

  • 10+ years of combined IT and IT security experience
  • at least 3 years in a significant leadership role
  • Proven management experience
  • Experience with security operations, incident response, and security engineering
  • Knowledge of privacy regulations (e.g., GDPR, CCPA, FERPA, HIPAA) preferred
  • Industry certifications such as CISSP, CISM, CISA, or equivalent preferred
  • Experience with vulnerability management, and security architecture
  • Experience with cloud security (e.g. Azure, GCP, and AWS) preferred
  • Knowledge of compliance frameworks and regulatory requirements (e.g. NIST 800-171 and PCI DSS)

Work Rights

Not specified

Tailored Resume

Cover Letter