Director of Security Assurance
Inside Higher Ed
Position Title
Director of Security Assurance
Location
Hanover, NH (Hybrid remote work eligible)
Position Purpose
The Director of Security Assurance leads Dartmouth’s cybersecurity governance, risk, and compliance functions within the Office of Information Security. The role establishes and maintains the institutional security policy framework, enterprise risk management program, third‑party risk oversight, awareness initiatives, and audit support processes, translating complex regulatory and research security requirements into actionable institutional standards. In a decentralized academic environment with shared governance, the Director advises the CISO and senior leadership on institutional cyber risk posture, ensures compliance with applicable federal and state requirements, and partners across academic and administrative units to embed security and risk management practices that support Dartmouth’s teaching, research, and clinical missions.
Responsibilities
- Develop, implement, and maintain Dartmouth’s cybersecurity policy framework aligned with NIST CSF 2.0 and CIS Controls v8 for institutional systems, research computing, and cloud services.
- Draft and maintain enforceable standards, procedures, and guidelines that reflect Dartmouth’s shared governance environment and distributed operational model.
- Manage the full policy lifecycle, including drafting, stakeholder consultation, governance review and approval, publication, version control, exception management, and periodic review.
- Translate regulatory and contractual obligations (FERPA, GLBA Safeguards, HIPAA, NIST SP 800‑171, CMMC, ITAR/EAR, PCI DSS, NH RSA 359‑C:20) into clear, actionable institutional requirements.
- Design, implement, and continuously improve a formal cybersecurity risk management program covering risk identification, assessment methodology, scoring, treatment planning, risk acceptance, and exception workflows.
- Lead and facilitate risk assessments across institutional systems, research computing environments, cloud platforms, and third‑party integrations.
- Maintain an enterprise cybersecurity risk register and present risk posture and trends to the CISO, senior leadership, and the Board of Trustees in non‑technical language.
- Develop and oversee a comprehensive third‑party risk management program, including intake workflows, vendor tiering, security assessment criteria, and ongoing monitoring.
- Evaluate vendors, SaaS providers, cloud services, and research collaborators for alignment with institutional security standards and regulatory requirements.
- Partner with Procurement, the Office of General Counsel, and Research Administration to integrate security review into contracting, vendor onboarding, and research partnership processes.
- Monitor and report on aggregate third‑party risk exposure, prioritizing mitigation based on risk severity and concentration.
- Design and lead a comprehensive cybersecurity awareness and training program tailored to faculty, staff, students, and researchers, including role‑based curricula for high‑risk populations.
- Oversee phishing simulations, tabletop exercises, and targeted awareness initiatives aligned with current threat trends and institutional risk priorities.
- Establish and track metrics to evaluate behavioral change, training effectiveness, and risk reduction.
- Define and maintain key performance and risk indicators that inform decision‑making at the CISO, CIO, executive leadership, and Board levels.
- Develop dashboards and recurring reports that communicate program maturity, compliance posture, risk exposure, and operational effectiveness in accessible language.
- Benchmark institutional cybersecurity capabilities against higher education peers using available EDUCAUSE, REN‑ISAC, and Ivy Plus cohort data.
- Serve as the primary information security liaison for internal and external audits, compliance reviews, and regulatory inquiries.
- Oversee control mapping, evidence collection, gap assessments, and remediation tracking across applicable regulatory frameworks.
- Partner with Research Administration to support compliance requirements for federally funded and export‑controlled research (NIST SP 800‑171, CMMC, ITAR/EAR).
- Maintain audit‑ready documentation and ensure corrective actions are tracked through completion.
- Demonstrate professionalism and collegiality through actions, interactions, and communications with others appropriate to a welcoming environment.
- Perform other duties as assigned.
Required Qualifications
- Bachelor’s degree plus six or more years’ experience, or an equivalent combination of education and experience.
- Minimum of 10 years progressive professional experience in cybersecurity, including at least 5 years in governance, risk, and compliance leadership roles.
- Demonstrated experience designing, implementing, and maturing cybersecurity governance, risk, and compliance programs.
- Ability to conduct risk assessments, develop enforceable policies and standards, configure and optimize GRC platforms, and perform compliance gap analyses.
- Direct experience with at least two of the following regulatory or compliance frameworks: NIST SP 800‑171, CMMC, HIPAA, FERPA, GLBA Safeguards, PCI DSS, ITAR, and EAR.
- Demonstrated application of established security frameworks, such as NIST CSF, NIST RMF, CIS Controls, or ISO 27001, to structure and advance enterprise security programs.
- One or more current industry certifications, such as CISSP, CISM, CRISC, CGRC, or CISA, or equivalent credentials.
- Proven ability to communicate complex security and risk concepts effectively to executive leadership, faculty governance bodies, and technical stakeholders.
- Experience leading, hiring, mentoring, and developing cybersecurity or GRC professionals.
Preferred Qualifications
- Master’s degree in cybersecurity, information security, risk management, or a related field.
- Experience in an R1 or R2 research university, academic medical center, or complex multi‑entity higher education environment.
- Experience supporting or managing controlled unclassified information environments, including Department of Defense‑funded research subject to NIST SP 800‑171 or CMMC requirements.
- Experience operating effectively in decentralized organizations where influence, relationship building, and consensus development are critical to success.
- Experience assessing and governing security and privacy risks associated with artificial intelligence and machine learning systems, including generative AI adoption, data exposure risks, and institutional AI governance frameworks.
Equal Opportunity Statement
Dartmouth College is an equal‑opportunity employer under federal law. We prohibit discrimination on the basis of race, color, religion, sex, age, national origin, sexual orientation, gender identity or expression, disability, veteran status, marital status, or any other legally protected status. Applications are welcome from all.
Background Check
Employment in this position is contingent on consent to and successful completion of a pre‑employment background check, which may include a criminal background check, reference checks, verification of work history, conduct review, and verification of any required academic credentials, licenses, and/or certifications, with results acceptable to Dartmouth College. A criminal conviction will not automatically disqualify an applicant from employment. Background check information will be used in a confidential, non‑discriminatory manner consistent with state and federal law.
#J-18808-Ljbffr- ...Americas Country: USA State/Province: Texas City: Richardson Summary We are seeking an experienced and strategic Director of Data Security and Governance to lead our comprehensive data protection program. This critical role involves establishing and enforcing...SuggestedWork at office
- ...Key Accountabilities Distribute food to support food security and food equity, maintaining respect and dignity for everyone in... ...of donated food within the warehouse. Support the Operations Director and Warehouse Coordinator in managing WH food inventory, loading...SuggestedFull timeWork at officeLocal areaShift work
- ...cybersecurity reporting deliverables, including monthly scorecards and status updates for stakeholders. - Coordinate with designated security personnel and operational teams to ensure alignment on security actions and deliverables. - Ensure all cybersecurity...SuggestedMinimum wageContract workTemporary workWork experience placement
- ..., including coordinating and executing directed cyber activities. - Lead and support containment and restoration efforts during security incidents, ensuring timely resolution and stabilization of affected systems. - Ensure all response actions are fully documented...SuggestedMinimum wageContract workTemporary workWork experience placementRemote workShift work
- ...Proven ability to lead, schedule, and motivate large, diverse teams. (50+ employees with high turnover). This role reports to the Director of Operations. Problem Solver: "Rolling up your sleeves" mentality—comfortable on the floor/in the field, resolving urgent, on...SuggestedMonday to FridayFlexible hoursShift workAfternoon shift
$85 - $100 per hour
KBW Financial Staffing & Recruiting is seeking an interim CFO for a client in Enfield, New Hampshire. This hands-on role involves leading financial operations, managing accounting functions, and overseeing IT and HR. The ideal candidate will have software or SaaS experience...Hourly payInterim role$20.29 per hour
...is currently seeking leaders who want to grow with us in a fast paced environment. Major Duties: Controls, accounts for and secures all cash stored in the canteen safe as well as all safe transactions involving petty cash, change funds, withdrawals of funds, coupon...Hourly paySeasonal work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Security Assurance. Be the first to apply!

