We are excited that you are considering joining Nova Southeastern University!
Nova Southeastern University (NSU) was founded in 1964, and is a not-for-profit, independent university with a reputation for academic excellence and innovation. Nova Southeastern University offers competitive salaries, a comprehensive benefits package including tuition waiver, retirement plan, excellent medical and dental plans and much more. NSU cares about the health and welfare of its students, faculty, staff, and campus visitors and is a tobacco-free university.
We appreciate your support in making NSU the preeminent place to live, work, study and grow. Thank you for your interest in a career with Nova Southeastern University.
Primary Purpose:
Serves as the Deputy CISO and senior operational leader for the University’s information security program, providing enterprise-wide leadership for cybersecurity operations, staff, risk management, and security governance. Directs effective delivery, resilience, and continuous improvement of cybersecurity operations while supporting the University’s enterprise security strategy and protecting institutional information assets and systems.
Job Category: Exempt
Hiring Range:
Pay Basis: Annually
Subject to Grant Funding? No
Essential Job Functions:
1. Plans, directs, supervises, and coordinates work activities of subordinates and staff, including hiring, coaching, evaluating, and terminating, all in accordance with university policies and procedures.
2. Oversees day-to-day security operations, including continuous monitoring, alert triage, escalation, and closure quality, and establishes and enforces documented service levels for detection and response.
3. Leads the incident response program, including the incident response plan, playbooks, severity classification, on-call and escalation structure, incident command, executive communication during active incidents, and post-incident review and lessons learned.
4. Manages the university’s managed detection and response provider, including scope, service level performance, escalation quality, coverage validation, contract and renewal input, and integration with internal operations.
5. Manages the operational vulnerability management program, including scanning cadence, risk-based prioritization, remediation coordination with infrastructure and application owners, exception handling, and closure verification.
6. Establishes and maintains the threat intelligence function, including intelligence sources, indicator management, sector-specific intelligence sharing, and translation of intelligence into detection and hardening actions.
7. Develops, publishes, and reports security operations metrics, including mean time to detect, mean time to respond, alert disposition, coverage, and remediation performance, for the CISO and executive leadership.
8. Acts with delegated authority on behalf of the Chief Information Security Officer in their absence on operational and incident matters.
9. Develops staffing plans, on-call schedules, coverage models, and analyst career development paths; conducts performance management, coaching, and skills development for assigned staff.
10. Designs and facilitates tabletop exercises, purple team activity, and incident response readiness testing in coordination with the Senior Security Engineer and the Manager of Security Governance, Risk, and Compliance.
11. Ensures security operations activity produces the documentation and evidence required for audit, regulatory examination, and cyber insurance requirements.
12. Coordinates security operations activity with Infrastructure, Client Technology, Enterprise Applications, Legal, Compliance, Public Safety, and external law enforcement as appropriate.
Provides strategic input to the information security operating budget, including staffing, cybersecurity tools, technology, and managed service investments.
13. Supports business continuity and disaster recovery planning and execution as it relates to security operations.
14. Completes special projects as assigned.
15. Performs other duties as assigned or required.
Job Requirements:
Required Knowledge, Skills, & Abilities: Knowledge:
1. Comprehensive knowledge of security operations center practices, including monitoring, triage, escalation, and shift or on-call coverage models.
2. Comprehensive knowledge of incident response methodology, incident command, evidence handling, and post-incident analysis.
3. Comprehensive knowledge of vulnerability management practices, risk-based prioritization, and remediation governance.
4. Working knowledge of SIEM, endpoint detection and response, and security orchestration and automation platforms.
5. Working knowledge of the MITRE ATT&CK framework, threat intelligence practices, and adversary tradecraft relevant to higher education and healthcare.
6. Working knowledge of managed security service provider oversight, service level management, and vendor performance evaluation.
7. Working knowledge of regulatory breach notification and reporting obligations, including HIPAA, GLBA, PCI-DSS, and state breach notification law.
8. Working knowledge of supervisory practices, performance management, and University human resources policies and procedures.
Skills:
1. Complex Problem Solving – Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
2. Leadership and Supervision – Proficient skills in directing, coaching, evaluating, and developing technical staff.
3. Crisis Management – Advanced skills in leading and communicating during active, high-severity security incidents.
4. Executive Communication – Proficient skills in briefing senior leadership clearly and accurately under time pressure and incomplete information.
5. Process Design – Proficient skills in building repeatable operational procedures, playbooks, and measurable service levels.
Abilities:
1. Ability to lead a small team through sustained operational demand and high-severity events.
2. Ability to exercise independent judgment and delegated authority in the absence of the Chief Information Security Officer.
3. Ability to balance operational urgency against institutional impact on academic, clinical, and research activity.
4. Ability to maintain composure, objectivity, and confidentiality during sensitive investigations.
5. Ability to hold peer departments and external providers accountable to remediation and service commitments.
Physical Requirements and Working Environment:
1. Speech Recognition - Must be able to identify and understand the speech of another person.
2. Speech Clarity - Must be able to speak clearly so others can understand you.
3. Near Vision - Must be able to see details at close range (within a few feet of the observer).
4. Travel - Must be able to travel on a daily and/or overnight basis.
5. May be required to work nights or weekends.
6. May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
7. May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.
Required Certifications/Licensures: Must possess one of the following certifications at the time of hire or obtain at least one (1) within twelve (12) months of hire and maintain it in good standing throughout employment:
Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM).
Required Education: Bachelor’s degree
Major (if required:
Required Experience: Minimum ten (10) years of leadership experience in information security, including experience in security operations, incident response, and supervising cybersecurity staff or equivalent formal leadership responsibility.
Preferred Qualifications:
1. Experience in higher education, academic health, or another complex, decentralized environment.
2. Experience managing a managed detection and response or co-managed security operations provider.
3. Experience leading response to a major security incident with executive and legal involvement.
4. Experience building a security operations function or formalizing an informal one.
5. Experience with cyber insurance requirements and incident notification workflows.
Is this a safety sensitive position? No
Background Screening Required? Yes
Pre-Employment Conditions:
Sensitivity Disclaimer: Nova Southeastern University is in full compliance with the Americans with Disabilities Act (ADA) and does not discriminate with regard to applicants or employees with disabilities and will make reasonable accommodation when necessary.
NSU is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion, creed, gender, national origin, age, disability, marital or veteran status or any other legally protected status.
We use cookies.
Some are necessary to operate the website and its functions. Others help personalize, improve content and services to show you the most relevant job opportunities. With the decision "Accept essential only" we will respect your privacy and will not set cookies that aren't necessary for the operation of the site.