Senior Director of Information Security
Job Description
The Senior Director of Information Security serves as Berklee’s primary information security authority and hands-on technical leader. Operating in a high-impact, lean team environment, the Sr. Director balances strategic governance, policy development, and budget management with active technical leadership. Reporting to the VP & CIO, the Sr. Director directly supervises the Information Security Analyst and works collaboratively across IT operations to protect Berklee's digital assets, ensure regulatory compliance, and lead incident response efforts.
The Sr. Director of Information Security possesses a strong technical background in risk management, threat mitigation, and technical controls. As a hands-on leader, they provide strategic vision and technical guidance both to the internal security function and to cross-functional IT operations and engineering teams to build a secure, scalable environment across Berklee’s global networks, applications, and systems.
In partnership with executive leadership and the Office of General Counsel, this role develops, maintain, and enforces the College’s Information Security Policy, standards, and awareness programs to ensure compliance with relevant statutes and regulations. The Sr. Director oversees security system architecture, evaluates emerging technologies, and serves as the primary subject manager expert for enterprise security design.
Additionally, the Sr. Director manages Berklee's overarching IT security strategy, roadmap, and budget. This role requires exceptional communication skills, including the ability to translate complex technical risks into clear concepts for leadership, faculty, staff, and external partners.
ESSENTIAL JOB DUTIES
Operational & Technical Leadership
- Establish, monitor, and optimize security processes and technical controls to prevent unauthorized access to Berklee's networks, systems, and cloud environments.
- Directly supervise, mentor, and manage the performance and professional development of the Information Security Analyst.
- Implement security automation, orchestration, and streamlined workflows to maximize team efficiency and reduce repetitive manual tasks.
- Partner with broader IT operations, networking, and engineering teams to provide hands-on security guidance, ensure proper protocol implementation, and promote security awareness across the division.
Strategic, Financial & Governance Oversight
- Develop, maintain, and enforce institutional IT security policies and programs in alignment with legal regulations (e.g., FERPA, PCI, GDPR, etc.) and higher ed standards.
- Oversee IT security budget processes, forecast costs, negotiate vendor contracts, and manage security-related procurements to align with institutional goals.
- Facilitate third-party security audits, risk evaluations, and vendor security reviews (including HECVAT assessments).
- Actively participate in the IT division’s change management process to ensure new systems and...