Nova Southeastern University

Security Governance, Risk, and Compliance Manager - 991309 **Hybrid work in the State of Florida**

Nova Southeastern University  •  Hybrid  •  2 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We are excited that you are considering joining Nova Southeastern University!

Nova Southeastern University (NSU) was founded in 1964, and is a not-for-profit, independent university with a reputation for academic excellence and innovation. Nova Southeastern University offers competitive salaries, a comprehensive benefits package including tuition waiver, retirement plan, excellent medical and dental plans and much more. NSU cares about the health and welfare of its students, faculty, staff, and campus visitors and is a tobacco-free university.

We appreciate your support in making NSU the preeminent place to live, work, study and grow. Thank you for your interest in a career with Nova Southeastern University.

Primary Purpose:

Directs the University’s information security governance, risk, and compliance program, including the security control framework, enterprise risk register, policy lifecycle, audits and assessments, third-party risk, security awareness, and AI governance. Translates regulatory, contractual, accreditation, and research security requirements, into documented, tested, and audit-ready controls, serving as the accountable owner for ensuring controls are implemented, effective, and defensible to auditors, regulators, sponsors, and the Board.

Job Category: Exempt

Hiring Range:

Pay Basis: Annually

Subject to Grant Funding? No

Essential Job Functions:

  1. Oversees, maintains, and matures the university’s information security control framework, mapping controls to NIST Cybersecurity Framework 2.0 and cross walking to HIPAA Security Rule, PCI-DSS, GLBA Safeguards Rule, FERPA, NIST SP 800-171/CMMC, and applicable state breach notification law.
  2. Establishes and maintains the enterprise information security risk register, including risk identification, scoring methodology, treatment plans, risk acceptance and exception workflow, executive escalation thresholds, and periodic reassessment.
  3. Manages the information security policy lifecycle — authoring, revising, routing for review and approval, publishing, communicating, and retiring policies, standards, procedures, and guidelines on a defined review cycle.
  4. Leads the university’s response to internal audit, external audit, regulatory examination, cyber insurance underwriting, sponsor security reviews, and customer or partner security questionnaires; coordinates evidence collection, control owner interviews, findings remediation, and corrective action plan tracking to closure.
  5. Designs and operates the third-party and vendor security risk management program, including intake and tiering, pre-contract security assessment, SOC 2 and comparable attestation review, contractual security and breach notification terms in partnership with Legal and Procurement, and ongoing monitoring of critical vendors.
  6. Extends the governance program to AI-enabled systems and services by establishing acceptable-use guardrails, AI and model vendor risk review criteria, data classification and data exposure controls for AI platforms, and documented evidence of compliance, aligned to the NIST AI Risk Management Framework and coordinated with university AI governance bodies.
  7. Performs and coordinates control testing and continuous control monitoring; collects and maintains audit evidence, control owner attestations, and a defensible system of record for compliance artifacts.
  8. Designs, delivers, and measures the security awareness and training program, including role-based training, annual policy attestation, phishing simulation, and reporting on behavioral risk indicators.
  9. Monitors changes in law, regulation, accreditation standards, sponsor requirements, and industry frameworks; assesses institutional impact and translates changes into control, policy, and remediation requirements.
  10. Develops and reports information security risk and compliance metrics, key performance indicators, and key risk indicators for the CISO, executive leadership, Internal Audit, and the Board of Trustees.
  11. Partners with Legal, Compliance and Privacy, Internal Audit, Research Administration, Procurement, Human Resources, and academic and clinical units to embed security requirements into institutional processes and to resolve compliance gaps.
  12. Supports incident response from a regulatory and governance standpoint, including breach risk assessment and determination, notification obligation analysis, regulator and sponsor reporting coordination, and post-incident control improvement.
  13. Maintains security-related business continuity and disaster recovery documentation and participates in the design and facilitation of tabletop exercises.
  14. Completes special projects as assigned.
  15. Performs other duties as assigned or required.

Job Requirements:

Required Knowledge, Skills, & Abilities: Knowledge:

  1. Comprehensive knowledge of information security control frameworks, including NIST Cybersecurity Framework 2.0, NIST SP 800-53, NIST SP 800-171, ISO/IEC 27001, and CIS Critical Security Controls.
  2. Comprehensive knowledge of regulatory and contractual security obligations applicable to higher education and academic health environments, including HIPAA/HITECH, FERPA, GLBA Safeguards Rule, PCI-DSS, and state data breach notification requirements.
  3. Working knowledge of research security requirements, including NIST SP 800-171, Controlled Unclassified Information handling, and Cybersecurity Maturity Model Certification concepts.
  4. Working knowledge of risk assessment and risk quantification methodologies, including NIST SP 800-30 and comparable approaches.
  5. Working knowledge of third-party risk management practices and attestation reporting, including SOC 2 Type II, HITRUST, and ISO certification review.
  6. Working knowledge of artificial intelligence governance frameworks and emerging obligations, including the NIST AI Risk Management Framework and ISO/IEC 42001.
  7. Working knowledge of governance, risk, and compliance platforms, control testing methods, and audit evidence management practices.

Skills

  1. Complex Problem Solving – Proficient skills in identifying complex problems and reviewing related information to develop and evaluate options and implement solutions.
  2. Technical Writing – Proficient skills in drafting policies, standards, procedures, risk assessments, and audit responses that are precise, defensible, and understandable to non-technical audiences.
  3. Analytical Skills – Proficient skills in evaluating control design and operating effectiveness and in identifying gaps between documented and actual practice.
  4. Consultative and Interpersonal Skills – Proficient skills in advising technical and business stakeholders, negotiating remediation commitments, and influencing outcomes without direct authority.
  5. Project Management – Proficient skills in managing concurrent audits, assessments, and remediation efforts against fixed external deadlines.

Abilities:

  1. Ability to translate technical security risk into business and financial terms for executive and Board audiences.
  2. Ability to manage multiple concurrent audits, assessments, and remediation efforts with competing deadlines.
  3. Ability to work independently, exercise sound judgment, and establish a program where none currently exists.
  4. Ability to handle confidential and sensitive information with discretion and integrity.
  5. Ability to build effective working relationships across academic, clinical, research, and administrative units.

Physical Requirements and Working Environment:

  1. Speech Recognition - Must be able to identify and understand the speech of another person.
  2. Speech Clarity - Must be able to speak clearly so others can understand you.
  3. Near Vision - Must be able to see details at close range (within a few feet of the observer).
  4. Travel - Must be able to travel on a daily and/or overnight basis.
  5. May be required to work nights or weekends.
  6. May be exposed to short, intermittent, and/or prolonged periods of sitting and/or standing in performance of job duties.
  7. May be required to accomplish job duties using various types of equipment/supplies, to include but not limited to pens, pencils, and computer keyboards.

Required Certifications/Licensures: Must possess one of the following certifications at the time of hire or obtain at least one (1) within twelve (12) months of hire and maintain it in good standing throughout employment:

Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Security Professional (CISSP).

Required Education: Bachelor’s degree.

Major (if required:

Required Experience: Minimum of six (6) to eight (8) years’ experience in information security, including governance, risk, and compliance functions such as control framework ownership, risk management, policy development, audit response, or third-party risk assessment.

Preferred Qualifications:

  1. Experience in higher education, an academic health center, or another multi-regulatory environment.
  2. Direct experience leading to external audit, regulatory examination, or sponsor security assessment.
  3. Experience implementing or administering a governance, risk, and compliance platform.
  4. Experience developing AI acceptable use, AI vendor risk, or AI governance controls.
  5. Experience with research security and Controlled Unclassified Information requirements.
  6. IAPP Artificial Intelligence Governance Professional (AIGP) certification.
  7. ISO/IEC 42001 Lead Implementer / Lead Auditor certification.
  8. ISACA Certified AI Systems Manager (CAISM) / AI Fundamentals certification.
  9. CompTIA SecurityX (formerly Sec+) with AI/SecAI + / Certified AI Security Professional (CAIS) certification.

Is this a safety sensitive position? No

Background Screening Required? Yes

Pre-Employment Conditions:

Sensitivity Disclaimer: Nova Southeastern University is in full compliance with the Americans with Disabilities Act (ADA) and does not discriminate with regard to applicants or employees with disabilities and will make reasonable accommodation when necessary.

NSU is an Equal Opportunity Employer and considers applicants for all positions without regard to race, color, religion, creed, gender, national origin, age, disability, marital or veteran status or any other legally protected status.

Nova Southeastern University

About Nova Southeastern University

Industry
Unknown
Company Size
Unknown
Headquarters
Unknown
Year Founded
Unknown
Website
nova.edu
Social Media