Ensure team members log all relevant incident or request details in appropriate systems according to information security processes and DoIT
ITSM processes.
Evaluates team status updates and makes strategic decisions around the work to be done
Uses knowledge and experience to provide first-line investigation and diagnosis and, whenever possible, resolves incidents and fulfills requests when first contacted.
Research security trends and tools to ensure team stays current in knowledge and skills.
Ensure incidents and requests are escalated as appropriate due to need, complexity, risk or general discretion
Coaches, mentors, and provides inspiration for team to improve performance and technical knowledge
Resolves conflict to improve interpersonal connections and professional relationships Creates and enforces staff performance improvement plans
Ensure team members develop strong knowledge in
NIST and
CIS security frameworks to design and implement controls and procedures for security and ease of audit.
Establishes goals and metrics, and evaluates results to measure progress of goals
Research and stay current on regulations to stay current in knowledge and skills Determines and develops processes to meet regulatory, risk, and audits requirements.
Designs Controls to meet business needs in accordance with business risk levels and regulations that map to
NIST and/or
CIS security frameworks
Understands security compliance regulations and works with cross functional teams on security tools implementation for compliance (i.e.
PCI,
GLBA,
HIPAA,
FERPA, etc.).
Collaborate with business units on implementing updated regulatory changes
Participates in regulatory advisory committees as an information security leader to educate the University community and IT resources on
INFOSEC principles
Leads annual regulatory compliance efforts across business units.
Research security trends and tools to ensure security processes are kept current and map to
NIST and/or
CIS security frameworks
Propose and develop new information security procedures or process improvements, automation processes wherever possible, and implementing documentation to support reporting and audits.
Collaborates with other units and participates on projects to continuously improve integration of information security with business and IT practices.
Collaborate with federal, state, and local law enforcement when required
Assist Human Resources, General Counsel, and Ethics Officers as it relates to investigations or matters filed with external agencies.
Creates and tracks KPI's for forms, incidents, requests, security tools, and processes |