The Senior Director of Information Security serves as Berklee’s primary information security authority and hands-on technical leader. Operating in a high-impact, lean team environment, the Sr. Director balances strategic governance, policy development, and budget management with active technical leadership. Reporting to the VP & CIO, the Sr. Director directly supervises the Information Security Analyst and works collaboratively across IT operations to protect Berklee's digital assets, ensure regulatory compliance, and lead incident response efforts.
The Sr. Director of Information Security possesses a strong technical background in risk management, threat mitigation, and technical controls. As a hands-on leader, they provide strategic vision and technical guidance both to the internal security function and to cross-functional IT operations and engineering teams to build a secure, scalable environment across Berklee’s global networks, applications, and systems.
In partnership with executive leadership and the Office of General Counsel, this role develops, maintain, and enforces the College’s Information Security Policy, standards, and awareness programs to ensure compliance with relevant statutes and regulations. The Sr. Director oversees security system architecture, evaluates emerging technologies, and serves as the primary subject manager expert for enterprise security design.
Additionally, the Sr. Director manages Berklee's overarching IT security strategy, roadmap, and budget. This role requires exceptional communication skills, including the ability to translate complex technical risks into clear concepts for leadership, faculty, staff, and external partners.
ESSENTIAL JOB DUTIES:
Operational & Technical Leadership
Establish, monitor, and optimize security processes and technical controls to prevent unauthorized access to Berklee's networks, systems, and cloud environments.
Directly supervise, mentor, and manage the performance and professional development of the Information Security Analyst.
Implement security automation, orchestration, and streamlined workflows to maximize team efficiency and reduce repetitive manual tasks.
Partner with broader IT operations, networking, and engineering teams to provide hands-on security guidance, ensure proper protocol implementation, and promote security awareness across the division.
Strategic, Financial & Governance Oversight
Develop, maintain, and enforce institutional IT security policies and programs in alignment with legal regulations (e.g., FERPA, PCI, GDPR, etc.) and higher ed standards.
Oversee IT security budget processes, forecast costs, negotiate vendor contracts, and manage security-related procurements to align with institutional goals.
Oversee threat monitoring across SOC tools and SIEM systems; direct vulnerability assessments, risk reviews, and penetration testing remediation plans.
Define security requirements and design policies governing Identity & Access Management (IAM), multi-factor authentication, single sign-on, and cloud connections.
Serve as the primary technical and escalation lead during potential or actual security incidents or data breaches and maintain transparent, proactive communication with IT leadership, executive stakeholders, and external partners regarding threat environments and security posture.
Lead project management for security initiatives from inception to rollout, ensuring alignment with institutional technology roadmaps.
Act as the primary security subject matter expert and advisor to the VP & CIO, executive leadership, and external partners.
Ideal Profile
The ideal candidate combines hands-on technical cybersecurity expertise with strategic leadership and financial management capabilities. They possess experience managing heterogeneous environments spanning on premises, co-located, and cloud architecture, with the ability to translate complex technical risks into clear, actionable guidance for executive leadership and community stakeholders. Operating as a player-coach, they are skilled in incident response, risk management, policy design, and vendor negotiations, with the interpersonal agility needed to mentor an Information Security Analyst and partner across broader IT teams.
Minimum Qualifications
10+ yearsof progressive cybersecurity and IT experience, including 3+ years in a team lead or supervisor role.
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or an equivalent combination of education and experience).
Demonstrated experience managing enterprise security solutions, SIEM systems, identity and access management (IAM), and cloud security architectures.
Direct experience leading incident response, threat detection, vulnerability management, and infrastructure risk remediation.
Proven ability to interpret, implement, and enforce compliance requirements and security standards (e.g., FERPA, PCI-DSS, 201 CMR 17.00, NIST).
Exceptional oral and written communication skills, including the ability to present security updates to executive leadership and lead vendor contract discussions.
CISSP, CISM, or equivalent professional cybersecurity credentials.
Master’s degree, MBA, or advanced degree in Information Assurance, Cybersecurity, or Technology Management
Experience working within higher education or a similarly decentralized, open-network institutional environment.
Familiarity with cybersecurity frameworks (ISO 27001, CIS Controls) and higher education security assessment tools (HECVAT).
Hands-on experience managing IT security budgets, forecasting costs, and negotiating software and service contracts.
Proficiency with Google Workspace, Rapid Identity, Microsoft 365, Active Directory, endpoint detection and response (EDR) solutions, and multi-OS platforms (Windows, Linux).
Core Competencies:
Ability to directly supervise and mentor an Information Security Analyst while staying actively engaged in daily security operations.
Capability to align IT security investments, vendor procurements, and strategic roadmaps with overall institutional priorities.
Demonstrated skill in embedding security practices into systems, networking, and help desk operations without direct managerial authority over those teams.
Calmness and technical authority under pressure during actual or potential data breaches and security incidents.
Ability to translate complex technical concepts into clear written and verbal formats, as well as elicit detailed technical requirements to establish defined project milestones, tasks, and goals.
In-depth knowledge of security practices, institutional policies, and technology service delivery frameworks (such as ITIL) to navigate complex operational situations effectively.
HIRING RANGE:
$160,000 to $180,000; salary dependent on relevant experience and education.
Please visit the Total Rewards page to learn more about the benefits of working at Berklee.
Workplace Considerations
Berklee College maintains a global infrastructure. Planned and unplanned work may be required after hours or on weekends.
The Senior Director of Information Security may be required to participate in 7x24 on-call coverage.
Light physical work as related to server systems may be required.
Employees will be required to stand for periods of time or move throughout the college campus, including occasional travel to any off-site hosting facilities.
Why Choose Berklee?
Mission-Driven Impact: Play a pivotal role in identifying and cultivating the world's most inspired creative entrepreneurs and performing artists.
Cultural Access: Enjoy nightly, unrivaled access to world-class music, theater, and dance performances across our campus venues.
Comprehensive Benefits: Exceptional health and dental plans, a 403(b) retirement system with matching institutional contributions, and tuition benefits for you and your family.
Generous Time Off: Extensive paid time off alongside observed holidays and a paid winter break to rest and recharge.
This document does not create an employment contract, implied or otherwise, other than an “at will” employment relationship.
Diversity, Equity, Inclusion & Equal Employment Opportunity at Berklee:
We support an inclusive workplace where everyone excels based on personal merit, qualifications, experience, ability, and job performance.Berklee affirms that inequality is detrimental to our faculty, staff, students, and the communities we serve. Our goal is to make lasting change through our actions. Berklee is committed to providing fair and equitable consideration of all employees and applicants without regard to race, color, religion, ancestry, age, national origin, place of birth, gender, sexual orientation, gender identity or expression, disability, genetic information, or status as a member of the armed forces or veteran of the armed forces, or any other category protected by federal, state, or local law.
As part of this commitment, Berklee will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact the Human Resources Team at hroperations@Berklee.edu or call 617-747-2375.
*Currently enrolled Berklee students are not permitted to apply for staff or faculty positions.*