Position Requirements:
EDUCATION:
· Bachelor’s degree in Computer Science, Information Security, or a related field. (Masters Preferred)
· Certification(s) in one or more of the following areas: GIAC Certified Incident Handler (GCIH), Certified Information Systems Security Professional (CISSP), CISA: Certified Information Security Auditor, CEH: Certified Ethical Hacker, CISM: Certified Information Security Manager, or CompTIA Security+.
EXPERIENCE:
· Minimum of 6 years of professional IT experience, working hands on in a complex, enterprise-level technology infrastructure. Minimum 4 years in a cybersecurity leadership role. Experience working in a research institution with scientific researchers and/or academic faculty preferred.
· Experience in data protection and cybersecurity, including incident management, security incident response frameworks, and disaster recovery planning.
· Proficiency in security technologies and tools, including SIEM, firewalls, VPNs, data encryption protocols, and anti-malware solutions.
· Experience in cloud security and working with cloud platforms like AWS, Azure, or Google Cloud.
· Strong understanding of GDPR, CCPA, HIPAA, or similar data privacy regulations.
· Hands-on experience with vulnerability assessments, penetration testing, and ethical hacking.
· Extensive knowledge of regional and global cybersecurity frameworks, such as NIST, ISO 27001, SOC 2,nand CIS Controls.
SKILLS:
· Strong leadership and team management skills, with experience leading cybersecurity initiatives.
· Solid analytical and problem-solving skills, with the ability to identify and mitigate data security risks.
· Excellent communication skills (oral and written) with the ability to be accurate, precise and, whenever possible, succinct in messaging about complex problems to be solved and/or work to be completed.
· Ability to work cross-functionally with IT, legal, and business stakeholders.
· Experience in the following platforms, systems, applications and network hardware including: Rapid7, Mimecast, ESET, ThreatLocker, DUO, Windows Server, Active Directory, Exchange, MS365, Fortinet, Linux/CentOS,TCP/IP, firewall and systems security, signal detection and review, business continuity, and disaster recovery.
· Experience with regulatory compliance related to cybersecurity and data privacy laws.
· Knowledge of threat intelligence platforms and advanced persistent threats (APT).
· Familiarity with Zero Trust Architecture and its implementation.
· Expertise in threat modelling, risk management, and securing controlled-access data.