Deputy Director of IT Risk and Compliance
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager
Deputy Director Of It Risk & Compliance Management
The Deputy Director of IT Risk & Compliance Management provides strategic and operational leadership over enterprise technology risk, compliance, and governance functions across the MBTA. The role safeguards information assets by operationalizing security and privacy control frameworks, orchestrating supply chain and vendor risk diligence, and translating risk posture between executive-level dashboards and actionable remediation plans. The Deputy Director fosters a high-performance culture of security awareness, drives policy governance, and serves as a trusted advisor to senior leadership on emerging risks spanning legacy, cloud, Dev Ops, and operational technology environments.
Duties & Responsibilities- Direct the risk management lifecycle—identification, assessment, response, monitoring—for IT and OT systems, ensuring alignment with NIST CSF, NIST 800-53, ISO 27001, CIS, and applicable privacy mandates (e.g., MA 201 CMR 17.00, GDPR, CCPA).
- Maintain an authoritative inventory (Risk Register) of business, technology, regulatory, contractual, and organizational security related risks; oversee continuous control testing and issue management.
- Design and run a robust Supply-Chain Risk Management (SCRM) program, including third-party onboarding, due-diligence assessments (SOC 2, ISO 27001, PCI DSS, FedRAMP, CMMC), and ongoing performance monitoring.
- Coordinate with Procurement and Legal to embed security clauses and right-to-audit provisions in contracts.
- Develop, socialize, and maintain MBTA information security and privacy policies; drive adoption through targeted awareness campaigns, phishing simulations, and organization-wide training.
- Evangelize a Security-First mindset via townhalls, brownbag sessions, and executive briefings.
- Administer and optimize GRC portals (e.g., Service Now, Archer) for control catalogues, risk registers, exception management, and board-level metrics.
- Integrate vulnerability, incident, and asset data to deliver end-to-end traceability from findings to remediation and residual risk reporting.
- Produce concise, data-driven dashboards and briefings for the CISO, CIO, Board, and federal regulators (TSA, FTA, DHS/CISA).
- Present program status, risk trending, and budget justification in public speaking forums, executive committees, and industry conferences.
- Lead, mentor, and develop a diverse team of risk analysts and compliance specialists; cultivate psychological safety, accountability, and continuous learning.
- Champion collaboration across Operations, Engineering, Legal, Audit, and Finance to embed security into MBTA's technology and business roadmaps.
- Evaluate emerging threats, technologies, and regulatory changes; recommend process enhancements, automation, and tooling (e.g., IRM workflows, AI assisted control testing).
- Serve as primary interface for internal/external auditors and regulatory bodies; coordinate evidence collection, track remediation commitments, and attest to control effectiveness.
- Perform all other duties and projects that may be assigned.
Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions.
Supervision
- Manage a team of engineers and administrators.
- Bachelor's degree from an accredited institution in Computer Science or a related field.
- Five (5) years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments,
- Two (2) years of supervisory, managerial, and/or leadership experience.
- Demonstrated implementation of NIST 800-53/CSF, ISO 27001/27701, CIS Controls, ITIL, COBIT, and privacy regulations.
- Working knowledge of network, cloud (AWS/Azure), Dev Ops pipelines, legacy on-prem systems, security tooling (SIEM, EDR, IAM), and vulnerability management platforms.
- Handson administration of GRC suites (Service Now GRC, Archer, Origami, Armis, Nazomi) and phishing training platforms (KnowBe4, Proofpoint, Cofense).
- Exceptional verbal and written communication, public speaking, and executive level presentation skills.
- At least one of: CRISC, CISM, CISSP, CISA; willingness to achieve additional certifications as needed.
Substitutions
- A High School Diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor's degree requirement.
- An associate's degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor's degree requirement.
- A master's degree in a related subject substitutes for two (2) years of general experience.
- A nationally recognized certification, or statewide/professional certification in a related field substitutes for one year of experience.
- Seven (7) or more years of progressive IT risk, compliance, or cybersecurity governance experience within large, complex environments.
- Three (3) or more years in a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).