Senior Information Security Engineer CFREIT
Listed on 2025-12-21
-
IT/Tech
Cybersecurity, Information Security
Senior Information Security Engineer (FT), CFRE
43224IT
Apply for the Senior Information Security Engineer (FT), CFRE
43224IT role at Inside Higher Ed.
The College of DuPage is a comprehensive community college located 27 miles west of downtown Chicago, vitally connected to our local area for over 50 years. We prepare students for a lifelong passion for learning on our 273-acre campus which is home to nine associate degrees and a wide variety of professional and technical certificates. Many of these credentials prepare students to seamlessly articulate into the baccalaureate programs of our higher education partner institutions.
College of DuPage is committed to student success and values an inclusive and welcoming community environment. We are an equal‑opportunity employer committed to diversity in the workforce. Our connection to the larger metropolitan area is essential to our success and provides a wealth of diverse cultural and recreational opportunities.
Primary Duties and Responsibilities- Proactively monitor network traffic and systems vulnerabilities to detect security incidents and breaches. Respond to security incidents, performing root‑cause analysis and developing mitigation strategies.
- Maintain and test incident response plans to ensure rapid recovery in the event of security breaches or failures.
- Work with Managed Security Service Provider to implement security operation solutions and act as point of contact for cybersecurity escalations.
- Lead the operation of security tools and platforms, such as Security Information and Event Management (SIEM) systems, and endpoint protection.
- Design, implement, and maintain security architectures and technologies such as encryption protocols, identity and access management (IAM), and secure network infrastructure.
- Maintain the encryption and protection of sensitive data, including personally identifiable information (PII), financial data, and intellectual property. Implement and manage data loss prevention (DLP) solutions.
- Lead vulnerability scans and penetration tests to identify and prioritize potential threats. Implement risk‑mitigation tasks.
- Develop and update information security policies, standards, and guidelines in accordance with industry best practices, regulations (e.g., FERPA, HIPAA), and compliance frameworks (e.g., NIST, ISO 27001).
- Support security awareness programs for students, faculty, and staff to ensure the campus community understands security risks and best practices.
- Work closely with academic and administrative departments to ensure the institution’s technology and security needs are met.
- Evaluate the security posture of third‑party vendors, partners, and cloud service providers. Ensure that appropriate security controls are in place when integrating external systems. (Vendor & Third‑Party Risk Assessment)
- Stay up-to-date with the latest cybersecurity trends, tools, and threats, and assess their impact on the college’s infrastructure and systems.
- Perform other duties as assigned.
- Education
- Bachelor’s degree in computer science, information technology, cybersecurity, or a related field required.
- Experience
- Minimum of 5‑7 years of experience in information security, with at least 3 years in a senior or lead role required.
- Industry‑recognized certifications such as CISSP, CISM, or similar certifications are strongly preferred. Familiarity with cloud security (AWS, Azure, Google Cloud) and securing hybrid on‑prem/cloud environments. Knowledge of data privacy regulations and best practices for securing research data in an academic setting.
- Familiarity with security frameworks, compliance standards (FERPA, HIPAA, PCI‑DSS), and regulatory requirements for higher education institutions required.
- Experience with security operations centers (SOCs) and incident response teams required.
- Experience with implementing and managing data loss prevention (DLP) solutions required.
- Experience with vendor & third‑party risk assessment required.
- Experience in higher education environments is preferred.
- In-depth understanding of cybersecurity technologies including firewalls, SIEM, encryption, DLP, and IAM solutions.
- Strong expertise…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).