Full-Time

Director, Cybersecurity and Risk

Arizona State University Enterprise Partners

Arizona State University Enterprise Partners

51-200 employees

Nonprofit backing ASU through ecosystem services

No salary listed

Scottsdale, AZ, USA

Hybrid

Hybrid schedule with two work-from-home days per week.

Bachelor's, Master's

Category
IT & Security (1)
Required Skills
Microsoft Azure
Incident Response
Workday HRIS
Cybersecurity
Salesforce
SOC 2
SAML
Risk Management
Google Workspace
OAuth

Get referred to Arizona State University Enterprise Partners

See people who can refer or advise you

Requirements
  • Strong understanding of security risk management, security controls, incident response readiness, vendor security, identity and access governance, data protection, and modern enterprise technology environments.
  • Ability to evaluate information security risk for new initiatives and recommend practical mitigation strategies.
  • Ability to define secure configuration expectations, access control requirements, monitoring needs, and remediation plans for enterprise platforms.
  • Working knowledge of Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, identity and access management, endpoint protection, SaaS governance, cloud security concepts, and data protection practices.
  • Ability to maintain confidentiality and responsibility regarding organizational, affiliate, university, constituent, employee, financial, and other sensitive information.
  • Ability to communicate clearly with technical and non-technical individuals, including executive, legal/procurement, governance/compliance, business, and vendor stakeholders.
  • Strong project management, reporting, documentation, and stakeholder communication skills.
  • Ability to develop executive-ready summaries, remediation dashboards, risk narratives, procedures, standards, and implementation guidance.
  • Ability to work independently and as part of a team.
  • Ability to manage complex situations involving numerous and competing constituencies.
  • Strong knowledge of process and quality improvement.
  • Ability to support planning and management of security-related budgets, vendor spend, and resource needs.
  • Bachelor's degree in cybersecurity, information technology, risk management, information systems, or a closely related field, or an equivalent combination of education and experience.
  • At least eight years of experience in information security, technology risk, security operations, IT risk management, or related technology leadership roles.
  • At least four years of experience managing employees in a technical environment.
  • Experience securing, governing, or assessing enterprise SaaS and cloud platforms such as Microsoft 365, Azure/Entra ID, Google Workspace/Cloud Identity, Workday, Salesforce, or comparable enterprise platforms.
  • Experience with identity and access management, access governance, privileged access, secure configuration, tenant hardening, data protection, or SaaS governance.
  • Experience working cross-functionally with technology, data, legal/procurement, governance/compliance, business, and vendor stakeholders.
  • Experience implementing security controls, managing remediation efforts, conducting security reviews, or supporting audit and evidence activities.
  • Experience with vendor security reviews, incident response coordination, and security risk communication.
  • An equivalent combination of experience and/or education may provide comparable knowledge, skills, and abilities.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, Security+, Microsoft Security, Azure Security, Google Cloud Security, or similar security/risk credentials.
Responsibilities
  • Lead security risk reduction efforts across systems, vendors, processes, and technology initiatives.
  • Implement and operationalize security controls with infrastructure, identity, endpoint, data, application, and business teams.
  • Support security control alignment, audit readiness, remediation tracking, and evidence collection with governance and compliance stakeholders.
  • Track security remediation efforts, identify owners, communicate status, and escalate unresolved risks through governance or leadership channels.
  • Translate security risks, technical issues, and control gaps into clear business impact for technical and non-technical audiences.
  • Develop, update, and maintain security procedures, standards, implementation guidance, and operational documentation.
  • Own and mature the security posture of enterprise SaaS and cloud platforms, including Microsoft 365, Azure/Entra ID, Google Workspace/Cloud, Workday, Salesforce, and other critical applications.
  • Lead oversight of identity and access controls, including multifactor authentication, conditional access, single sign-on, SAML, OAuth, privileged access, role-based access, service accounts, access reviews, and joiner/mover/leaver security processes.
  • Establish and maintain secure configuration standards and review processes, including tenant hardening, administrative role governance, external sharing controls, audit logging, data protection settings, and integration/API security.
  • Partner with platform, infrastructure, identity, endpoint, cloud, SaaS, data, and application teams to implement security controls consistently.
  • Participate in design reviews, access reviews, release readiness conversations, and control reviews.
  • Implement data protection controls, including data classification, data loss prevention, secure sharing, access monitoring, retention-aligned safeguards, and protection of sensitive information.
  • Define security logging, monitoring, alerting, and evidence requirements and ensure detection and response capabilities are in place.
  • Maintain information flow documentation, risk documentation, and safeguards for organizational, subsidiary, university, donor, prospect, and business-sensitive information.
  • Support incident response through response plan maintenance, tabletop participation, documentation, escalation, and post-incident improvement.
  • Coordinate with technology, governance/compliance, legal, communications, business units, vendors, and leadership during security incidents.
  • Manage the vendor security review process, including security questionnaires, vendor documentation review, risk identification, and mitigation recommendations.
  • Partner with legal, finance, governance, and compliance stakeholders on vendor security requirements, contract considerations, data protection expectations, and remediation commitments.
  • Lead security architecture and risk reviews for technology purchases, integrations, platform changes, data initiatives, SaaS implementations, and business process changes.
  • Engage business units to understand new initiatives, identify security risks, and recommend practical mitigation strategies.
  • Lead and participate in projects related to information security, security awareness, continuity planning, IT policies, control improvement, and risk mitigation.
  • Develop security risk metrics, executive-ready reporting, remediation dashboards, and maturity updates.
  • Lead and manage assigned security or risk-focused staff, including hiring, coaching, mentoring, prioritization, performance development, training, and accountability.
  • Define deliverables, objectives, results, outcomes, milestones, and timelines for security and risk initiatives.
  • Represent Technology & Solutions and ASU Enterprise Partners in discussions involving security, technology risk, vendor security, and institutional trust.
Desired Qualifications
  • Advanced degree in cybersecurity, information systems, risk management, business, privacy, or a related field.
  • Experience in higher education, nonprofit, SaaS/cloud, privacy-sensitive, financial, fundraising, or regulated environments.
  • Experience supporting SOC 2, NIST CSF, CIS Controls, internal controls, external assessments, or audit evidence activities.
  • Experience developing security procedures, security standards, control implementation guidance, risk summaries, or stakeholder-facing security materials.
  • Experience defining security monitoring and logging requirements.
  • Experience coordinating access recertifications, privileged access reviews, service account reviews, platform hardening initiatives, or SaaS security posture assessments.
  • Willingness to complete relevant Microsoft, Google, cloud security, security operations, or risk-related certifications.
Arizona State University Enterprise Partners

Arizona State University Enterprise Partners

View

ASU Enterprise Partners is a nonprofit group that provides an ecosystem of services to support Arizona State University and its affiliated entities. It works by coordinating fundraising, resource generation, and support activities to extend the university’s reach and advance its charter. Although it shares the same mission as ASU, it is a separate 501(c)(3) organization governed by a volunteer board and supports ASU and several affiliates such as the ASU Foundation for a New American University, ASU Outreach Hub, ASURE, ECASU, NEWSWELL, Skysong Innovations and University Realty. Its goal is to mobilize resources and programs that help ASU grow its impact and fulfill its public mission.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Buckshot, Arizona

Founded

2016

Get referred to Arizona State University Enterprise Partners

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • ASU endowment reached $1.7 billion in February 2026, signaling stronger fundraising momentum.
  • ASU Foundation celebrated record-setting philanthropic impact in August 2025, supporting enterprise demand.
  • ASU Enterprise Partners remains a top Arizona employer, helping recruiting and retention.

What critics are saying

  • Dependence on ASU's reputation makes any campus scandal instantly contaminate partner trust.
  • Private nonprofit structure creates scrutiny over executive pay, related-party transactions, and donor influence.
  • Edtech bets like RealmSpark face startup failure risk and long payoff timelines.

What makes Arizona State University Enterprise Partners unique

  • ASU Enterprise Partners anchors ASU's private ecosystem across fundraising, real estate, research, and edtech.
  • Its affiliates include ASU Foundation, ASURE, Enterprise Collaboratory, NEWSWELL, and University Realty.
  • The model converts ASU brand access into recurring partnerships and mission-aligned investments.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Holidays

Parental Leave

Hybrid Work Options

Phone/Internet Stipend

Professional Development Budget

Company News

Google
Aug 8th, 2023
ASU Enterprise Partners honored as top employer for 10th consecutive year

ASU Enterprise Partners earned a spot among the Top Companies to Work For in Arizona, marking this its 10th consecutive year achieving the award in the medium employer category.

The Business Journals
Jan 5th, 2022
ASU Enterprise Partners hired Chris Howard as executive vice president and chief operating officer on Feb 1st 16'.

Arizona State University has named Robert Morris University President Chris Howard as executive vice president and chief operating officer of the ASU Enterprise.