Job Classification: IT Security Compliance Officer
Job Title: IT Security Compliance Officer
Department: Information Technology
Reports To: Chief Information Officer (CIO) or designated IT Security Manager
Summary:
The IT Security Compliance Officer is responsible for ensuring the K-12 school districts information technology systems and practices adhere to all applicable federal state and local regulations as well as district policies related to data privacy and security. This position plays a crucial role in safeguarding student staff and district data mitigating security risks and promoting a culture of security awareness across the district.
Essential Duties and Responsibilities:
- Compliance Management:
- Develop implement and maintain IT security compliance programs and procedures.
- Ensure compliance with relevant regulations including but not limited to:
- FERPA (Family Educational Rights and Privacy Act)
- CIPA (Childrens Internet Protection Act)
- State data privacy laws
- PCI DSS (if applicable)
- Conduct regular audits and assessments to identify compliance gaps and vulnerabilities.
- Prepare and maintain accurate compliance documentation and reports.
- Stay up-to-date on changes in relevant regulations and industry best practices.
- Risk Management:
- Conduct risk assessments to identify and evaluate potential security threats and vulnerabilities.
- Develop and implement risk mitigation strategies.
- Monitor and report on security incidents and breaches.
- Assist in the development and implementation of disaster recovery and business continuity plans.
- Security Awareness and Training:
- Develop and deliver security awareness training programs for faculty staff and students.
- Promote a culture of security awareness across the district.
- Provide guidance and support to district personnel on security best practices.
- Policy and Procedure Development:
- Develop and maintain IT security policies and procedures.
- Ensure that policies and procedures are communicated effectively to all stakeholders.
- Monitor adherence to established policies and procedures.
- Incident Response:
- Assist in the development and implementation of incident response plans.
- Participate in security incident investigations and response efforts.
- Document and report on security incidents.
- Third-Party Security:
- Manage security risks associated with third-party vendors and contractors.
- Ensure third-party compliance with organizational security policies.
- Collaboration and Communication:
- Collaborate with IT staff school administrators and other stakeholders to ensure effective security compliance.
- Communicate effectively with all stakeholders regarding security compliance matters.
- Represent the district in security compliance matters as needed.
Qualifications:
- Bachelors degree in information technology Cybersecurity or associates degree with equivalent experience/certifications.
- Minimum of 3-5 years of experience in IT security and compliance.
- Strong knowledge of relevant regulations including FERPA and CIPA.
- Experience conducting risk assessments and developing security policies.
- Excellent communication interpersonal and problem-solving skills.
- Ability to work independently and as part of a team.
- Strong attention to detail and organizational skills.
Preferred Qualifications:
- Relevant certifications such as:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified in Risk and Information Systems Control (CRISC)
- CompTIA Security
- Experience working in a K-12 education environment.
- Knowledge of student information systems and educational technology.
Working Conditions:
- Ability to work in a typical office environment.
- Work may involve occasional evening and weekend hours.
- Occasional travel between school sites may be required.
- Will be required to handle sensitive and confidential information.
Required Experience:
Unclear Seniority