Reporting to the Sr. Director of Infrastructure & Operations, the Director of Information Security is a member of the IT leadership team and serves a key role in university leadership, working closely with senior administration, academic leaders, and the campus community. The Director of Information Security is an advocate for Creighton Universityâ??s total information security needs and is responsible for the development and delivery of a comprehensive information security risk management program to optimize the security posture of the university.
The Director of Information Security leads the development and implementation of a risk-based security program that leverages collaboration and campus-wide resources, facilitates information security governance, advises senior leadership on security direction and resource investments, and designs appropriate policies to manage information security risk.
The complexity of this position requires a leadership approach that is engaging, imaginative, and collaborative, with a sophisticated ability to work with other leaders to set the best balance between security strategies and other priorities at the campus level.
Essential Functions
Security Strategy, Governance & Risk Management
â?¢ Defines and executes the universityâ??s multi-year information security strategy and roadmap.
â?¢ Establishes governance structures, policies, standards, and risk management frameworks aligned with NIST and regulatory requirements.
â?¢ Presents security posture, roadmap progress, and risk trends to Sr. Director of Infrastructure & Operations
â?¢ Develop institutional risk models that reflect academic, clinical, and research environments.
Security Architecture & Engineering Oversight
â?¢ Leads the design and engineering of technical controls, including SIEM, SOAR, EDR, logging pipelines, MFA, vulnerability management, email security, and administrative privilege management.
â?¢ Ensures alignment with enterprise infrastructure, networking, cloud operations, and data governance teams.
Compliance & Regulatory Stewardship
â?¢ Ensures cybersecurity compliance for HIPAA-aligned clinics, academic research, financial systems, and federal reporting requirements.
â?¢ Leads security components of internal and external audits.
â?¢ Creates institutional documentation, controls matrices, and evidence packages aligned with regulatory frameworks and accreditation needs.
Security Awareness, Culture & Academic Partnership
â?¢ Develops institution-wide security training, awareness campaigns, and behavior-based education programs.
â?¢ Builds strong relationships with colleges, schools, and clinical programs to support secure and compliant environments.
â?¢ Encourages a campus culture of shared responsibility for cybersecurity.
Team Leadership & Talent Development
â?¢ Leads security engineering, risk, compliance, and incident response teams.
â?¢ Develops staff skillsets in threat detection, architecture, identity governance, cloud security, and compliance.
â?¢ Fosters a culture of transparency, continuous improvement, and operational rigor.
Vulnerability Management & Remediation
â?¢ Leads enterprise vulnerability identification, prioritization, and remediation workflows across servers, endpoints, networks, and cloud services.
â?¢ Establishes risk-based SLAs, reporting dashboards, and remediation playbooks.
â?¢ Partners with system owners, infrastructure engineering, and academic/clinical environments to implement secure baselines and configuration standards.
Qualifications
Knowledge, Skills, and Abilities:
Licenses/Certifications:
Creighton University is committed to providing a safe and non-discriminatory educational and employment environment. The University admits qualified students, hires qualified employees and accepts patients for treatment without regard to race, color, religion, sex, marital status, national origin, age, disability, citizenship, sexual orientation, gender identity, gender expression, veteran status, or other status protected by law. Its education and employment policies, scholarship and loan programs, and other programs and activities, are administered without unlawful discrimination. Creighton complies with all applicable laws and regulations governing equal opportunity in the workplace and in educational activities.
Applicants with disabilities needing reasonable accommodations to complete the application or hiring process should contact Human Resources at [email protected]. Creighton University seeks candidates who understand, respect, and can contribute to the University's mission and values.
| Date Posted | January 28, 2026 |
|---|---|
| Date Closes | January 28, 2027 |
| Requisition | 300000997026681 |
| Located In | Omaha, NE |
| SOC Category | 11-3021.00 Computer and Information Systems Managers |