At Stanford, we are committed to creating meaning, solving complex challenges, and enriching lives on a global scale. We are seeking a talented Associate Information Security Officer to play a vital role in our dynamic team within the Information Security Office. In this position, you will support a broad range of information security activities, helping protect the university''s digital resources and contributing to a culture of security awareness and accountability.
The Information Security Office is a high-profile team with university-wide purview. We operate with a high degree of autonomy, and we expect each contributor to bring their own strengths to the tough challenges facing the university.
The Cybersecurity Governance, Risk, and Compliance (GRC) team within the Information Security Office has an entrepreneurial spirit, and we invite you to help us grow while advancing your own career.
In this role, you will support core GRC functions including security awareness and training, data risk assessments, add-in and plug-in reviews, and compliance support across applicable regulatory frameworks. A working knowledge of HIPAA is important, as the university handles protected health information across research, clinical, and administrative environments.
You will report directly to the Senior Information Security Officer and work closely with team members across ISO and university departments to support the university''s information security program.
Typical Activities
Approved budgeted salary for this position is: $104,623-$135,000
REMOTE WORK: This position is eligible for permanently remote work, but keep the following in mind: our team operates on Pacific Time, and we adjust salary based on regions of the country. You may be expected to come to campus, but generally expect that to be no more than a few days each quarter. Well pay for your travel if youre outside the greater Bay Area. See our admin guide for more information. https://adminguide.stanford.edu/chapters/human-resources/staff-employment-policies/remote-work-arrangements.
Core Duties:
Develop procedures to safeguard computer configurations against accidental or unauthorized modification, destruction, or disclosure and to meet the data standards.
Perform system security reviews and tests and write formal reports and follow up advisory memos.
Receive reports on security breaches and risks, take appropriate action, and recommend solutions to minimize harm and liability.
Monitor process and inspect system and network data for computer and network usage policy compliance, system integrity, and incident response. Interface with Information Security Office to report incidents.
Participate in the development and documentation of information security standards, best practices and guidelines by drafting policies, standards and procedures. Deliver educational information and develop awareness for system administrators and user community.
Provide guidance in the design of secure system and network architectures.
Evaluate new applications to comply with enterprise security standard. Recommend and implement solutions identified through organizational security audits.
Network with information security members from other communities.
Translate technical information to users of various knowledge levels at outreach events such as presentations and meetings.
Minimum Education and Experience:
Bachelor's degree plus three years relevant experience, or a combination of education and relevant experience.
Knowledge, Skills and Abilities:
Demonstrated knowledge and understanding of IT security trends and emerging technologies and an ability to relate them to Stanford and its objectives.
Thorough and demonstrated knowledge of networking protocols, principles, and intrusion detection devices, including firewalls and VPNs.
Fundamental architecture and configuration knowledge of desktop server and operating systems.
Solid understanding of security issues, techniques, and solutions.
Strong experience with debugging, troubleshooting, forensics and security utilities.
Basic understanding of scripting language.
In-depth knowledge of authentication protocols, encryption and other fundamental security technologies.
Excellent written and verbal communication skills.
High level of integrity and excellence judgment concerning proprietary and privacy issues.
Core Duties:
Develop procedures to safeguard computer configurations against accidental or unauthorized modification, destruction, or disclosure and to meet the data standards.
Perform system security reviews and tests and write formal reports and follow up advisory memos.
Receive reports on security breaches and risks, take appropriate action, and recommend solutions to minimize harm and liability.
Monitor process and inspect system and network data for computer and network usage policy compliance, system integrity, and incident response. Interface with Information Security Office to report incidents.
Participate in the development and documentation of information security standards, best practices and guidelines by drafting policies, standards and procedures. Deliver educational information and develop awareness for system administrators and user community.
Provide guidance in the design of secure system and network architectures.
Evaluate new applications to comply with enterprise security standard. Recommend and implement solutions identified through organizational security audits.
Network with information security members from other communities.
Translate technical information to users of various knowledge levels at outreach events such as presentations and meetings.
Minimum Education and Experience:
Bachelor's degree plus three years relevant experience, or a combination of education and relevant experience.
Knowledge, Skills and Abilities:
Demonstrated knowledge and understanding of IT security trends and emerging technologies and an ability to relate them to Stanford and its objectives.
Thorough and demonstrated knowledge of networking protocols, principles, and intrusion detection devices, including firewalls and VPNs.
Fundamental architecture and configuration knowledge of desktop server and operating systems.
Solid understanding of security issues, techniques, and solutions.
Strong experience with debugging, troubleshooting, forensics and security utilities.
Basic understanding of scripting language.
In-depth knowledge of authentication protocols, encryption and other fundamental security technologies.
Excellent written and verbal communication skills.
High level of integrity and excellence judgment concerning proprietary and privacy issues.