Director of Security Assurance
Position Purpose
The Director of Security Assurance leads Dartmouth's cybersecurity governance, risk, and compliance functions within the Office of Information Security. The role establishes and maintains the institutional security policy framework, enterprise risk management program, third party risk oversight, awareness initiatives, and audit support processes, translating complex regulatory and research security requirements into actionable institutional standards.
Operating in a decentralized academic environment with shared governance, the Director advises the CISO and senior leadership on institutional cyber risk posture, ensures compliance with applicable federal and state requirements, and partners across academic and administrative units to embed security and risk management practices that support Dartmouth's teaching, research, and clinical missions.
Required Qualifications - Education and Yrs Exp
Bachelors plus 6 or more years' experience or combination of education and experience
Required Qualifications - Skills, Knowledge and Abilities
- Demonstrated commitment to a collaborative, mission driven environment, with a track record of building cross functional trust and enabling teaching, research, and clinical operations through effective security practices.
- Minimum of 10 years of progressive professional experience in cybersecurity, including at least 5 years in governance, risk, and compliance leadership roles.
- Demonstrated experience designing, implementing, and maturing cybersecurity governance, risk, and compliance programs.
- Ability to conduct risk assessments, develop enforceable policies and standards, configure and optimize GRC platforms, and perform compliance gap analyses.
- Direct experience with at least two of the following regulatory or compliance frameworks: NIST SP 800-171, CMMC, HIPAA, FERPA, GLBA Safeguards Rule, PCI DSS, or ITAR and EAR.
- Demonstrated application of established security frameworks, such as NIST CSF, NIST RMF, CIS Controls, or ISO 27001, to structure and advance enterprise security programs.
- One or more current industry certifications, such as CISSP, CISM, CRISC, CGRC, or CISA, or equivalent credentials.
- Proven ability to communicate complex security and risk concepts effectively to executive leadership, faculty governance bodies, and technical stakeholders.
- Experience leading, hiring, mentoring, and developing cybersecurity or GRC professionals.
Preferred Qualifications
- Master's degree in cybersecurity, information security, risk management, or a related field preferred.
- Experience in an R1 or R2 research university, academic medical center, or complex multi entity higher education environment.
- Experience supporting or managing controlled unclassified information environments, including Department of Defense funded research subject to NIST SP 800-171 or CMMC requirements.
- Experience operating effectively in decentralized organizations where influence, relationship building, and consensus development are critical to success.
- Experience assessing and governing security and privacy risks associated with artificial intelligence and machine learning systems, including generative AI adoption, data exposure risks, and institutional AI governance frameworks.
Unlock this job opportunity
View more options below
View full job details
See the complete job description, requirements, and application process








%20Jobs.jpg&w=128&q=75)







