University of Phoenix

IT289 - Security Engr Sr- Governance and Compliance

University of Phoenix • $96K — $194K *
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Business, or related area.
  • 10 years of progressive experience in Information Security roles, with at least 6 years hands-on experience.
  • Security certifications like CISSP, CISM, CISA are required.
  • Knowledge of compliance regulations (SOX, GLBA) and audit support experience is essential.
  • Experience with IAM and cloud security solutions is preferred.

Responsibilities

  • Lead the implementation and configuration of security tools for information asset protection.
  • Monitor and recommend changes to information security strategies focused on privacy and vulnerabilities.
  • Identify and communicate risk findings; develop and coordinate remediation plans.
  • Evaluate and update information security standards according to technological advances and threats.
  • Design and manage IAM and cloud solutions, overseeing user access controls.
  • Collaborate across teams to ensure effective integration of IAM and cloud services.
  • Support off-hours as needed and fulfill additional assigned duties.

Benefits

  • Annual Bonus Award
  • Comprehensive medical, dental, and vision plans; Flexible Spending Accounts; Health Savings Accounts; Life and Disability insurance; Wellness incentive program.
  • Competitive 401(k) employer match.
  • Substantial tuition discount for employees and eligible dependents.
  • Generous time off package including paid vacation, sick leave, and holidays.
Full Job Description
About the Position:

A Senior Security Engineer-Governance and Compliance works closely with colleagues in Information Technology, as well as with internal audit, compliance and other key stakeholders to develop information security strategies and build related programs that enhance the University's ability to protect the confidentiality, availability and integrity of its information assets, including customer information. An individual serves as lead for implementing and configuring security tools within the University's technology space, including implementing the framework for security standards and compliance of systems, infrastructure, cloud technologies and solutions or Identity and Access Management (IAM). Additionally, an individual contributes to enterprise-level policies and standards, leads incident response activities, and security issue remediation.

What You'll Do

1. Lead efforts to implement and configure security tools within the University's technology space to protect its information assets, including customer assets; collaborate with information security peers and management to ensure various platforms, such as Azure, AWS, Private cloud, SaaS applications, are compliant and meet the University's information security standards and regulatory requirements.

2. Monitor and recommend changes in strategies and standards that affect Information Security, especially in the area of privacy and identity theft; proactively assess potential items of risk and vulnerabilities in cloud technologies and applications or IAM; establish and provide security governance during the systems development lifecycle, construction, and maintenance of cloud or IAM technologies and solutions using DevOps, DevSecOps, and Agile development methodologies.

3. Identify opportunities to improve risk posture, develop solutions for remediating or mitigating risks and assessing the residual risk. Communicates risk findings to Information Security customers and business partners; develop remediation plans and coordinate with appropriate service, application, and technology owners through the completion of those plans, as appropriate.

4. Evaluate existing Information Security standards and updates according to technology advances, changes in business process and threat landscape; adjust existing Information Security standards to align with leading cloud and/or IAM security practices and technologies.

5. Hands-on experience with designing, implementing, and managing IAM and/or cloud solutions while overseeing user access provisioning, deprovisioning and role-based access controls (RBAC)

6. Maintain detailed working knowledge and awareness of concepts within the following: Identity & Access Management (IAM), Access Controls, Authorization, Encryption of data at rest / in transit, multi-factor authentication, SAML, Single-Sign-On, Social Sign On, web application firewalls, etc.

7. Work collaboratively across cross-functional teams to integrate IAM and/or cloud solutions and services; maintaining runbooks for cloud and/or IAM workflows and processes.

8. Able to provide support after normal business hours, as needed.

9. Perform other duties as assigned or apparent

NOTE: The Primary Accountabilities above are intended to describe the general content and requirements of the position and are not intended to be an exhaustive statement of duties. Incumbents may perform all or most of the Primary Accountabilities listed above. Specific goals or responsibilities will be documented in incumbents' performance objectives as outlined by the incumbents' immediate manager.

Supervisory Responsibilities

None

MINIMUM EDUCATION AND RELATED WORK EXPERIENCE:
• Bachelor's degree in Computer Science, Business, or related area
• Ten (10) years of progressive experience in Information Security related roles with at least Six (6) years of hands-on experience
• Security related certifications e.g., CISSP, CISM, CISA

ADDITIONAL QUALIFICATIONS:
• Ability to align compliance regulations (SOX, GLBA, etc.)
• Experience with being an audit liaison and support
• Experience with controls documentation and accuracy
• Experience with vendor management
• Experience with legal contract support
• Experience with simplified artifacts retrieval
• Ability to QA process for validation of evidence before providing
• Cybersecurity Insurance
• Experience with automation of evidence collection and process
• Able to provide support after normal business hours as needed
• Industry recognized certifications specific to IAM (e.g. Certified Identity and Access Manager, Identity and Access Administrator Associate, etc.)
• Working knowledge of industry frameworks related to information security (e.g. ISO 27000, NIST, etc.)
• Experienced in network and Security components, including firewalls, intrusion detection systems, anti-malware products, e-Discovery and forensics tools and products, IT Risk Management methodologies, data encryption, VPN's, vulnerability scanners, multiple operating systems (Windows, UNIX, Linux, etc.), cloud security groups, and directory services (Active Directory, LDAP)
• Subject Matter Expert (SME) level knowledge of security tools, trends, methodologies, and best practices for securing platforms and operating systems at the server, client, and handheld level
• Expert knowledge of information security risks and countermeasures for Windows, Unix/Linux platforms and cloud environments
• Experience with principal and policy-based security design methodologies with understanding of IaaS, PaaS, and SaaS models
• Able to create and manage Security solutions with a high degree of integration
• Strong understanding of regulatory requirements (PCI, SOX, GLBA) and how they impact information security functions
• Demonstrated ability to work effectively in a collaborative team environment as an individual contributor
• Strong business analysis skills
• Able to learn quickly, absorb and retain information, and apply knowledge when and where relevant
• Self-motivated and able to work on own initiative with minimal guidance and a desire to see tasks through to completion
• Experience managing a varied and heavy workload

#LI-Remote

Pay Range

The annual pay range for this position is $96,400 (minimum), $145,500 (midpoint), and $194,600 (maximum).*

*Typical hiring range is between the minimum and midpoint of the above pay range. Actual starting base pay may vary based on factors such as education, experience, skills, location and budget. Compensation above the midpoint is generally associated with experienced, long-tenured employees who have demonstrated sustained performance and expertise in the role.

Individuals in this role are eligible for:

  • Annual Bonus Award


Your work is critical to helping adult learners achieve their dreams, and we're committed to rewarding you for your efforts. We offer a competitive, comprehensive total rewards package designed to help you achieve your health, financial, educational and work-life balance goals.

Full-time employees are eligible for:

  • Medical, dental and vision plans; Flexible Spending Accounts; Health Savings Accounts; Life and Disability insurance; and our Wellness incentive program;
  • Competitive 401(k) employer match;
  • Substantial tuition discount for you and eligible dependents; and,
  • A generous time off package, including paid vacation, sick time and company holidays.*

*For more details around paid time off benefits, please click here.

Application Deadline is 09/29/2026.

About University of Phoenix

The University of Phoenix is a for-profit university that offers undergraduate and graduate degree programs in a variety of fields, including business, education, healthcare, and technology. The university was founded in 1976 and is headquartered in Tempe, Arizona. The university is known for its online programs, which allow students to complete their coursework from anywhere in the world. The university has faced criticism in recent years for its high tuition costs and low graduation rates, but it remains one of the largest universities in the United States.
Learn more about University of Phoenix
Size
20,000 employees
Industry

Similar Jobs

More Jobs at University of Phoenix

More Education, Government & Non-Profit Jobs

Find similar IT289 - Security Engr Sr- Governance and Compliance jobs: