Key ResponsibilitiesProgram Development & Consulting- Assess a customer's current compliance posture and design a scalable, right-sized program that fits their size, structure, budget, and risk tolerance.
- Author the program's foundational artifacts — charter, governance structure, policies, roles and responsibilities, escalation paths, and compliance calendar — and establish merchant/departmental inventories, scope definitions, and data flow documentation.
- Define the metrics and reporting cadence by which the customer's leadership will judge the program's health, and advise on organizational placement — who owns compliance and what committee it reports through.
Program Management (Managed Services)- Lead the planning, execution, and delivery of customer PCI DSS, GLBA, and related compliance initiatives, applying a hybrid (predictive and adaptive) methodology that adapts to shifting scope, personnel turnover, and evolving standards.
- Develop and maintain schedules, work breakdown structures, RACI matrices, and risk/issue logs, coordinating stakeholders — IT, security, treasury/bursar, athletics, advancement, financial aid, and vendors — across a decentralized institution.
- Own the annual compliance lifecycle (scoping, evidence collection, SAQ/AOC, ASV scans, remediation tracking) and serve as the customer's primary point of contact, maintaining artifacts in CampusGuard Central®.
Capability Transfer & Enablement- Train and coach customer staff — compliance coordinators, departmental merchant contacts, IT and security personnel — to operate the program independently.
- Develop customer-facing playbooks, runbooks, checklists, and templates that outlive the engagement.
- Structure engagements with a deliberate handoff in mind, defining what “self-sufficient” means for each customer and managing toward it.
vISO Engagement Support (Virtual Information Security Officer)- Support senior CampusGuard advisors delivering fractional Information Security Officer services, drafting and maintaining security policies and procedures against applicable frameworks (PCI DSS, GLBA, NIST CSF/SP 800-171, HIPAA).
- Assemble and facilitate risk assessments, translating technical findings into business-language, budget-aware remediation roadmaps, and prepare materials for governance, leadership, and audit committees.
- Contribute to third-party/vendor risk reviews, incident response plan maintenance, and tabletop exercise facilitation.
Internal Contribution- Partner with CampusGuard's QSAs, assessors, and security engineers to ensure customer deliverables are accurate, timely, and consistent with our standards.
- Contribute to service delivery methodology, templates, and continuous improvement of the Managed Services practice.
- Support scoping and renewal conversations with Customer Relationship Managers, and maintain utilization across a portfolio of approximately [X] concurrent customers.
Required Qualifications
- Bachelor's degree in information systems, business, or a related field — or an equivalent combination of education and experience.
- 5+ years of progressive experience in program/project management, IT compliance, information security, or IT governance.
- Demonstrated end-to-end ownership of a compliance or information security program, including stakeholder management up to the executive level.
- Working knowledge of at least one major compliance framework (e.g., PCI DSS, GLBA), with the ability to build depth in others.
- Proven ability to drive accountability without direct authority, teach technical concepts to non-technical audiences, and communicate fluidly across working sessions and leadership briefings.
- Highly organized and self-directed, able to manage multiple concurrent customer engagements from inception through post-implementation, including plans, schedules, and budgets.
- Proficiency with common project management and productivity tools (e.g., Microsoft Project, Excel, the Microsoft 365 suite).
- Must obtain the PCIP (PCI Professional) credential within 12 months of hire.
- PMP (Project Management Professional) certification preferred; if not already held, must be obtained within 12 months of hire.
- Must pass a background check.
- Must be authorized to work in the United States without sponsorship.
Preferred Qualifications
- Direct higher education experience — having run a compliance or information security program at a college or university.
- Experience building a compliance or security program from the ground up, rather than only operating one someone else designed.
- Additional certifications such as PMI-ACP, CSM, CISM, CISA, CISSP, CRISC, or similar.
- Prior consulting or professional services experience managing a portfolio of customers.
- Familiarity with the higher education technology landscape and/or GRC platforms (e.g., Banner, Workday, Ellucian, Archer, ServiceNow).
- Experience with additional compliance frameworks (e.g., PCI DSS, GLBA, HIPAA, etc.).
Compensation range for this role is $70,000-$100,000 annually, depending on experience.
#LI-CW1
#LI-Remote
Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: