Berklee College of Music

Senior Director of Information Security

Berklee College of Music$160K — $180K *
US-AnywhereRemote in United States
Education, Government & Non-Profit
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of progressive cybersecurity and IT experience, including 3+ years in a leadership role.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Demonstrated experience managing enterprise security solutions and cloud security architectures.
  • Direct experience leading incident response and vulnerability management.
  • Proven ability to interpret and enforce compliance requirements and security standards.
  • Exceptional oral and written communication skills, suitable for presenting to executive leadership.

Responsibilities

  • Establish and optimize security processes to prevent unauthorized access to systems.
  • Supervise and mentor the performance of the Information Security Analyst.
  • Implement security automation and streamline workflows for efficiency.
  • Collaborate with IT operations teams to ensure proper security protocol implementation.
  • Develop and enforce institutional IT security policies in alignment with legal regulations.
  • Oversee budget processes, negotiate vendor contracts, and manage security-related procurements.
  • Lead project management for security initiatives from inception to rollout.

Benefits

  • Comprehensive healthcare and wellness programs.
  • Generous paid time off and holiday schedule.
  • Opportunities for professional development and training.
  • Retirement savings plan with employer match.
  • Dynamic and innovative work environment.
Full Job Description

Job Description:

The Senior Director of Information Security serves as Berklee’s primary information security authority and hands-on technical leader. Operating in a high-impact, lean team environment, the Sr. Director balances strategic governance, policy development, and budget management with active technical leadership. Reporting to the VP & CIO, the Sr. Director directly supervises the Information Security Analyst and works collaboratively across IT operations to protect Berklee's digital assets, ensure regulatory compliance, and lead incident response efforts.

The Sr. Director of Information Security possesses a strong technical background in risk management, threat mitigation, and technical controls. As a hands-on leader, they provide strategic vision and technical guidance both to the internal security function and to cross-functional IT operations and engineering teams to build a secure, scalable environment across Berklee’s global networks, applications, and systems. 

In partnership with executive leadership and the Office of General Counsel, this role develops, maintain, and enforces the College’s Information Security Policy, standards, and awareness programs to ensure compliance with relevant statutes and regulations. The Sr. Director oversees security system architecture, evaluates emerging technologies, and serves as the primary subject manager expert for enterprise security design.

Additionally, the Sr. Director manages Berklee's overarching IT security strategy, roadmap, and budget. This role requires exceptional communication skills, including the ability to translate complex technical risks into clear concepts for leadership, faculty, staff, and external partners.

ESSENTIAL JOB DUTIES:

Operational & Technical Leadership

  • Establish, monitor, and optimize security processes and technical controls to prevent unauthorized access to Berklee's networks, systems, and cloud environments. 
  • Directly supervise, mentor, and manage the performance and professional development of the Information Security Analyst. 
  • Implement security automation, orchestration, and streamlined workflows to maximize team efficiency and reduce repetitive manual tasks. 
  • Partner with broader IT operations, networking, and engineering teams to provide hands-on security guidance, ensure proper protocol implementation, and promote security awareness across the division. 

Strategic, Financial & Governance Oversight

  • Develop, maintain, and enforce institutional IT security policies and programs in alignment with legal regulations (e.g., FERPA, PCI, GDPR, etc.) and higher ed standards. 
  • Oversee IT security budget processes, forecast costs, negotiate vendor contracts, and manage security-related procurements to align with institutional goals. 
  • Facilitate third-party security audits, risk evaluations, and vendor security reviews (including HECVAT assessments). 
  • Actively participate in the IT division’s change management process to ensure new systems and configuration changes adhere to security baselines.
  • Oversee institutional security awareness and training programs for faculty, staff, and students. 

Engineering, Security Operations & Incident Response

  • Oversee threat monitoring across SOC tools and SIEM systems; direct vulnerability assessments, risk reviews, and penetration testing remediation plans. 
  • Define security requirements and design policies governing Identity & Access Management (IAM), multi-factor authentication, single sign-on, and cloud connections. 
  • Serve as the primary technical and escalation lead during potential or actual security incidents or data breaches and maintain transparent, proactive communication with IT leadership, executive stakeholders, and external partners regarding threat environments and security posture.
  • Lead project management for security initiatives from inception to rollout, ensuring alignment with institutional technology roadmaps. 
  • Act as the primary security subject matter expert and advisor to the VP & CIO, executive leadership, and external partners. 

Ideal Profile

The ideal candidate combines hands-on technical cybersecurity expertise with strategic leadership and financial management capabilities. They possess experience managing heterogeneous environments spanning on premises, co-located, and cloud architecture, with the ability to translate complex technical risks into clear, actionable guidance for executive leadership and community stakeholders. Operating as a player-coach, they are skilled in incident response, risk management, policy design, and vendor negotiations, with the interpersonal agility needed to mentor an Information Security Analyst and partner across broader IT teams. 

Minimum Qualifications

  • 10+ yearsof progressive cybersecurity and IT experience, including 3+ years in a team lead or supervisor role.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or an equivalent combination of education and experience). 
  • Demonstrated experience managing enterprise security solutions, SIEM systems, identity and access management (IAM), and cloud security architectures. 
  • Direct experience leading incident response, threat detection, vulnerability management, and infrastructure risk remediation.
  • Proven ability to interpret, implement, and enforce compliance requirements and security standards (e.g., FERPA, PCI-DSS, 201 CMR 17.00, NIST). 
  • Exceptional oral and written communication skills, including the ability to present security updates to executive leadership and lead vendor contract discussions. 


Years of Experience:

  • 10+ Years


Level of Education:

  • Bachelor’s Degree required; Master’s Degree preferred

Preferred Qualifications and Knowledge:

  • CISSP, CISM, or equivalent professional cybersecurity credentials.
  • Master’s degree, MBA, or advanced degree in Information Assurance, Cybersecurity, or Technology Management
  • Experience working within higher education or a similarly decentralized, open-network institutional environment. 
  • Familiarity with cybersecurity frameworks (ISO 27001, CIS Controls) and higher education security assessment tools (HECVAT). 
  • Hands-on experience managing IT security budgets, forecasting costs, and negotiating software and service contracts. 
  • Proficiency with Google Workspace, Rapid Identity, Microsoft 365, Active Directory, endpoint detection and response (EDR) solutions, and multi-OS platforms (Windows, Linux). 

Core Competencies:

  • Ability to directly supervise and mentor an Information Security Analyst while staying actively engaged in daily security operations. 
  • Capability to align IT security investments, vendor procurements, and strategic roadmaps with overall institutional priorities. 
  • Demonstrated skill in embedding security practices into systems, networking, and help desk operations without direct managerial authority over those teams. 
  • Calmness and technical authority under pressure during actual or potential data breaches and security incidents. 
  • Ability to translate complex technical concepts into clear written and verbal formats, as well as elicit detailed technical requirements to establish defined project milestones, tasks, and goals.
  • In-depth knowledge of security practices, institutional policies, and technology service delivery frameworks (such as ITIL) to navigate complex operational situations effectively.

HIRING RANGE:

$160,000 to $180,000; salary dependent on relevant experience and education. 

Please visit the  page to learn more about the benefits of working at Berklee.

Workplace Considerations

  • Berklee College maintains a global infrastructure. Planned and unplanned work may be required after hours or on weekends. 
  • The Senior Director of Information Security may be required to participate in 7x24 on-call coverage. 
  • Light physical work as related to server systems may be required. 
  • Employees will be required to stand for periods of time or move throughout the college campus, including occasional travel to any off-site hosting facilities. 

Employee Type:Staff

About Berklee College of Music

Berklee College of Music is a private music college located in Boston, Massachusetts. The college was founded in 1945 and has grown to become one of the most prestigious music schools in the world. Berklee College of Music offers a wide range of undergraduate and graduate programs in music performance, music production, music business, and more. The college has a strong commitment to innovation and has been at the forefront of music education for over 75 years. Berklee College of Music is also committed to diversity and inclusion, and has implemented a number of initiatives to support underrepresented groups in the music industry.
Learn more about Berklee College of Music
Size
4,000 employees
Industry

Similar Jobs

More Jobs at Berklee College of Music

More Education, Government & Non-Profit Jobs

Find similar Senior Director of Information Security jobs: