Baltimore Ravens
IT Security Director
Dept: Information Technology
Position Reports To: VP of IT
Full-Time / Exempt
General Description:
This position will fill a critical role for the organization by directing and managing security practices, policies/standards and developing and implementing comprehensive strategies to prevent unauthorized access to company assets and/or information. The primary responsibilities include assessing risks and driving security policies/governance/compliance across the organization (including third-party vendors) to ensure secure configuration of systems and appropriate awareness of employees. This position will also focus on ensuring organizational compliance with PCI-DSS, PII, HIPAA, and NFL Security guidelines. In addition, the position will be responsible for security monitoring, incident response, engineering/threat/vulnerability management, and identity and access management. This position will advise the club on action steps, implement enforcement and adhere to best practices in the IT security space.
Primary Job Duties:
1. Set the vision for enterprise security strategy and execution roadmap.
Establish, maintain, and optimize security policies and ensure proper implementation of those policies on all data and systems, voice networks, local area and wide area networks, communications software, equipment, and network facilities, using the most secure configuration and the most efficient structure for both on premise and cloud environments.
2. Perform security audit for compliance standards
Develop security guidelines and policies to address and test compliance with regulatory requirements and standards, such as PCI-DSS, PII, DHS, HIPAA, and all other relevant security standards. Manage recurring NFL-initiated risk assessments and audits intended to identify potential risks, concerns or deficiencies in the organization’s information technology ecosystem.
3. Maintain integrity of network systems and platforms
Ensure that systems are updated with patches and backed up regularly. Ensure the security and integrity of all networks and data. Develop, implement and test disaster recovery policies and procedures and establish contingency plans for business continuity purposes.
4. Monitor security
Manage the security and integrity of the network, applications, servers, and endpoints by monitoring security logs and checking for suspicious activity, security problems, or errors. Investigate and resolve irregularities immediately. Track historical activity for trends or patterns for future comparison and planning. Intervene when necessary to protect the franchise, its employees and/or data.
5. Develop security training/support for all company employees
Select security training videos for ongoing training of all employees and review and enforce employee compliance. Ensure employee devices are properly equipped with endpoint protection software to protect against all security threats and to safeguard the integrity of equipment/data. Serve as liaison and resident expert in IT security.
6. Document security policies and processes.
Establish written log of all requests and problems, noting the resolution for future reference. Document new systems/software and the related processes used for each one. Document compliance to ensure written record for regulatory purposes. Report on best practices, areas for improvement and/or needs for the Club.
7. Budget Management
Work with the VP of IT to strategize on proper allocation of resources for IT security activities effectively. Use a data driven approach to ensure that the organization has an adequate budget to maintain all required security and risk management initiatives. Stay on top of trends, make recommendations and monitor execution of tools and technologies.
8. Vendor Management
Manage all security vendors as well as stakeholders, providing guidance, training and support to ensure the effective execution of security initiatives, policies and procedures. Influence stakeholders in terms of IT security management.
Work Arrangements:
This position will work in the office at least 4 days a week.
Salary and Benefits:
Application Process
To be considered for this position, applicants must complete the online application, submit a resume and cover letter. Any applications that are missing the required information will not be considered.
As an equal opportunity employer, we consider candidates from all backgrounds and identities. We encourage individuals from all ethnicities, sexual orientations, gender identities, socio economic status, as well as military veterans and individuals with disabilities, to apply.