CybersecurityJobs.io
← Back to all jobs

Job Description

The Executive Director of Cybersecurity and Privacy leads Charlotte-Mecklenburg Schools’ approach to protecting digital systems and sensitive information across the district. In this onsite role in Charlotte, NC, you will oversee cybersecurity program operations and data privacy functions, guiding policy, incident response execution, compliance, and day-to-day leadership of the cybersecurity staff. The position reports to the Cybersecurity Officer and provides both strategic direction and operational implementation for the office.

Key Responsibilities

  • Adhere to all state, federal, and local laws, policies, and procedures.
  • Lead, manage, supervise, and evaluate assigned programs and staff in the district.
  • Collaborate on cybersecurity strategic planning, policy development, incident response planning, and threat and risk analysis.
  • Oversee identity and access management security across district identity platforms, including security monitoring and incident response, conditional access and privileged access controls, risk-based authentication, and account and session security.
  • Conduct vendor data privacy reviews and ed-tech application vetting to ensure compliance with student data privacy laws and district privacy standards.
  • Investigate and analyze special projects and reporting, including determining methods for how work should be handled.
  • Partner with the Cybersecurity Officer to develop and maintain district-wide cybersecurity policies, standards, and procedures aligned with Board policy and industry frameworks such as NIST CSF.
  • Direct the day-to-day execution of district cybersecurity incident response plans and playbooks, covering investigation, containment, remediation, and reporting.
  • Oversee evaluation, piloting, and implementation of cybersecurity products and technologies identified through strategic planning, including SIEM/SOAR and endpoint detection and response.
  • Oversee required cybersecurity audits, vulnerability assessments, and compliance reviews, including security control documentation and remediation tracking.
  • Coordinate with other departments on disaster and contingency emergency management planning.
  • Ensure adherence to security, privacy, and intellectual property laws across the cybersecurity program.
  • Participate in development and administration of the department budget.
  • Oversee creation and maintenance of standard operating procedures, best practices, and playbooks across cybersecurity and privacy functions.
  • Facilitate and participate in professional development and related meetings.
  • Complete local, state, or federal surveys and reports accurately and promptly, including cybersecurity compliance reporting.
  • Create an inclusive environment with positive communication and public relations.
  • Perform related work as assigned or required.

Required and Preferred Qualifications

  • Comprehensive knowledge of cybersecurity principles, frameworks, threats, and best practices, including their application to incident response, risk management, and policy development.
  • Comprehensive knowledge of enterprise IT infrastructure and identity and access management security controls sufficient to oversee day-to-day cybersecurity operations.
  • Comprehensive knowledge of vendor data-privacy review and ed-tech application vetting, including compliance with student data privacy laws.
  • Skilled in SIEM/SOAR technologies, incident response, and security audit and compliance processes.
  • Ability to act as a thought partner and subject matter expert to the Cybersecurity Officer on strategy, policy, and incident response planning, translating direction into day-to-day execution for cybersecurity office staff.
  • Skilled in evaluating, selecting, and implementing cybersecurity and identity security technologies aligned with district goals.
  • Ability to supervise cybersecurity office staff, manage a departmental budget, and ensure compliance with applicable laws and regulations.
  • Strong judgment, problem-solving, and decision-making skills, including the ability to work independently under pressure.
  • Effective communication and relationship-building skills, with an ability to maintain confidentiality and evaluate program effectiveness.
  • Bachelor’s degree in cybersecurity, information security, computer science, information systems, or a related field required.
  • Prior experience directing cybersecurity audits, risk assessments, and remediation efforts required.
  • Possess and maintain a valid driver’s license or ability to provide own transportation.
  • Travel to school district buildings and professional meetings.
  • Minimum of five (5) years of progressively responsible experience in cybersecurity or information technology preferred.
  • Professional certifications (CISSP, CISM, CISA, etc.) preferred.
  • Experience with cybersecurity standards, frameworks, and best practices, including NIST CSF, preferred.
  • Equivalent combination of education and experience.

Technologies

  • NIST CSF
  • SIEM/SOAR
  • Endpoint detection and response

Compensation, Status, and Reporting

  • Pay Grade: 11
  • Status: Full-time, 12 months
  • Reports to: Cybersecurity Officer

Work Location and Scheduling

  • Location: Charlotte, NC (onsite)
  • Place of work: On the premises used by Charlotte-Mecklenburg Schools; the district may require work at other reasonable locations from time to time.
  • On-call: Must be on-call as a regular part of the job.

Working Conditions and Physical Requirements

  • Occasional exertion of up to twenty pounds of force.
  • Regular requirement for accurate and detailed information exchange through oral and written communication.
  • Constant operation of a computer and other office business equipment.
  • Ability to remain stationary for required meetings and work.
  • Ability to move to other work locations.
  • Visual acuity to prepare and analyze written or computer data, determine accuracy and thoroughness of work, and observe general surroundings and activities.
  • Hearing required to perceive information at normal spoken word levels and receive detailed information through oral communications.
  • Occasional exposure to outdoor weather conditions.
  • Work generally in a moderately noisy location (for example, business office, light traffic).
  • Ability to deal with people beyond giving and receiving instructions.
  • Adaptable to performing under mild to high levels of stress.

Education and Experience Summary

  • Bachelor’s degree in cybersecurity, information security, computer science, information systems, or a related field required.
  • Prior experience directing cybersecurity audits, risk assessments, and remediation efforts required.
  • Minimum five (5) years progressively responsible experience in cybersecurity or information technology preferred.
  • Professional certifications preferred.

Disclaimer: This job description is intended to indicate the general nature and level of work performed within this classification. It is not designed to be a comprehensive inventory of all duties, responsibilities, and qualifications required. The job description is sourced from employee interviews, internal documents, representative job descriptions in similar districts, and other state and federal agencies.

Similar Jobs