Director III, Info Technology

The Director of Data Protection, Privacy, and Risk is responsible for establishing, implementing, and managing the organization's IT risk management and cybersecurity governance program. This position oversees IT risk assessment, data protection i...

  • 520809
  • Manhattan, Kansas, United States
  • Division of Info Tech
  • Staff Full Time (Unclassified - Regular)
  • Closing at: Feb 6 2026 - 23:55 CST
    • On-site
    View favorites

    About This Role

    The Director of Data Protection, Privacy, and Risk is responsible for establishing, implementing, and managing the organization's IT risk management and cybersecurity governance program. This position oversees IT risk assessment, data protection including privacy, third-party risk management (including supply chain security), compliance monitoring, security policy development, security awareness training, and security exception management.

    Worksite Description

    This position is On-site.

    All employees must reside in the United States when they begin working to comply with state law. K-State is unable to provide remote or hybrid work opportunities for residents of the state of Idaho.

    What You'll Need to Succeed

    Minimum Qualifications:

    • Requires a high school diploma (or equivalent) and ten years of relevant experience in a combination of the following: IT risk management and leadership, cybersecurity governance and compliance and/or developing and delivering security programs at scale. Requirements may be met through a combination of education and experience.

     

    Preferred Qualifications:

    • Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or related field
    • Minimum of 8 years of progressive experience in IT risk management, cybersecurity governance, compliance, or related fields
    • Minimum of 3 years of supervisory or team leadership experience
    • Demonstrated expertise in IT risk assessment methodologies and frameworks (NIST CSF, ISO 27001/27005, FAIR)
    • Strong understanding of cybersecurity principles, technologies, and threat landscape
    • Experience with regulatory compliance requirements relevant to the organization
    • Master's degree in Cybersecurity, Information Systems, Risk Management, or MBA
    • Professional certifications such as CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), CISSP (Certified Information Systems Security Professional), CGRC (Certified GRC Professional), or CISA (Certified Information Systems Auditor)
    • Demonstrated success building IT risk management or GRC programs from inception
    • Extensive experience with third-party risk management and supply chain security
    • Experience in higher education, healthcare, financial services, or similarly regulated industry
    • Strong knowledge of privacy regulations (GDPR, CCPA, HIPAA), compliance frameworks (SOC 2, ISO 27001, Secure Control Framework), and regulatory requirements (PCI DSS, GLBA, FERPA, CMMC)
    • Experience with GRC platforms and risk management tools
    • Proven ability to communicate complex technical risks to non-technical executives and board members
    • Experience developing and delivering security awareness programs at scale
    • Strong project management skills and experience leading cross-functional initiatives
    • Must maintain currency with evolving cybersecurity threats, regulations, and industry best practices
    • Strong analytical skills with ability to synthesize complex technical information into executive communications
    • Excellent written and verbal communication skills with ability to influence stakeholders at all levels
    • Ability to work independently and manage multiple priorities in a dynamic environment
    • Strong business acumen and ability to balance security requirements with operational needs

    Sponsorship eligibility:

    Candidates must be legally authorized to work in the U.S. on an ongoing basis without sponsorship

    How to Apply

    Please submit the following documents:

    • Resume
    • Cover Letter
    • Three Professional References

    Application Window

    Applications close on: 2/6/26

    Anticipated Hiring Pay Range

    $110,000-$140,000

     

     

    Why Join Us:

    Kansas State University offers a supportive and inclusive community, dedicated to your professional growth. While specific benefits may vary by position, many roles come with comprehensive packages that support your well-being and work-life balance, including health and life insurance, retirement plans, and generous paid time off. To learn more about benefits that are available for various positions, visit our benefits overview page.

    Work Authorization: 

    Applicants must be currently authorized to work in the United States at the time of employment.

    Equal Employment Opportunity:

    Kansas State University is an Equal Opportunity Employer. All applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender, gender identity, age, national origin, disability or status as a protected veteran.

    Remote and Hybrid work options:

    Some positions are eligible for remote or hybrid working arrangements.  An employee who is working in a remote or hybrid capacity for K-State must reside within the United States in order to comply with all federal and state laws, filings, or tax requirements. Remote and hybrid work arrangements are not available for anyone who resides in the state of Idaho.

    Relocation to Kansas: 

    Kansas participates in the MakeMyMove program, which connects eligible newcomers with participating communities offering financial incentives, housing support, and local perks to help make your move easier and more rewarding. If relocating you can visit the site apply online for the program incentives. 

    Background Screening Statement:

    Upon acceptance of a contingent offer of employment, a candidate may be subject to a background check per K-State’s background check policy.

    Interview Preferences:

    Kansas State University honors interview preferences for qualified applicants who are veterans or individuals with disabilities. Eligible applicants who meet the minimum qualifications, submit all required application materials, and submit required preference documentation by the closing date on the job advertisement will be granted a first-level interview.

    The disability and veteran interview preferences do not apply to student employment positions, temporary positions, athletics positions, academic and administrative department heads*, positions that require licensure as a physician, and positions that require that the employee be admitted to practice law in Kansas.

    *Heads of Departments refers to any individual holding a primary leadership role responsible for the overall strategic direction, management and operational oversight of a recognized academic or administrative unit within the university.

    To learn more about interview preferences at K-State, please visit our interview preferences page.