The Executive Director of Cybersecurity and Privacy leads Charlotte-Mecklenburg Schools’ approach to protecting digital systems and sensitive information across the district. In this onsite role in Charlotte, NC, you will oversee cybersecurity program operations and data privacy functions, guiding policy, incident response execution, compliance, and day-to-day leadership of the cybersecurity staff. The position reports to the Cybersecurity Officer and provides both strategic direction and operational implementation for the office.
Key Responsibilities: Adhere to all state, federal, and local laws, policies, and procedures. Lead, manage, supervise, and evaluate assigned programs and staff in the district. Collaborate on cybersecurity strategic planning, policy development, incident response planning, and threat and risk analysis. Oversee identity and access management security across district identity platforms, including security monitoring and incident response, conditional access and privileged access controls, risk-based authentication, and account and session security. Conduct vendor data privacy reviews and ed-tech application vetting to ensure compliance with student data privacy laws and district privacy standards. Investigate and analyze special projects and reporting, including determining methods for how work should be handled. Partner with the Cybersecurity Officer to develop and maintain district-wide cybersecurity policies, standards, and procedures aligned with Board policy and industry frameworks such asNIST CSF .Direct the day-to-day execution of district cybersecurity incident response plans and playbooks, covering investigation, containment, remediation, and reporting. Oversee evaluation, piloting, and implementation of cybersecurity products and technologies identified through strategic planning, includingSIEM/SOARand endpoint detection and response. Oversee required cybersecurity audits, vulnerability assessments, and compliance reviews, including security control documentation and remediation tracking. Coordinate with other departments on disaster and contingency emergency management planning. Ensure adherence to security, privacy, and intellectual property laws across the cybersecurity program. Participate in development and administration of the department budget. Oversee creation and maintenance of standard operating procedures, best practices, and playbooks across cybersecurity and privacy functions. Facilitate and participate in professional development and related meetings. Complete local, state, or federal surveys and reports accurately and promptly, including cybersecurity compliance reporting. Create an inclusive environment with positive communication and public relations. Perform related work as assigned or required.
Required and Preferred Qualifications:
  • Comprehensive knowledgeof cybersecurity principles, frameworks, threats, and best practices, including their application to incident response, risk management, and policy development.
  • Comprehensive knowledgeof enterprise IT infrastructure and identity and access management security controls sufficient to oversee day-to-day cybersecurity operations.
  • Comprehensive knowledgeof vendor data-privacy review and ed-tech application vetting, including compliance with student data privacy laws.
  • Skilled inSIEM/SOARtechnologies, incident response, and security audit and compliance processes.
  • Ability to act as a thought partner and subject matter expert to the Cybersecurity Officer on strategy, policy, and incident response planning, translating direction into day-to-day execution for cybersecurity office staff.
  • Skilled in evaluating, selecting, and implementing cybersecurity and identity security technologies aligned with district goals.
  • Ability to supervise cybersecurity office staff, manage a departmental budget, and ensure compliance with applicable laws and regulations.
  • Strong judgment, problem-solving, and decision-making skills, including the ability to work independently under pressure.
  • Effective communication and relationship-building skills, with an ability to maintain confidentiality and evaluate program effectiveness.
  • Bachelor’s degree in cybersecurity, information security, computer science, information systems, or a related field required.
  • Prior experience directing cybersecurity audits, risk assessments, and remediation efforts required.
  • Possess and maintain a valid driver’s license or ability to provide own transportation.
  • Travel to school district buildings and professional meetings.
  • Minimum of five (5) years of progressively responsible experience in cybersecurity or information technology preferred.
  • Professional certifications (CISSP, CISM, CISA, etc.) preferred.
  • Experience with cybersecurity standards, frameworks, and best practices, includingNIST CSF, preferred.
  • Equivalent combination of education and experience.
  • TechnologiesNIST CSFSIEM/SOAREndpoint detection and response
  • Compensation, Status, and Reporting
Pay Grade: 11
Status: Full-time, 12 months
Reports to: Cybersecurity Officer
Work Location and Scheduling
Location:
  • Charlotte, NC (onsite)
  • Place of work:
  • On the premises used by Charlotte-Mecklenburg Schools; the district may require work at other reasonable locations from time to time.
On-call: Must be on-call as a regular part of the job.
Working Conditions and Physical Requirements: Occasional exertion of up to twenty pounds of force. Regular requirement for accurate and detailed information exchange through oral and written communication. Constant operation of a computer and other office business equipment. Ability to remain stationary for required meetings and work. Ability to move to other work locations. Visual acuity to prepare and analyze written or computer data, determine accuracy and thoroughness of work, and observe general surroundings and activities. Hearing required to perceive information at normal spoken word levels and receive detailed information through oral communications. Occasional exposure to outdoor weather conditions. Work generally in a moderately noisy location (for example, business office, light traffic).Ability to deal with people beyond giving and receiving instructions. Adaptable to performing under mild to high levels of stress.
Education and Experience: Summary Bachelor’s degree in cybersecurity, information security, computer science, information systems, or a related field required. Prior experience directing cybersecurity audits, risk assessments, and remediation efforts required.
Disclaimer: This job description is intended to indicate the general nature and level of work performed within this classification. It is not designed to be a comprehensive inventory of all duties, responsibilities, and qualifications required. The job description is sourced from employee interviews, internal documents, representative job descriptions in similar districts, and other state and federal agencies.

Also on the board Same function, level within a rung

Level

Manager

Location

Charlotte, NC

Occupation

Education Administrators, Kindergarten through Secondary

Industry

Elementary and Secondary Schools

Posted

yesterday

Apply for this role →