Tides is a nonprofit and philanthropic organization committed to advancing social justice. We work across the social sector to shift power to communities of color and other groups historically denied power.
Centering equity and justice in everything we do, we collaborate in deep partnership with movement leaders, nonprofits, donors, foundations, and corporations to amplify the impact of their work by providing services like fiscal sponsorship, donor advised funds, grant making, and a variety of innovative solutions. Learn more at tides.org.
Reporting to the Senior Director, Information Technology, the Director, Information Security will own and deliver on the “Six P’s”: Establish the processes, hire and manage the people, manage the portfolio, supervise the policy & architecture, own performance management for team and any third parties, and manage the projects for a comprehensive cybersecurity approach for this energetic and progressive 501c3 organization in a dynamic, cloud-forward environment.
Ideal candidates will have experience scaling and building out an existing cybersecurity framework navigating compliance issues and developing policies. The role will interact with teams across the organization to ensure their needs are met.
Provides regular reporting on the current status of the cybersecurity program to enterprise risk teams, senior business leaders.
Works with the vendor management office to ensure that cybersecurity requirements are included in contracts by liaising with vendor management and procurement organizations.
Directs the creation of a targeted cybersecurity awareness training program for all employees, contractors, and approved system users, and establishes metrics to measure the effectiveness of this security training program for different audiences.
Advises on the cyber risk posture of the organization, including the mandatory application of controls.
Leads the cybersecurity function across the company to ensure consistent and high-quality information security management in support of the business goals.
Determines the cybersecurity approach and operating model in consultation with stakeholders and aligned with the risk management approach and compliance monitoring of non-digital risk areas.
Manages an effective cybersecurity organization, consisting of one direct report
Develops a cybersecurity vision and strategy that is aligned to organizational priorities and enables and facilitates the organization's business objectives, and ensures senior stakeholder buy-in and mandate.
Develops, implements, and monitors a strategic, comprehensive cybersecurity program to ensure appropriate levels of confidentiality, integrity, and availability of information assets owned, controlled, or/and processed by the organization as well as the meeting of safety, privacy, reliability, and resilience requirements as needed.
Works effectively with business units to facilitate cybersecurity risk assessment and risk management processes and empowers them to make the right decisions that fall within the risk appetite of their organization.
Enhances the security posture by adopting a cybersecurity framework that is applicable to the organization: ITIL, COBIT/Risk IT, and National Institute of Standards and Technology (NIST) Cybersecurity Framework.
Develops and owns a document framework of continuously up-to-date cybersecurity policies, standards, and guidelines. Oversees the approval and publication of these cybersecurity policies and practices.
Facilitates a metrics and reporting framework to measure the efficiency and effectiveness of the program, facilitates appropriate resource allocation, and increases the maturity of the cybersecurity, and reviews it with stakeholders at the executive and board levels.
Coordinates the development of implementation of incident response plans and procedures to ensure that business-critical services are recovered in the event of a security event; provides direction, support, and in-house consulting in these areas.
Outstanding verbal and written communication skills
Proven track record of start-to-finish project management
An understanding of all current legislation and regulations pertaining to Tides
Experience in effective coordination, prioritization, collaboration, organization, and successful project delivery
Knowledge of IT Security related hardware, software, and vendor solutions
An analytical mind with the ability to quickly get to the root cause of issues
You will need to be organized, efficient and able to work unsupervised under your own initiative
Outstanding written and verbal communication skills
8 years of direct experience and relevant bachelor’s degree in a technology discipline; or 10 years of relevant experience in cybersecurity roles.
4 years of experience in a supervisory capacity, required
Experience with cybersecurity management of cloud and SaaS environments, required
Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or other similar credentials
Please submit your resume and a cover letter expressing why you are well-qualified for this role and your motivation for joining the team at Tides. For best consideration, apply by Friday, October 3, 2025 at 11:59pm ET.
We look forward to reviewing applications from all qualified job seekers. We strongly encourage applications from women, people of color, and bilingual and bicultural individuals, as well as members of the LGBTQIA+ communities. No applicant will be discriminated against because of their race, religion, sex, national origin, ethnicity, age, disability, political affiliation, sexual orientation, gender identity, color, marital status, or medical condition including acquired immune deficiency syndrome (AIDS) and AIDS-related conditions. Pursuant to the San Francisco Fair Chance Ordinance, we encourage and will consider qualified applicants with arrest and conviction records. Where required by state law, we utilize E-Verify as a part of our employment authorization process.
Reasonable accommodation will be made so that all who are interested may participate in our interview process. If you are in need of an accommodation, please advise in writing at the time you apply.
If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.
Delaware Nation Investments/Emerging Technologies seeks a cleared Senior Systems Administrator to manage RMF-driven cybersecurity, STIG implementation, and OT/IT network operations across AFSC depot locations.
Adtalem Global Education is hiring an Associate Systems Analyst in Lisle, IL to support and optimize the Canvas LMS, integrations, and cloud applications in a hybrid work setting.
Quizlet is hiring a Staff Corporate Engineer in San Francisco to architect and automate cloud-first corporate systems, identity & device management, and operational support for business users.
The University of Chicago Press is hiring an Electronic Publishing Specialist to support and administer Editorial Manager and Arbortext workflows for its scholarly journals.
Experienced ERP-focused Business Analyst needed to support shipping, receiving and warehouse processes, manage system configurations and lead ERP implementations across Stratas Foods plants.
A growth-focused Business Systems Analyst role supporting Salesforce and enterprise applications while learning to design and implement AI-driven workflow automations.
TTEC Digital is hiring a remote ServiceNow Technical Consultant (FSM) to design and deliver complex ServiceNow solutions, lead implementations, and provide advanced technical guidance to clients and internal teams.
University of Rochester is hiring a Customer Technology Support Tech I to deliver frontline device and desktop support for staff and clinicians at Highland Hospital.
University of Rochester is hiring a Customer Technology Support Tech II to deliver in-person and remote endpoint support, device deployment, and user training across campus.
Lead Delinea's Cloud Support and Data Center teams to deliver secure, resilient infrastructure and operational excellence across on-prem and cloud environments.
Experienced DB2 for z/OS systems programmer needed to lead database administration, upgrades, tuning and migration work for Ensono's mainframe clients in a remote, customer-facing role.
Experienced ISSE needed in Huntsville to lead RMF/ATO efforts, perform vulnerability and compliance assessments, and coordinate security for mission systems in on-prem and cloud environments.
Support Systems Administrator needed to maintain and enhance CX platforms (Zendesk, Amazon Connect, Khoros, etc.), automate routine tasks, and partner with support and engineering teams to improve agent and customer workflows.