{"21663732":{"jobPath":"/jobs/21663732/senior-director-privacy-and-cybersecurity","source":"naylor","job":"21663732","jobTitle":"Senior Director, Privacy and Cybersecurity"},"21663853":{"jobPath":"/jobs/21663853/chief-audit-officer-and-director-internal-audit-division","source":"naylor","job":"21663853","jobTitle":"Chief Audit Officer and Director, Internal Audit Division"},"21662885":{"jobPath":"/jobs/21662885/alnylam-pharmaceuticals-global-patient-safety-and-risk-management-postdoctoral-research-fellow","source":"naylor","job":"21662885","jobTitle":"Alnylam Pharmaceuticals-Global Patient Safety and Risk Management Postdoctoral Research Fellow"},"21659077":{"jobPath":"/jobs/21659077/senior-certified-pharmacy-technician-340b-retail-audit-team-days-001","source":"naylor","job":"21659077","jobTitle":"Senior Certified Pharmacy Technician - 340B Retail Audit Team - Days (001)"},"21660586":{"jobPath":"/jobs/21660586/manager-treasury-and-risk-management","source":"naylor","job":"21660586","jobTitle":"Manager, Treasury and Risk Management"},"21661612":{"jobPath":"/jobs/21661612/cyber-exercise-analyst-2-ohio-cyber-range-institute-school-of-information-technology-cech","source":"naylor","job":"21661612","jobTitle":"Cyber Exercise Analyst 2, Ohio Cyber Range Institute, School of Information Technology, CECH"},"21660962":{"jobPath":"/jobs/21660962/part-time-faculty-cybersecurity-instructor","source":"naylor","job":"21660962","jobTitle":"Part-time Faculty Cybersecurity Instructor"},"21661614":{"jobPath":"/jobs/21661614/assistant-professor-elementary-middle-science-education-school-of-education-cech-it","source":"naylor","job":"21661614","jobTitle":"Assistant Professor, Elementary/Middle Science Education, School of Education, CECH-IT"},"21634238":{"jobPath":"/jobs/21634238/associate-vice-president-of-audit-services-and-institute-compliance-chief-compliance-officer","source":"naylor","job":"21634238","jobTitle":"Associate Vice President of Audit Services and Institute Compliance & Chief Compliance Officer"},"21661615":{"jobPath":"/jobs/21661615/asst-professor-instructional-design-and-technology-school-of-education-cech-it","source":"naylor","job":"21661615","jobTitle":"Asst Professor, Instructional Design and Technology, School of Education, CECH-IT"},"21600937":{"jobPath":"/jobs/21600937/senior-it-auditor","source":"naylor","job":"21600937","jobTitle":"Senior IT Auditor"},"21653924":{"jobPath":"/jobs/21653924/information-systems-auditor-auditor-iv","source":"naylor","job":"21653924","jobTitle":"Information Systems Auditor (Auditor IV)"},"21657309":{"jobPath":"/jobs/21657309/senior-it-associate","source":"naylor","job":"21657309","jobTitle":"Senior IT Associate"},"21656855":{"jobPath":"/jobs/21656855/it-service-desk-support-staff-learn-and-earn-grant-multiple-vacancies-middlesex-community-college","source":"naylor","job":"21656855","jobTitle":"IT Service Desk Support Staff - Learn and Earn Grant (Multiple Vacancies) - Middlesex Community College"},"21623566":{"jobPath":"/jobs/21623566/senior-internal-audit-data-analyst","source":"naylor","job":"21623566","jobTitle":"Senior Internal Audit Data Analyst"},"21521706":{"jobPath":"/jobs/21521706/it-audit-division-director","source":"naylor","job":"21521706","jobTitle":"IT Audit Division Director"},"21636806":{"jobPath":"/jobs/21636806/senior-it-and-data-analytics-internal-auditor","source":"naylor","job":"21636806","jobTitle":"Senior IT and Data Analytics Internal Auditor"},"21662358":{"jobPath":"/jobs/21662358/museum-security-guard-part-time","source":"naylor","job":"21662358","jobTitle":"Museum Security Guard (Part-Time)"},"21663923":{"jobPath":"/jobs/21663923/chief-information-officer","source":"naylor","job":"21663923","jobTitle":"Chief Information Officer"},"21620258":{"jobPath":"/jobs/21620258/technology-audit-manager","source":"naylor","job":"21620258","jobTitle":"Technology Audit Manager"},"21662718":{"jobPath":"/jobs/21662718/adjunct-instructors-department-of-computer-science-and-information-technology","source":"naylor","job":"21662718","jobTitle":"Adjunct Instructors - Department of Computer Science and Information Technology"},"21657288":{"jobPath":"/jobs/21657288/district-director-of-it-infrastructure","source":"naylor","job":"21657288","jobTitle":"District Director of IT Infrastructure"},"21623479":{"jobPath":"/jobs/21623479/director-of-government-relations","source":"naylor","job":"21623479","jobTitle":"Director of Government Relations"},"21653811":{"jobPath":"/jobs/21653811/chief-regulatory-and-government-affairs-officer-crgao","source":"naylor","job":"21653811","jobTitle":"Chief Regulatory and Government Affairs Officer (CRGAO)"},"21661154":{"jobPath":"/jobs/21661154/physician-director-government-relations","source":"naylor","job":"21661154","jobTitle":"Physician Director, Government Relations"}}
The budgeted salary range for this position is currently $136,000 to $155,000 per year.
Preferred Education:
4 Year Degree/Bachelor Degree
Certifications:
CISM
CISM - Certified Information Security Manager
POSITION SUMMARY
(Eligible for Hybrid/ 3 days in office - Alexandria, VA)
The Senior Director, Privacy and Cybersecurity provides executive leadership to protect United Way Worldwide’s data, systems and reputation. The Senior Director establishes a comprehensive security, privacy, AI and data governance program rooted in NIST Cybersecurity, NIST Privacy, and NIST AI Risk Management Frameworks, aligned with global best practices.
The Senior Director acts as a thought leader, coach, and advisor, ensuring that privacy, cybersecurity, and AI governance principles are embedded across business operations. The Senior Director partners with Information Technology, Marketing and Communications, Development, and the Office of General Counsel to foster a culture of trust, resilience, and compliance.
The Senior Director also serves as the organization’s Data Protection Officer (DPO), overseeing data protection strategies, compliance with global privacy regulations (GDPR, CCPA, HIPAA, etc.), vendor risk management, and the secure and responsible adoption of Artificial Intelligence (AI). This includes embedding privacy and security controls in AI systems, evaluating AI vendors, and ensuring alignment with emerging regulations (EU AI Act, US AI Bill of Rights).
KEY RESPONSIBILITIES/ESSENTIAL DUTIES OF POSITION
An individual must be able to perform each essential duty listed below at a satisfactory level:
Security and Privacy | UWW Internal Operations
Privacy
Serve as the Data Protection Officer (DPO) for United Way Worldwide
Monitor, interpret, and implement compliance with global privacy regulations (GDPR, CCPA, HIPAA, PIPEDA, etc.), along with analyzing and advising on recent trends for non-profit organizations.
Lead alignment and compliance with established and emerging privacy laws and regulations applicable to LUWs at a global level.
Develop, deliver and drive awarenes of data privacy and security privacy awareness programs and training. While providing coaching & educating staff about applicable privacy practices, drive awareness on data privacy and security issues, including development of training, policies, and guidelines that help business stakeholders spot and address data protection and privacy issues as they emerge in development of new products and technologies
Champion Privacy by Design when developing, implementing, or considering new data systems
Provide guidance and feedback in contracting/purchasing process to ensure vendors meet security/privacy requirements and to advise on optimizing data matters such as data minimization, flow and security
Conduct Privacy Impact Assessments (PIA: Privacy of Data) and Data Privacy Impact Assessments (DPIA: Risk) and Transfer Impact Assessments (TIA)
Identify, build or implement tools to manage privacy across systems
Establish and lead cybersecurity program in alignment with NIST CSF and NIST SP 800-53. Operationalize security practices.
Work with system administrators to support security patching, monitoring and user account best practices
Develop annual calendar or security related activities
Lead adoption of zero-trust architecture across networks, applications, and cloud platforms.
Oversee Identity and Access Management (IAM), encryption standards, and endpoint security.
Direct vulnerability management, penetration testing cycles, and lead team exercises.
Lead IT Incident Response Plan and cybersecurity components of the Business Continuity and Disaster Recovery Plans.
Develop annual security roadmaps benchmarked against NIST CSF, ISO 27001/27701, and SOC 2 standards.
Develop and support change management logging and practices
Establish and contribute to Data and System classification records
Co-Lead Vendor Assessment process
Co-lead IT Incident Response and IT portion of UWW Business Continuity Plan
Risk Management & Governance
Drive enterprise-wide risk assessments and report outcomes to leadership and to the Board.
Develop, maintain and monitor cybersecurity and AI KPIs and dashboards.
Evaluate new data use initiatives and vendor security capacities prior to contracting with new vendors/partners
Partner with MDM/Data Governance Team to determine data use, data flows, to align governance mechanisms with enterprise strategy.
Develop and monitor meaningful metrics
Collaborate with Audit and Compliance teams to support annual internal and external annual audits and contribute to risk assessment activities.
External UWW Network
Monitor and maintain the InfoSec page on UWO including collaboration with Membership when issues occur
Contribute to Membership Standards by providing local United Way basic compliance measures and tools or training to support Membership compliance across the network
Collaborate with UWW Membership, US and International Network teams to elevate security/privacy through Membership standards, thought leadership and guidance
Provide expert guidance to local United Ways experiencing an IT or data related crisis to reinforce and guide based on best practices for incident management and to protect the United Way brand.
Other Duties
Interface with internal constituents and stakeholders to ensure technology products sufficiently support area divisions/departments at meeting their respective goals and objectives.
Work with the Senior Vice President Technology to manage resources, including utilization of team resources, forecasting and budget management.
Work with IT Leads to support broad UWW IT needs, planning and collaboration
Document all aspects of project development and evolution through concise meeting notes, action items, and task management. Eliminate barriers in completion of projects and manage scope, including identifying issues and working with the resources and client on resolution plans.
Must be able to multi-task and enjoy working in a fast-paced environment.
Other duties as assigned.
JOB REQUIREMENTS
Bachelor’s degree required; Master’s in Cybersecurity, Computer Science, or related field strongly preferred.
CISSP, CISM, CIPT or other Security Certification required.
10+ years of expert-level experience in cybersecurity, privacy, AI governance, or cyber law, with 5+ years experience in managing Security Team.
Excellent organization, communication, and motivational skills with an attention to detail.
Demonstrated success in cybersecurity program development and staff training/awareness aligned to NIST CSF, SP 800-53, ISO 27001/27701, and NIST AI RMF.
Demonstrated Knowledge of emerging AI regulations (EU AI Act, US AI Bill of Rights, etc.).
Experience in facilitation bringing end users to appropriate solutions involving an appropriate balance between end user requirements and risk minimization.
A self-starter attitude and strong interpersonal skills with the ability to work independently and collaboratively and ability to interact with people at all levels.
Solid understanding of Privacy regulations, data management practices and IT systems.
Understanding of large-scale System Development Life Cycle (SDLC) in addition to experience with implementation, integration, interfaces, data use mapping and flow design.
Experience in using efficient methodologies/frameworks, such as Agile and NIST or ISO.
ROLE SPECIFIC COMPETENCIES
AI Risk, Governance & Enhanced Cybersecurity
Applies NIST AI RMF and ISO/IEC 42001 to ensure safe and ethical AI Adoption. Anticipates AI-related risks (bias, adversarial attacks, model drift). Leverages AI tools for threat detection and privacy while mitigating risks.
Innovation/ Foresight
Anticipates future risks including AI-driven attacks, deepfakes, and quantum threats.
Evaluates UWW work processes, products and systems. Promotes ways to continuously improve them. Encourages and guides others to consider alternatives to current.
Accountability/Results Orientation
Takes ownership of work and outcomes achieved, selecting the best work approach, while delivering against commitments, models ethical integrity. Is accountable for the achievement of assigned work projects. Collaborates with others to establish work project parameters, desired results/outcomes, and resource requirements. Keeps team leader(s) informed on work progress and changes in work direction. Behaves ethically and honestly in all activities performed on behalf of UWW. Demonstrates a commitment to UWW’s values, including diversity and inclusiveness.
Decision-Making/Risk-Taking
Balances innovation, compliance, and risk minimization. Evaluates available information
and recommends a course of action. Contributes own assessment of risks and
implications of decisions in team decision-making efforts. Uses judgment appropriately
in decision-making. Knows when to shift decision-making upwards.
Teamwork Collaboration
Builds trust across diverse stakeholders and adapts to change. Contributes to the achievement of team objectives by helping others to complete tasks on own initiative. Shares information/ideas with other team members. Carries out assigned work projects. Identifies ways to make a greater contribution to the team. Able to adapt quickly to changing conditions or performance expectations. Able to focus on assignments during periods of change and/or uncertainty.
Relationship Management
Develops partnerships to elevate organizational maturity. Utilizes rapport to build trust and collaboration with others. Identifies and shares mutual benefits/needs in working together. Is ethical in dealing with others to achieve the desired results. Interacts and communicates with diverse stakeholders effectively. Fosters and maintains working relationships across the UW system.
Communications
Distills complex issues into actionable insights for technical and non-technical audiences. Expresses work issues and problems in a clear and concise manner. Communicates effectively with others up, down, and across the organization to achieve expected organization results. Gives and receives constructive feedback. Seeks direct input on team effectiveness and environment.
This job description describes the general nature and level of work performed by employees assigned to this position. It should not be construed as an exhaustive list of all required duties, responsibilities, and skills. Reasonable accommodations may be made to enable disabled individuals to perform the essential functions of the job. You should be able to work on-site in the Alexandria, VA location; relocation assistance is not offered.
SALARY STATEMENT
The budgeted salary range for this position is currently $136,000 to $155,000 per year. Salary is determined by several factors including applicant’s knowledge, skills, experience, position, equity, and market.
ABOUT UNITED WAY WORLDWIDE
United Way Worldwide seeks diverse, qualified professionals who want to make a difference in the world. If you are passionate about your work and desire to help others achieve enhanced education, income, and health, United Way Worldwide is the place for you.
United Way Worldwide is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, creed, disability, veteran status, marital status, age, sex (including pregnancy), sexual orientation, gender identity, gender expression, national origin or ancestry, genetic information, and other legally protected characteristics, in accordance with applicable laws. If you need a reasonable accommodation because of a disability for any part of the employment process, please e-mail recruitment@uww.unitedway.org and provide the nature of your request and your contact information.
We are a charter member of Employers of National Service and encourage AmeriCorps, Peace Corps, and other national service alumni to apply.
United Way Worldwide is located in Old Town Alexandria, VA. We offer competitive salary and excellent benefits including: health, dental, life, short-term and long-term disability, employee assistance program, 403(b) plan, tuition assistance, paid time off, family sick leave, medical appointment leave, parental/adoption leave, dress for your day, free parking, onsite gym, monthly volunteering opportunities, and more.
OUR MISSION
United Way seeks to improve lives by mobilizing the caring power of communities around the world to advance the common good.
United Way brings people together to build strong, equitable communities where everyone can thrive. As one of the world's largest privately funded charities, we serve 95% of U.S. communities and 37 countries and territories -- making life better for 48 million people every year. Through United Way, communities tackle tough challenges and work with private, public, and nonprofit partners to boost education, economic mobility, and health resources.
United Way is the mission of choice for 1.5 million volunteers, 6.8 million donors, and 45,000 corporate partners in more than 1,100 communities worldwide. In our second century of service, we're building resilient, equitable communities across the globe.