Skip to main content

Example Job Description

Director of Cybersecurity

A security leader who turns district risk priorities into disciplined protection, detection, response, recovery, and continuous improvement.

Classified Management
Download this job descriptionEditable Microsoft Word format based on the SDLA Professional template.
Download DOCX

Interview Planning Resource

Possible Interview Q&A: Director of Cybersecurity

How to use this resource: Select questions that measure competencies established through the district’s current job analysis. Ask candidates the same predetermined questions under comparable conditions and evaluate responses against the same job-related criteria.

The indicators below describe evidence a strong response may contain; they are not required scripts or the only acceptable answers.

  1. How would you establish priorities and a practical annual work plan for identity, network, endpoint, cloud, application, data-protection, monitoring, incident-response, and recovery systems?

    Strong response indicators: Connects district goals and user needs to risk, dependencies, capacity, owners, milestones, service measures, communication, and review rather than producing an unranked project list.

  2. Describe a time you found that a familiar process or report was producing unreliable results. How did you investigate and correct it?

    Strong response indicators: Defines the expected result, traces evidence to authoritative sources, distinguishes symptoms from root causes, involves accountable owners, tests the correction, reconciles downstream effects, documents decisions, and monitors recurrence.

  3. You encounter credible evidence of active compromise affecting student, employee, or operational services. What would you do first, and how would you manage the issue through resolution?

    Strong response indicators: Protects people and continuity, establishes scope and authority, preserves evidence, engages the right owners, communicates proportionately, documents decisions, verifies recovery or correction, and completes a lessons-learned review.

  4. How would you work with executive leaders, technology teams, privacy and legal staff, school administrators, communications, law enforcement, insurers, vendors, and service owners when they disagree about priorities or the acceptable level of risk?

    Strong response indicators: Clarifies decision rights and shared purpose, surfaces evidence and constraints, distinguishes requirements from preferences, documents options and residual risk, facilitates a timely decision, and escalates through established authority when needed.

  5. What controls would you put in place before making a significant change to identity, network, endpoint, cloud, application, data-protection, monitoring, incident-response, and recovery systems?

    Strong response indicators: Includes requirements, ownership, risk and privacy review, representative testing, accessibility where relevant, approvals, change communication, rollback or contingency, validation, monitoring, documentation, and support readiness.

  6. How would you decide what to automate and what should retain meaningful human review?

    Strong response indicators: Selects stable, repeatable, testable work for automation; preserves human authority for exceptions and consequential judgments; addresses access, logging, bias or error, monitoring, failure recovery, documentation, and periodic reassessment.

  7. How would you explain a serious technical, instructional, operational, or data concern to a leader who does not work in your specialty?

    Strong response indicators: States the affected people and services, evidence, uncertainty, consequence, deadline, accountable owners, options, recommendation, residual risk, and next update in plain language.

  8. What would you do when a request exceeds executive risk acceptance, legal and privacy determinations, law-enforcement authority, business ownership, and emergency decision rights?

    Strong response indicators: Recognizes the limit, avoids unauthorized action, clarifies the legitimate need, preserves service where possible, routes the decision to the authorized owner, documents the handoff, and follows through without abandoning the requester.

  9. How would you protect confidential information while still providing useful service and appropriate access?

    Strong response indicators: Applies purpose limitation, minimum necessary access, role-based permissions, secure transmission and storage, approved retention, understandable communication, auditability, timely removal, and incident escalation.

  10. How would you build staff capability so your office does not become the permanent fixer of every problem?

    Strong response indicators: Uses clear ownership, role-based training, usable procedures, coaching, feedback loops, office hours, communities of practice, quality reports, cross-training, and measures whether source practices improve.

  11. What evidence would you use to determine whether your work is improving risk reduction, control coverage, detection and response time, recovery, recurrence, vulnerability age, training outcomes, and service resilience?

    Strong response indicators: Uses a balanced set of outcome, implementation, service, risk, equity, and user-experience measures; disaggregates appropriately; explains limitations; establishes baselines and review cadence; and changes course when evidence warrants.

  12. What would you prioritize during your first 90 days?

    Strong response indicators: Would validate incident readiness and privileged access, review critical risks and open findings, assess monitoring and recovery evidence, meet service owners, and publish a prioritized security operations roadmap; listens before redesigning, identifies urgent risks, delivers credible early improvements, and creates an achievable longer-term roadmap with owners and measures.

Position Description

Under the direction of the appropriate district administrator, the Director of Cybersecurity directs cybersecurity operations, engineering, risk management, incident response, security awareness, and resilience across district technology and data services.

The position connects policy, people, process, information, and technology; establishes repeatable practices; makes unresolved risk visible; and supports continuous improvement without displacing the authority of designated program, legal, privacy, security, fiscal, instructional, or executive decision-makers.

Reports To

Illustrative reporting relationship: Chief Information Security Officer, Chief Information Officer, Chief Technology Officer, or other designated executive. Insert the school district’s approved reporting relationship here.

Required Education and Credentials

Required

  • Bachelor's degree in cybersecurity, information systems, computer science, engineering, or a related field.
  • No specific credential is universally required; relevant professional certifications are preferred.
  • Successful completion of all district-required employment clearances and assigned privacy, security, accessibility, records, and safety training.

Preferred

  • Graduate study, advanced coursework, or current professional learning directly related to the position’s assigned scope.
  • Relevant training in project management, facilitation, change management, data-informed improvement, and public-sector service.

Required / Desired Experience

Required Experience

  • Progressively responsible experience leading security operations, architecture, incident response, vulnerability management, identity, or technology risk programs.
  • Experience coordinating deadline-driven work with multiple departments, users, or school sites.
  • Experience handling confidential information and documenting decisions, exceptions, and completed work.

Desired Experience

  • Experience in K-12 or public-sector security, cloud and endpoint protection, zero trust, digital forensics, business continuity, vendor risk, and team leadership.
  • Experience developing procedures, training users, improving processes, and supporting continuity during staff or system changes.

Essential Duties and Responsibilities

Security Operations and Engineering

  • Direct monitoring, detection, triage, threat hunting, vulnerability management, configuration assurance, security engineering, and operational escalation.
  • Establish standards and roadmaps for identity, endpoint, network, cloud, application, email, data, logging, encryption, and backup protections.
  • Coordinate remediation with service owners and track exceptions, compensating controls, due dates, and residual risk.

Incident Response and Resilience

  • Maintain and exercise incident-response, communications, continuity, disaster-recovery, and cyber-recovery plans.
  • Lead or support incident command; preserve evidence, establish scope, coordinate containment and recovery, and maintain decision logs.
  • Conduct after-action reviews and ensure lessons become tested technical, procedural, training, and governance improvements.

Risk, Assurance, and Third Parties

  • Perform risk assessments, control reviews, penetration-test coordination, audit support, and remediation tracking for critical services.
  • Integrate security requirements into architecture, procurement, contracts, projects, vendor oversight, and system lifecycle decisions.
  • Report material risks, incidents, metrics, unresolved exceptions, and investment needs to designated leaders.

People, Policy, and Program Leadership

  • Supervise assigned employees and vendors; manage budgets, contracts, schedules, professional development, and succession readiness.
  • Maintain security policies, standards, runbooks, inventories, diagrams, evidence, and role-based awareness programs.
  • Coordinate with privacy, legal, records, safety, communications, and program owners; perform other related duties consistent with classification.

Required Skills and Abilities

Knowledge of

  • NIST Cybersecurity Framework functions and profiles, security governance, risk assessment, control design, threat modeling, and defense in depth
  • Identity and access management, networks, endpoints, cloud, applications, email, logging, vulnerability management, encryption, backups, and recovery
  • Incident command, forensics, evidence preservation, notification coordination, continuity, disaster recovery, and after-action improvement
  • Student and employee data contexts, privacy, records, procurement, vendor risk, awareness, policy, and public-sector constraints

Ability to

  • Lead calm, evidence-driven response under uncertainty while protecting people, services, and investigative integrity
  • Translate risk into prioritized controls, owners, funding needs, residual risk, and executive decisions
  • Design measurable operational processes for detection, triage, containment, eradication, recovery, and follow-up
  • Build productive partnerships without obscuring security accountability
  • Develop security engineers, analysts, administrators, and incident leaders
  • Communicate technical findings and urgent actions clearly to varied audiences

Work Environment

  • Work is performed primarily in district offices, schools, meeting rooms, training environments, and other computer-based professional settings, with remote participation as authorized.
  • The position requires extended computer use and detailed review of records, systems, reports, procedures, communications, or technical documentation.
  • Work involves frequent coordination with executive leaders, technology teams, privacy and legal staff, school administrators, communications, law enforcement, insurers, vendors, and service owners.
  • The employee may encounter competing priorities, interruptions, confidential matters, fixed deadlines, and time-sensitive problems requiring calm, documented judgment.
  • Workload may increase during school opening and closing, reporting cycles, audits, major changes, incidents, and other critical district operations.

Other Requirements

  • Successfully complete required criminal-record, fingerprint, and employment clearances.
  • Complete a tuberculosis risk assessment and any examination required by applicable law or district policy.
  • Complete district-required cybersecurity, privacy, accessibility, nondiscrimination, workplace-safety, and records-management training.
  • Maintain professional confidentiality and comply with district policies governing records, information security, acceptable technology use, conflicts of interest, and data access.
  • Travel between district offices, schools, meetings, training locations, and professional-development activities as assigned.
  • Possess a valid California driver’s license and maintain insurability when driving is an essential function of the position.
  • Occasionally work evening, weekend, or extended hours during critical operations, incidents, deadlines, public meetings, or system transitions.
  • Regularly sit, stand, walk, speak, hear, read, and operate computers and standard office equipment; occasionally lift, carry, or move records, equipment, or supplies weighing up to 25 pounds.
  • Perform the essential functions of the position with or without reasonable accommodation.