Join CalNonprofits Insurance Services, a leading provider of insurance solutions to the nonprofit sector. As a remote, in-office - Capitola, CA, or hybrid team, our commitment to servicing nonprofits extends beyond our physical locations in California. We are seeking an experienced, collaborative, and forward-thinking Cybersecurity, IT & AI Governance Manager to join our team.
Our core values are Excellence, Collaboration, Trust, Diversity/Inclusion, and Respect. When you join us, you’ll have the opportunity to continue learning, develop new skills, and grow personally and professionally. We celebrate achievement and reward our employees for their great ideas, attitude, and teamwork.
Position Overview
$85,000.00-$100,000.00 Salary
Responsible for leading and coordinating the organization’s cybersecurity, technology operations, compliance, and AI governance initiatives. This position serves as a key internal resource and strategic partner for technology-related risk, security, governance, and operational needs while managing relationships with third-party technology vendors and the organization’s Managed Service Provider (MSP).
The Cybersecurity, IT & AI Governance Manager works cross-functionally with leadership, employees, vendors, and technology partners to strengthen cybersecurity practices, maintain effective technology controls, support responsible adoption of emerging technologies, and ensure technology initiatives align with organizational priorities.
Principal Duties and Responsibilities
- Lead the development, implementation, monitoring, and maintenance of cybersecurity, technology governance, compliance, and related policies and procedures.
- Develop and maintain governance frameworks, operational controls, documentation, and standards related to cybersecurity, technology, privacy, and artificial intelligence.
- Support organizational compliance with applicable security standards, regulatory requirements, and industry best practices.
- Monitor evolving cybersecurity risks, privacy requirements, technology trends, and regulatory developments and recommend appropriate organizational responses.
- Conduct and coordinate security audits, assessments, risk reviews, and gap analyses to evaluate the organization’s security posture and compliance status.
- Develop and coordinate remediation plans for identified security, technology, or compliance gaps.
- Work with internal departments and external vendors to ensure security and technology controls are appropriately integrated into business operations.
- Lead and coordinate cybersecurity awareness initiatives and employee training related to security, privacy, responsible technology use, and emerging risks.
- Promote a culture of cybersecurity awareness and responsible technology use throughout the organization.
- Coordinate vulnerability identification, risk mitigation, and other cybersecurity activities with the organization’s MSP and outside technology partners.
- Participate in cybersecurity incident response activities and support the development, testing, and maintenance of disaster recovery and business continuity plans.
- Serve as the primary organizational contact for the third-party Managed Service Provider and other key technology vendors.
- Manage relationships with external vendors, consultants, and technology service providers, including oversight of service quality, deliverables, projects, and organizational needs.
- Oversee user access, authentication, permissions, and related security controls across company applications and technology systems.
- Coordinate technology-related employee onboarding and offboarding processes.
- Oversee the coordination and resolution of technical issues, service requests, technology maintenance, equipment procurement, and system needs.
- Lead and coordinate technology projects, system implementations, security initiatives, and organizational technology improvements.
- Partner with departments and leadership to identify opportunities to improve business processes through technology, automation, and digital tools.
- Lead the development and ongoing management of the organization’s AI governance framework, including policies, standards, risk considerations, and appropriate-use guidelines.
- Support the responsible evaluation, adoption, and implementation of artificial intelligence tools and emerging technologies.
- Partner with stakeholders to evaluate AI use cases, risks, privacy considerations, security requirements, and business value.
- Support organizational adoption and effective use of Microsoft 365, Microsoft Copilot, Power Platform, cloud technologies, and other approved business technology tools.
- Develop recommendations related to cybersecurity, technology risk, AI governance, and technology investments and communicate findings to executive leadership.
- Maintain accurate documentation related to technology systems, security controls, vendor relationships, governance programs, policies, and organizational processes.
- Lead cross-functional projects and initiatives involving cybersecurity, technology, compliance, AI, and organizational change.
- Translate complex technical, security, and risk concepts into practical recommendations for non-technical stakeholders and organizational leadership.
- Plan, prioritize, and manage multiple projects and responsibilities while maintaining accuracy, confidentiality, and attention to detail.
Requirements
The ideal candidate will have
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, Business Information Systems, or a related field.
- Minimum of 5years of progressive experience in cybersecurity, technology management, IT operations, compliance, technology governance, or related roles.
- Experience managing external vendors, consultants, Managed Service Providers, and other technology service providers.
- Experience developing and implementing policies, procedures, governance frameworks, operational controls, or organizational technology standards.
- Demonstrated ability to lead cross-functional projects and organizational initiatives.
- Strong understanding of cybersecurity principles, risk management, privacy, information security, and technology governance.
- Working knowledge of cybersecurity frameworks and standards such as NIST Cybersecurity Framework, CIS Controls, SOC 2, HIPAA, or similar standards.
- Familiarity with security controls, cybersecurity tools, network infrastructure, cloud technologies, authentication systems, and common business technology environments.
- Knowledge of cybersecurity threats, vulnerabilities, incident response practices, and risk mitigation strategies.
- Strong analytical, critical-thinking, problem-solving, and project management skills.
- Excellent written and verbal communication skills, including the ability to translate technical concepts for non-technical audiences.
- Experience developing recommendations and communicating technology, cybersecurity, or risk-related information to executive leadership.
- Strong organizational skills, attention to detail, and ability to effectively manage multiple priorities and initiatives.
- Demonstrated ability to collaborate effectively with employees, leadership, vendors, and stakeholders across multiple functional areas.
Preferred
- Experience in insurance, financial services, professional services, nonprofit organizations, or other regulated industries.
- Experience with cybersecurity frameworks such as NIST CSF, CIS Controls, SOC 2, HIPAA, or similar standards.
- Experience leading AI governance, AI adoption, automation, or digital transformation initiatives.
- Knowledge of Microsoft 365, Microsoft Copilot, Power Platform, cloud technologies, and related Microsoft security tools.
- Experience evaluating emerging technologies and developing organizational standards for responsible technology use.
- Professional certifications such as CISSP, CISM, CRISC, Security+, CGRC, Microsoft Security, AI Governance, or related certifications.