CampusGuard, a Nelnet Company, provides information security services for campus-based organizations including higher education institutions, healthcare providers, city, county and state government agencies and hospitality markets. As a full-service information security firm, we leverage our knowledge combined with the industry standards for compliance and information security issues to provide our customers with world class information security & compliance services.
CampusGuard is a cybersecurity and compliance firm that has partnered with hundreds of colleges and universities since 2009 to build, mature, and sustain compliance programs — PCI DSS, GLBA, HIPAA, CMMC, FERPA, Nacha/ACH, and more — across higher education, healthcare, government, financial services, and SaaS/technology organizations. What sets us apart isn't just technical depth; it's that we understand the culture, governance, and decentralization of the environments we serve. You'll work alongside a credentialed team — QSAs, PMPs, PCIPs, and security engineers — with deep roots in higher education and senior security leadership supporting every engagement.
Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.
Key Responsibilities
Program Development & Consulting
- Assess a customer's current compliance posture and design a scalable, right-sized program that fits their size, structure, budget, and risk tolerance.
- Author the program's foundational artifacts — charter, governance structure, policies, roles and responsibilities, escalation paths, and compliance calendar — and establish merchant/departmental inventories, scope definitions, and data flow documentation.
- Define the metrics and reporting cadence by which the customer's leadership will judge the program's health, and advise on organizational placement — who owns compliance and what committee it reports through.
Program Management (Managed Services)
- Lead the planning, execution, and delivery of customer PCI DSS, GLBA, and related compliance initiatives, applying a hybrid (predictive and adaptive) methodology that adapts to shifting scope, personnel turnover, and evolving standards.
- Develop and maintain schedules, work breakdown structures, RACI matrices, and risk/issue logs, coordinating stakeholders — IT, security, treasury/bursar, athletics, advancement, financial aid, and vendors — across a decentralized institution.
- Own the annual compliance lifecycle (scoping, evidence collection, SAQ/AOC, ASV scans, remediation tracking) and serve as the customer's primary point of contact, maintaining artifacts in CampusGuard Central®.
Capability Transfer & Enablement
- Train and coach customer staff — compliance coordinators, departmental merchant contacts, IT and security personnel — to operate the program independently.
- Develop customer-facing playbooks, runbooks, checklists, and templates that outlive the engagement.
- Structure engagements with a deliberate handoff in mind, defining what “self-sufficient” means for each customer and managing toward it.
vISO Engagement Support (Virtual Information Security Officer)
- Support senior CampusGuard advisors delivering fractional Information Security Officer services, drafting and maintaining security policies and procedures against applicable frameworks (PCI DSS, GLBA, NIST CSF/SP 800-171, HIPAA).
- Assemble and facilitate risk assessments, translating technical findings into business-language, budget-aware remediation roadmaps, and prepare materials for governance, leadership, and audit committees.
- Contribute to third-party/vendor risk reviews, incident response plan maintenance, and tabletop exercise facilitation.
Internal Contribution
- Partner with CampusGuard's QSAs, assessors, and security engineers to ensure customer deliverables are accurate, timely, and consistent with our standards.
- Contribute to service delivery methodology, templates, and continuous improvement of the Managed Services practice.
- Support scoping and renewal conversations with Customer Relationship Managers, and maintain utilization across a portfolio of approximately [X] concurrent customers.
Required Qualifications
- Bachelor's degree in information systems, business, or a related field — or an equivalent combination of education and experience.
- 5+ years of progressive experience in program/project management, IT compliance, information security, or IT governance.
- Demonstrated end-to-end ownership of a compliance or information security program, including stakeholder management up to the executive level.
- Working knowledge of at least one major compliance framework (e.g., PCI DSS, GLBA), with the ability to build depth in others.
- Proven ability to drive accountability without direct authority, teach technical concepts to non-technical audiences, and communicate fluidly across working sessions and leadership briefings.
- Highly organized and self-directed, able to manage multiple concurrent customer engagements from inception through post-implementation, including plans, schedules, and budgets.
- Proficiency with common project management and productivity tools (e.g., Microsoft Project, Excel, the Microsoft 365 suite).
- Must obtain the PCIP (PCI Professional) credential within 12 months of hire.
- PMP (Project Management Professional) certification preferred; if not already held, must be obtained within 12 months of hire.
- Must pass a background check.
- Must be authorized to work in the United States without sponsorship.
Preferred Qualifications
- Direct higher education experience — having run a compliance or information security program at a college or university.
- Experience building a compliance or security program from the ground up, rather than only operating one someone else designed.
- Additional certifications such as PMI-ACP, CSM, CISM, CISA, CISSP, CRISC, or similar.
- Prior consulting or professional services experience managing a portfolio of customers.
- Familiarity with the higher education technology landscape and/or GRC platforms (e.g., Banner, Workday, Ellucian, Archer, ServiceNow).
- Experience with additional compliance frameworks (e.g., PCI DSS, GLBA, HIPAA, etc.).
Compensation range for this role is $70,000-$100,000 annually, depending on experience.
#LI-CW1
#LI-Remote
Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc
Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.
Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 or corporaterecruiting@nelnet.net.
Nelnet is a Drug Free and Tobacco Free Workplace.
Use of Artificial Intelligence in Hiring
We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring