EdTech Jobs

Role Snapshot

The Technical Security Manager ensures and maintains compliance with security standards and frameworks for Cambium Learning Group's educational technology products. This role leverages a mature security program while coordinating across teams to implement security improvements and support business development.

Key Responsibilities: Maintain conformance with ISO 27001, ISO 27018, ISO 42001, FedRAMP, SOC, and NIST standards; coordinate annual third-party security audits and remediate findings. Manage security improvement projects, oversee security awareness training programs, and respond to customer security/privacy inquiries for business proposals.
Skills & Tools: Strong knowledge of security frameworks (ISO 27001, FedRAMP, NIST 800, SOC 2) and compliance standards; excellent project management, stakeholder coordination, and communication abilities. Ability to balance security technical requirements with business needs and manage complex audit and documentation processes.
Qualifications: 5+ years of information security or compliance management experience, preferably with SaaS or EdTech companies. Bachelor's degree in cybersecurity, information security, or related field; relevant certifications (CISSP, CISM, ISO 27001 Lead Auditor) preferred.
Location: Remote
Compensation: Not provided by employer. Typical compensation for this role is $115,000 – $155,000/year based on title, seniority, and location.

Job Description

Cambium Learning® Group is an award-winning educational technology solutions leader dedicated to helping all students reach their potential through individualized and differentiated instruction. Using a research-based, personalized approach, Cambium Learning Group delivers SaaS resources and instructional products that engage students and support teachers in fun, positive, safe and scalable environments. These solutions are provided through Learning A-Z® (online differentiated instruction for elementary school reading, writing and science), ExploreLearning® (online interactive math and science simulations, a math fact fluency solution, and a K–2 science solution), Voyager Sopris Learning® (blended solutions that accelerate struggling learners to achieve in literacy and math and professional development for teachers), and VKidz Learning (online comprehensive homeschool education and programs for literacy and science). We believe that every student has unlimited potential, that teachers matter, and that data, instruction, and practice are the keys to success in the classroom and beyond.

Job Overview: The Security Manager will primarily support CAI’s Information Security program by ensuring and maintaining compliance with our current and anticipated commitments to external stakeholders and security frameworks. As our Security Manager, you will have the opportunity to leverage and build upon a mature program that is independently audited against various security standards, benchmarks, and industry best practices. The position is ideal for a well-rounded security professional that can effectively coordinate with established teams responsible for security monitoring, cloud infrastructure, enterprise support, software development, educational testing business processes, and project/customer management.

Job Responsibilities: Maintain, mature, and take ownership of our program that ensures conformance to security standards. This includes but is not limited to conformance with ISO 27001, ISO 27018, ISO 42001, Privacy laws, ISO 9001, GovRAMP, FedRAMP, NIST 800, SOC, and CIS Top Controls. Facilitate annual independent audits of our organization by third-party security and privacy experts. Create audit plan, co-ordinate with stakeholders, review reports and remediate audit findings. Responsible for planning and managing multiple security improvement projects from requirements phase through deployment/implementation. Managing document and record control processes and procedures, including maintaining accurate inventories and records of compliance/conformance artifacts Responsible for our Security Awareness and related training programs. Maintains and improves processes, platforms and systems that support our training campaigns and content. Creates, monitors and reports on campaigns. Supports business development by responding to requests for security and privacy information that is included in proposals for new business. Performs security risk assessments of software acquisitions, technical services, business systems and new technologies. Owns and administers a GRC tool to track security controls and current conformance status. Ensures that relevant security artifacts are recorded and updated. Conducts enterprise risk assessment reviews and report out to senior management regarding security issues and metrics – both as an ongoing process and on an as-needed basis. Assists in continual improvement by examining our current security posture and security practices, identifying risks or gaps, and recommending programs to address them. Manages privacy risks including exposures created by cookies and APIs. Maintains Privacy policies and ensures compliance.

Job Requirements: Bachelor’s Degree in Information Security, Cybersecurity, computer science, engineering, Information Systems or related technical field Minimum 5 years hands-on experience in the information security field Extensive and deep knowledge of security and privacy frameworks, standards, and industry best practices. Knowledge of Privacy laws and principles such as GDPR, COPPA, and FERPA Extensive and deep knowledge of tools and techniques used to protect against cybersecurity attacks and respond to incidents. Information Security Certifications such as CISSP, GIAC, ISACA, AWS Security. PMP certification a plus. Experience with GRC tools Exceptional verbal and written communication skills to effectively and accurately communicate with a variety of teams ranging from highly detailed discussions with technical and subject matter experts to executive-level communications required for senior leaders and decisionmakers.

Demonstrated working experience with: Security and privacy standards such as ISO, GovRAMP, FedRAMP and/or other industry best practice frameworks. Writing, developing, and maintaining official security and privacy-relevant records and documentation Reducing organizational risk by conducting risk assessments, gap analysis, improvement plans and tracking associated corrective actions or POAMs to closure Developing and executing project management plans for technical projects. Effectively communicating and coordinating with senior business leaders, subject matter experts, technical leaders and third party consultants. Experience of AI Governance highly desirable. Including frameworks such as NIST, ISO42001. To apply for this opportunity, simply click on the “Apply” button and submit a cover letter and resume. An Equal Opportunity Employer We are dedicated to fostering a culture that celebrates unique backgrounds, ideas, and experiences. All qualified applicants will receive consideration for employment without discrimination on the basis of race, color, religion, sex, gender, gender identity/expression, sexual orientation, national origin, protected veteran status, or disability. Cambium Learning® Group is the education essentials company. With an intentionally curated portfolio of respected global brands, Cambium serves as a leader in the education space, helping millions of educators and students feel more universally valued each and every day. In everything we do and across all our brands, we focus on the elements that are most essential to the success of education

Our family of companies includes: Cambium Assessment Lexia® Learning Learning A-Z® Voyager Sopris Learning® ExploreLearning® Time4Learning® Kurzweil Education® To learn more about the Cambium organization and our other career opportunities, visit www.cambiumlearning.com/about-us/careers As a group, we value: Simplicity - Across all our teams and all areas of our business, we create simplicity, making things easier and more clear for all those we work with. Certainty - We continually strive to eliminate doubt, delivering solutions, services and communications that our customers know they can count on. Now - We understand the need to make a difference not only for the future, but for today, and our people are committed to making the most of each moment we spend serving our customers.

View Full Job Posting on Cambium Assessment