Chief Information Security Officer

California State University - Channel Islands

Camarillo (CA)

On-site

USD 93,000 - 140,000

Full time

48 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

California State University, Channel Islands Information Technology Services is seeking an Administrator II to lead the information security program and ensure compliance across campus.

You will develop policies, oversee risk assessments, incident response, and collaborate with stakeholders to protect university information assets. This role requires a Bachelor's degree and extensive IT security experience; CSU CI emphasizes leadership and cross-campus coordination.

Qualifications

  • Bachelor’s degree is required; advanced degree preferred.
  • 8–10 years in IT Security, IT Risk Management, and related roles.
  • Experience leading security programs and cross-campus governance.
  • Certifications such as CISSP, CISM, or CISA preferred.

Responsibilities

  • Maintain and administer the University Information Security Program and governance.
  • Lead security architecture, controls, policies, standards, and procedures.
  • Provide metrics and reporting on security posture to CIO and leaders.
  • Develop and enforce information security policies and compliance with regs.
  • Coordinate education and training on information security and privacy.
  • Oversee incident prevention and response and liaison with law enforcement.

Skills

IT Security
Risk Management
Leadership
Policy Compliance

Education

Bachelor's degree required
Advanced degree preferred

Tools

CISSP
CISM
CISA

Job description

Information Technology Services
Administrator II
RESPONSIBILITIES & DUTIES:

Recognized as the University Information Security, Risk, and Policy Officer (ISO/CRO/CPO) and is responsible for all duties assigned in that capacity. Maintains and administers the University Information Security Program and provides leadership in establishing and maintaining University security architecture, controls, policies, standards, processes, and procedures. Provides regular overall assessment of University security posture, operation of existing controls, and progress on improvements using metrics and reporting available to CIO, IT Leadership, and University Leadership. Performs activities required by CSU, federal, state, or other regulations to achieve or maintain University compliance. Provides an annual and scheduled review of University procedural documents related to information security, compliance, and risk management; maintains and administers the University Information Security Awareness Program; maintains and administers procedures and documentation supporting security, risk management and compliance. Collaborates with system-wide Information Security Council (ISC) on matters related to CSU system compliance and risk.

Policy:

Coordinate the development of CSU Channel islands information security policies, standards, and procedures. Work with key ITS offices, data custodians, and governance groups in the development of such policies. Ensure that university policies support compliance with system and external requirements. Oversee the dissemination of policies, standards, and procedures to the university community.

Education and Training:

Coordinate the development and delivery of an education and training program on information security and privacy matters for employees, students, and other authorized users.

Compliance Enforcement:

Serve as the university compliance officer with respect to CSU Channel Islands, state, and federal information security policies and regulations. Work with the campus designated FERPA, Records Access, and HIPAA privacy officers on compliance issues as necessary. Prepare and submit required reports to external agencies.

Risk Assessment and Mitigation:

Develop and implement an ongoing risk assessment program targeting information security and privacy matters. Provide academic and business units with security risk assessments and provides or assist with the development, deployment, and monitoring of protective measures. Work with the CIO, appropriate IT committees, University executives, Deans, and top administrators in administrative departments and divisions to ascertain University security priorities. Work with the CIO to set a budget and advise on funding issues for identified priorities. Direct multiple complex security development projects and manages security systems so that the day-to-day IT functions of the University supporting teaching, learning, scholarship, and administration can work securely.

Incident Prevention and Response:

Oversee the monitoring of security controls and provide metrics and reporting to ensure controls are performing as designed and action is taken to correct deficiencies. Develop, implement, and maintain an Incident Reporting and Response Process to address security incidents, breaches, policy violations, or complaints from external parties. Serve as the official campus contact point for information security, privacy, and copyright infringement incidents, including relationships with law enforcement entities.

Technical:

Monitor and evaluate data from sources of security event information and/or network logs to promptly identify, evaluate, and respond appropriately to information security incidents that impact the information infrastructure at Channel Islands; provide regular assessments of CI's information security operations to provide metrics of efficacy; may be called upon to mobilize and participate in incident handling on short notice during off-shift hours; contribute to the security systems design process; draft formal incident reports; contribute to the preparation of vulnerability reporting metrics, threat intelligence, and other analysis; interfaces with other key stakeholders to facilitate coordinated security operations; assist in security thought leadership activities to promote greater awareness of information security practices; conducts information security user awareness training as needed; other duties as required.

Customer Service:

Work collaboratively with ITS staff to ensure proper enforcement of CSU and CI policies and practices regarding information security; work with end-users to assist with any information security-related issues and/or questions; work collaboratively with CI's Procurement and Risk Management offices to enforce secure procurement practices of IT services and resources including contract review and analysis; provide consultative and training support to ensure user satisfaction and effective and secure use of university systems.

Teamwork:

Participate as a member of the ITS team to ensure the successful operation of the entire work unit in supporting the security of university systems and meeting users’ needs. Possess the ability to effectively communicate technical terms and requirements to functional users. Cooperatively work with ITS teams in support of the implementation of the CSUICSUAM 8000 Series Information Security policies.

Official Contact:

Act as the designee representing Channel Islands on Information Security matters; serve as the campus contact point for external auditors and agencies, survey requests, etc. on security and privacy matters.

Other:

Attends CSU system-wide meetings and represents ITS as required. Performs other duties as required.

REQUIREMENTS OF POSITION:

Bachelor's degree is required; advanced degree is preferred. Must have eight to ten years of experience in a combination IT Security, IT Risk Management, and General IT positions; with at least 4 years of this experience in a leadership role. Certifications such as CISSP (Certified Information System Security Professional), CISM (ISACA Certified Information Security Manager), or CISA (ISACA Certified Information Security Auditor) are preferred. Experience working in an IT higher education institution preferred.

Proven and extensive experience in planning, organizing, developing, and implementing IT security strategies and related initiatives. Proficiency in IT security management, industry best practices, and standards. Proven ability to identify, prioritize and communicate, the impact of IT security risks to leadership, stakeholders, and users. Extensive experience in developing and implementing IT security policies, standards, and guidelines. Substantial knowledge and exposure in developing and testing business continuity and disaster recovery plans. Considerable experience in and knowledge of IT security auditing. Proven ability to measure, monitor, and report on the success of IT security-related initiatives. Understanding of effective IT security architectures, concepts, techniques, and tools. Understanding and experience managing network and system security components such as firewalls, intrusion detection/prevention systems, vulnerability scanning, etc. In-depth knowledge of applicable IT security-related laws and regulations. Proven ability to work effectively in a coordinating role across multiple constituencies to achieve tactical and strategic goals. Excellent oral and written communication skills. Self-motivated and self-directed/driven. Excellent analytical, evaluative, and problem-solving capabilities. Strong leadership, management, and team-building skills. Positive attitude, proven ability to work successfully with diverse populations, and demonstrated commitment to promoting and enhancing diversity and inclusion.

A background check (including a criminal records check) must be completed satisfactorily before any candidate can be offered a position with the CSU. Failure to satisfactorily complete the background check may affect the application status of applicants or continued employment of current CSU employees who apply for the position.

The person holding this position is considered a ‘mandated reporter’ under the California Child Abuse and Neglect Reporting Act and is required to comply with the requirements set forth in CSU Executive Order 1083 Revised July 21, 2017 as a condition of employment.

This position may be "Designated" under California State University’s Conflict of Interest Code. This would require the filing of a Statement of Economic Interest on an annual basis and the completion of training within 6 months of assuming office and every 2 years thereafter.

Please note: California State University, Channel Islands (CSUCI) is not currently sponsoring staff or management positions for H-1B employment visas. Applicants must be authorized to work for any employer in the United States.

Education Code 89521 Requirements: Applicants will be required to disclose whether they have received a final administrative decision or final judicial decision determining that they have committed sexual harassment within the last 7 years only after a determination is made that they meet the minimum qualifications for the position, and before an offer of employment is extended. Applicants who reach the final stages of the application process must also sign a release form that authorizes the release of information by the applicant’s current and/or former employers to the CSU concerning any substantiated allegations of misconduct.

Hiring Salary:

$8,333 - $12,500

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Chief Information Security Officer
Chief Information Security Officer

Socket.dev • Allen (TX)

On-site
USD 93,000 - 140,000
Chief Information Security Officer
Chief Information Security Officer

California State University Channel Islands • Oxnard (CA)

On-site
USD 8,300 - 13,000
Chief Information Security Officer
Chief Information Security Officer

Opt For Healthy Living • California (MO)

Hybrid
USD 90,000 - 115,000
Chief Information Security Officer
Chief Information Security Officer

Monash University • Camarillo (CA)

On-site
USD 120,000 - 160,000
None
Chief Information Security Officer
Chief Information Security Officer

The California State University • California (MO)

Hybrid
USD 120,000 - 180,000
Chief Information Security Officer
Chief Information Security Officer

Universityculture • Camarillo (CA), Northern (KY)

Hybrid
USD 93,000 - 140,000
Director, Facilities Operations
Director, Facilities Operations

Universityculture • Camarillo (CA)

Hybrid
USD 126,000 - 140,000
Director, Facilities Operations
Director, Facilities Operations

California State University Channel Islands • Oxnard (CA)

On-site
USD 126,000 - 140,000
Executive Assistant to the VPBFA & Coordinator for Strategic Initiatives
Executive Assistant to the VPBFA & Coordinator for Strategic Initiatives

Socket.dev • Allen (TX)

On-site
USD 79,000 - 86,000
Academic Program Analyst
Academic Program Analyst

Socket.dev • Allen (TX)

On-site
USD 49,000 - 58,000