Chief Information Security Officer

The Rector & Visitors of the University of Virginia

Charlottesville (VA)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

The Rector & Visitors of the University of Virginia is seeking a Chief Information Security Officer (CISO) in Charlottesville, VA. This pivotal role will establish a university-wide information security management program and lead high-performing teams across the institution.

The ideal candidate will have 10+ years of experience in risk management and information security, with proven leadership skills and the ability to communicate complex concepts effectively. A hybrid work model is available.

Join us in making a difference at this leading public institution.

Qualifications

  • At least 10 years of experience in risk management and information security, with five years in senior leadership.
  • Familiarity with AI and machine learning tools is preferred.
  • Strong written and verbal communication skills are required.

Responsibilities

  • Establish and maintain a university-wide information security management program.
  • Lead high-performing teams and collaborate across the institution.
  • Identify, evaluate, and report on security risks.

Skills

Leadership
Risk Management
Information Security Frameworks
Communication
Problem Solving

Education

Bachelor's degree in Information Technology, Computer Science, or related field
Professional security management certification (CISSP, CISM, CISA)

Job description

The University of Virginia (UVA), one of the nation's leading public institutions, seeks an experienced, dynamic, and mission-driven leader to be the next Chief Information Security Officer (CISO). Reporting to the Vice President and Chief Information Officer (CIO), the CISO will provide strategic leadership and oversight to a diverse portfolio and lead high-performing teams, collaborating across a large, complex institution.

The CISO must enjoy engaging with the university community, drawing on strong communication skills, a natural ability to build relationships, and comfort explaining complex technical concepts to faculty and staff at all levels. The complexity of this position requires strong leadership, collaboration, and partnership skills, and the ability to balance the urgency surrounding the risk of emerging threats with university strategies and business needs.

Position Summary

As a critical member of the Information Technology Services (ITS) leadership team, this pivotal role is responsible for establishing and maintaining a university-wide information security management program to ensure that the university’s data and assets are adequately protected. The CISO must stay current with the evolving threat landscape (particularly involving AI-based threats), ensure staff are upskilling to keep pace, and challenge the status quo to ensure the University maximizes its investment in information security resources. The candidate will work closely with IT leadership, administrative leaders, and academic faculties across Grounds to identify, evaluate, and report on information security risks in a manner that meets compliance and regulatory requirements and aligns with and supports the risk posture of the University.

Key Responsibilities
  • Information Security Program Leadership
  • Team Leadership
  • Policy, Compliance and Audit
  • Community and Partner Engagement
  • Risk Management, Security Operations, Projects, and Incident Response
Attributes, Competencies, and Qualifications

The successful candidate will bring a distinctive blend of leadership, strategic perspective, and technical expertise to advance the institution's information security strategy, strengthen organizational resilience, and build trusted partnerships across the university.

Desired Attributes
  • Curious – asks thoughtful questions, listens actively, and seeks understanding before taking action.
  • Entrepreneurial – embraces new ideas, explores innovative solutions, and remains open to different approaches.
  • Resourceful – identifies practical solutions, navigates constraints effectively, and remains focused despite obstacles.
  • Collaborative – builds strong relationships, values consultation, and engages stakeholders in developing solutions.
  • Adaptable – questions existing processes constructively and adjusts effectively as priorities and circumstances evolve.
  • User‑Centered – considers the impact of security practices and technologies on users’ ability to work effectively and achieve their goals.
  • Growth‑Oriented – fosters a culture of continuous learning, encourages skill development, and helps teams embrace new approaches as needs change.
Qualifications
  • A bachelor's degree in Information Technology, Computer Science, Information Systems, or a related field (advanced degree preferred).
  • Professional security management certification is strongly desired, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or other similar credentials.
  • At least 10 years of experience in a combination of risk management, information security, and IT jobs (at least five must be in a senior leadership role).
  • Knowledge of common information security management frameworks, such as ISO/IEC 27001 and NIST 800‑53, 800‑174, and Cybersecurity Framework (CSF).
  • Familiarity with AI and machine learning‑based tools used across the information security lifecycle.
  • Experience with contract and vendor negotiations and management, including managed services.
  • Experience with Cloud Computing/IaaS/PaaS/SaaS technologies and services.
  • Strong understanding of the higher education sector’s policy, regulatory, and legislative environment is preferred.
  • Excellent written and verbal communication skills, interpersonal, relationship‑building, and collaborative skills, and the ability to communicate security and risk‑related concepts to technical and nontechnical audiences at all levels.

The CISO role is based in Charlottesville, VA, with an expectation of strong in‑person presence to effectively engage with leadership and stakeholders. A hybrid work model is available, with flexibility to work remotely when appropriate and consistent with the needs of the organization.

The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Learn more about UVA’s commitment to non‑discrimination and equal opportunity employment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

University CISO — Strategic InfoSec Leader (Hybrid)
University CISO — Strategic InfoSec Leader (Hybrid)

University of Virginia • Charlottesville (VA)

Hybrid
USD 130,000 - 180,000
Strategic CISO | University-wide Security Leader (Hybrid)
Strategic CISO | University-wide Security Leader (Hybrid)

The Rector & Visitors of the University of Virginia • Charlottesville (VA)

Hybrid
USD 120,000 - 160,000
Deputy Chief Information Security Officer – Virginia Tech
Deputy Chief Information Security Officer – Virginia Tech

V T CORPORATE RESOURCE CTR • Blacksburg (VA)

On-site
USD 120,000 - 160,000
Deputy Chief Information Security Officer
Deputy Chief Information Security Officer

your Jared • Northern (KY)

Hybrid
USD 180,000 - 250,000
Remote work options
Travel to campuses
Deputy Chief Information Security Officer
Deputy Chief Information Security Officer

Touro University • New York (NY)

Hybrid
USD 120,000 - 150,000
Senior Director of Secure Identity Services – Virginia Tech
Senior Director of Secure Identity Services – Virginia Tech

V T CORPORATE RESOURCE CTR • Blacksburg (VA)

On-site
USD 120,000 - 150,000
Assistant Vice President, Information Security
Assistant Vice President, Information Security

The Chronicle Of Higher Education, Inc. • Tampa (FL)

On-site
USD 180,000 - 270,000
Senior IT Security and Compliance Manager
Senior IT Security and Compliance Manager

Virginia Tech • Blacksburg (VA)

On-site
USD 90,000 - 110,000
Information Security Assessment and Analysis Team Lead
Information Security Assessment and Analysis Team Lead

University of Connecticut • Storrs (CT)

On-site
USD 95,000 - 124,000
Healthcare options
Tuition waiver
35 hour work week
+2
vCISO - Solutions Provider
vCISO - Solutions Provider

Hamilton Barnes Associates Limited • Illinois

On-site
USD 121,500 - 148,500