Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
California State University Channel Islands seeks an experienced information security leader to serve as ISO/CRO/CPO, overseeing the university's information security program and compliance with CSU, state, and federal requirements. The role leads policy development, risk assessment, incident response, and education across campus.
Ideal candidates will have 8–10 years in IT security and risk management, with at least 4 years in a leadership role, and hold CISSP/CISM/CISA certifications.
Recognized as the University Information Security, Risk, and Policy Officer (ISO/CRO/CPO) and is responsible for all duties assigned in that capacity. Maintains and administers the University Information Security Program and provides leadership in establishing and maintaining University security architecture, controls, policies, standards, processes, and procedures. Provides regular overall assessment of University security posture, operation of existing controls, and progress on improvements using metrics and reporting available to CIO, IT Leadership, and University Leadership. Performs activities required by CSU, federal, state, or other regulations to achieve or maintain University compliance. Provides an annual and scheduled review of University procedural documents related to information security, compliance, and risk management; maintains and administers the University Information Security Awareness Program; maintains and administers procedures and documentation supporting security, risk management and compliance. Collaborates with system-wide Information Security Council (ISC) on matters related to CSU system compliance and risk.
Recognized as the University Information Security, Risk, and Policy Officer (ISO/CRO/CPO) and is responsible for all duties assigned in that capacity. Maintains and administers the University Information Security Program and provides leadership in establishing and maintaining University security architecture, controls, policies, standards, processes, and procedures. Provides regular overall assessment of University security posture, operation of existing controls, and progress on improvements using metrics and reporting available to CIO, IT Leadership, and University Leadership. Performs activities required by CSU, federal, state, or other regulations to achieve or maintain University compliance. Provides an annual and scheduled review of University procedural documents related to information security, compliance, and risk management; maintains and administers the University Information Security Awareness Program; maintains and administers procedures and documentation supporting security, risk management and compliance. Collaborates with system-wide Information Security Council (ISC) on matters related to CSU system compliance and risk.
Recognized as the University Information Security, Risk, and Policy Officer (ISO/CRO/CPO) and is responsible for all duties assigned in that capacity. Maintains and administers the University Information Security Program and provides leadership in establishing and maintaining University security architecture, controls, policies, standards, processes, and procedures. Provides regular overall assessment of University security posture, operation of existing controls, and progress on improvements using metrics and reporting available to CIO, IT Leadership, and University Leadership. Performs activities required by CSU, federal, state, or other regulations to achieve or maintain University compliance. Provides an annual and scheduled review of University procedural documents related to information security, compliance, and risk management; maintains and administers the University Information Security Awareness Program; maintains and administers procedures and documentation supporting security, risk management and compliance. Collaborates with system-wide Information Security Council (ISC) on matters related to CSU system compliance and risk.
Bachelor's degree is required; advanced degree is preferred. Must have eight to ten years of experience in a combination IT Security, IT Risk Management, and General IT positions; with at least 4 years of this experience in a leadership role. Certifications such as CISSP (Certified Information System Security Professional), CISM (ISACA Certified Information Security Manager), or CISA (ISACA Certified Information Security Auditor) are preferred. Experience working in an IT higher education institution preferred.
Proven and extensive experience in planning, organizing, developing, and implementing IT security strategies and related initiatives. Proficiency in IT security management, industry best practices, and standards. Proven ability to identify, prioritize and communicate, the impact ofIT security risks to leadership, stakeholders, and users. Extensive experience in developing and implementing IT security policies, standards, and guidelines. Substantial knowledge and exposure in developing and testing business continuity and disaster recovery plans. Considerable experience in and knowledge ofIT security auditing. Proven ability to measure, monitor, and report on the success ofIT security-related initiatives. Understanding of effective IT security architectures, concepts, techniques, and tools. Understanding and experience managing network and system security components such as firewalls, intrusion detection/prevention systems, vulnerability scanning, etc. In-depth knowledge of applicable IT security-related laws and regulations. Proven ability to work effectively in a coordinating role across multiple constituencies to achieve tactical and strategic goals. Excellent oral and written communication skills. Self-motivated and self-directed/driven. Excellent analytical, evaluative, and problem-solving capabilities. Strong leadership, management, and team-building skills. Positive attitude, proven ability to work successfully with diverse populations, and demonstrated commitment to promoting and enhancing diversity and inclusion.
A background check (including a criminal records check) must be completed satisfactorily before any candidate can be offered a position with the CSU. Failure to satisfactorily complete the background check may affect the application status of applicants or continued employment of current CSU employees who apply for the position.
The person holding this position is considered a 'mandated reporter' under the California Child Abuse and Neglect Reporting Act and is required to comply with the requirements set forth in CSU Executive Order 1083 Revised July 21, 201 7 as a condition of employment.
This position may be "Designated" under California State University's Conflict of Interest Code. This would require the filing of a Statement of Economic Interest on an annual basis and the completion of training within 6 months of assuming office and every 2 years thereafter.
Please note: California State University, Channel Islands (CSUCI) is not currently sponsoring staff or management positions for H-1B employment visas. Applicants must be authorized to work for any employer in the United States.
Education Code 89521 Requirements: Applicants will be required to disclose whether they have received a final administrative decision or final judicial decision determining that they have committed sexual harassment within the last 7 years only after a determination is made that they meet the minimum qualifications for the position, and before an offer of employment is extended. Applicants who reach the final stages of the application process must also sign a release form that authorizes the release of information by the applicant’s current and/or former employers to the CSU concerning any substantiated allegations of misconduct.
Hiring Salary: $8,333 - $12, 500