Deputy Chief Information Security Officer - #270015

Western Carolina University

Cullowhee (NC)

On-site

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Tuition waivers for up to three C/yr
Free group exercise classes
Discounted campus recreation center
Free vaccines and boosters on campus
Pretax flexible spending accounts

Job summary

Western Carolina University is seeking a Deputy Chief Information Security Officer to lead risk governance, regulatory compliance, and security operations. The role reports to the Chief Information Security & Privacy Officer and guides security policy, third‑party risk reviews, and incident response strategies.

The position drives risk awareness, coordinates audits, and ensures alignment with NIST CSF and CIS Controls across the university's IT landscape.

Qualifications

  • Bachelor’s degree in cybersecurity, computer science, information systems, business analytics, or a related field.
  • Five years of progressively responsible experience across multiple information security functions, such as governance, risk, compliance, security operations, incident response, identity and access management, infrastructure security, or third-party risk.
  • Demonstrated experience coordinating complex security initiatives across technical teams and business units.
  • Working knowledge of networking, systems administration, endpoint security, identity and access control, cloud or hosted services, vulnerability management, and incident response practices.
  • Experience developing or implementing security policies, risk assessments, control documentation, audit responses, or remediation plans.
  • Excellent oral, written, and interpersonal communication skills, including the ability to explain technical concepts and risk in non-technical terms.
  • Strong analytical, organizational, and problem-solving skills; ability to manage concurrent priorities with appropriate attention to detail.
  • Ability to obtain and maintain CISSP certification within eighteen months of appointment if not already certified.

Responsibilities

  • Lead technology risk assessments across university systems, business units, and third parties with remediation plans.
  • Coordinate audit preparation and response for internal and external audits and state reviews.
  • Oversee regulatory compliance across FTC Safeguards Rule, FERPA, UNC System policies, and state/federal requirements.
  • Own the human risk program including phishing simulations and security awareness training.
  • Develop and maintain information security policies, standards, and control frameworks aligned to NIST CSF and CIS Controls.
  • Inform prioritization for the broader technology organization and drive remediation sequencing and investment decisions.

Skills

Security leadership
Governance, risk, compliance
Incident coordination
Policy development
Third-party security review
Executive communication
Collaboration and customer service
Planning and documentation

Education

Bachelor’s degree in cybersecurity, computer science, information systems, business analytics, or a related field
Master’s degree in cybersecurity, information systems, business administration, or a related field

Job description

Western Carolina University has been ranked #3 in the nation on Forbes 2025 ‘America’s Best Midsize Employers’ list, out of the top 498 employers across all industries.

Deputy Chief Information Security Officer - #270015
Posting Details
  • Posting Number: EHRA1117P
  • Posting ID: 35162
  • Classification Title: Deputy Chief Security Information Officer
  • Working Title: Deputy Chief Information Security Officer - #270015
  • Department: IT Security Office
  • Anticipated Hiring Range: Based on qualifications/experience, internal equity, and departmental budget restrictions.
About WCU

Western Carolina University continues to rank high on Forbes ‘Best Employers’ lists each year. Including:

  • 2025 – Ranked 1st in the top 100 employers in North Carolina in Forbes ‘America’s Best Employers by State’ list.
  • 2024 – Ranking in the top 8.5% on Forbes ‘America’s Best Midsize Employers’ list, WCU was ranked 34 out of the top 400 employers across all industries.
  • 2023 – Ranked in the top 20% on Forbes ‘America’s Best Midsize Employers’ list, WCU was ranked 97 out of the top 500 employers across all industries.
  • 2022 – Ranked 14th in the top 100 employers in North Carolina in Forbes ‘America’s Best Employers by State’ list.

Western Carolina University is the UNC system’s westernmost campus and has been consistently ranked as one of the top 15 public regional institutions in the South.

Employees of WCU are provided a comprehensive benefits package as well as other resources, policies and programs to ensure a happy and healthy work/life balance. Benefit eligible employees have access to dental, vision and health insurance plans – eligibility begins on the first of the month following date of hire. Retirement plan contributions begin on the eligibility date following election and include employer contributions for either a defined contribution or a defined benefit plan. Optional disability plans are also available.

Eligible employees have access to tuition waivers for up to three courses per academic year; employee may enroll at any of the constituent UNC System campuses. Also offered are free group exercise classes multiple times per week, a discounted membership to the campus recreation center, free vaccine and booster shots offered on campus, pretax flexible spending accounts, 12 paid holidays and 24 hours of paid community service leave each year. Leave earning employees (staff and 12-month faculty) who work at least half of the working days of their first month of employment will begin accruing vacation and sick leave immediately. Paid parental leave after 12 months of continuous service.

WCU offers an abundance of training and development programs, certifications, workshops and conferences – many of which are offered free of charge.

Position Summary

The primary location of this position is on-site in Cullowhee, NC. This position is designated as being exempt from the State of North Carolina Human Resources Act (EHRA).

The Deputy Chief Information Security Officer (Deputy CISO) reports to the Chief Information Security & Privacy Officer. The position provides senior operational and program leadership for the IT Security Office and serves as the principal delegate for assigned security matters. The Deputy CISO translates institutional security and privacy priorities into coordinated operations, supports continuity of leadership, and works across the Division of IT and the university to reduce technology risk.

The position leads or coordinates security governance, risk assessment, regulatory and standards compliance, security awareness, security operations oversight, and security review of technology projects and third-party services. The Deputy CISO advises technical and non-technical stakeholders, documents risk-based recommendations, tracks corrective actions, and escalates significant risks and incidents to the CISPO.

Description of Work
  • Technology risk assessments across university systems, business units, and third parties. This includes maintaining the enterprise risk register, developing assessment methodologies, and ensuring risks are documented with accountable owners and remediation plans.
  • Audit preparation and response, including internal audit engagements, external audits, and reviews conducted by the Office of the State Auditor. The Deputy CISO serves as the primary coordinator for audit evidence, response, and remediation tracking.
  • Regulatory compliance across the frameworks that apply to the university, including the FTC Safeguards Rule (GLBA), FERPA, UNC System policies, and applicable state and federal requirements. The Deputy CISO maintains the compliance mapping and reporting cadence.
  • The human risk program, including phishing simulations, security awareness training, and security communications to the university community.
  • The technology risk governance framework, including the development and maintenance of information security policies, standards, and control frameworks aligned to recognized industry frameworks such as NIST CSF and CIS Controls.
  • The Deputy CISO’s work directly informs prioritization for the broader technology organization. The risk view produced by the function drives remediation sequencing, planning priorities, and investment decisions across IT.
Required Knowledge, Skills, and Abilities
  • Security leadership and operational judgment
  • Governance, risk, compliance, and control assessment
  • Incident coordination and decision support
  • Policy and procedure development
  • Third-party, software, and project security review
  • Clear executive, technical, and campus communication
  • Collaboration, consultation, and customer service
  • Planning, prioritization, documentation, and accountability
Minimum Qualifications
  • Bachelor’s degree in cybersecurity, computer science, information systems, business analytics, or a related field.
  • Five years of progressively responsible experience across multiple information security functions, such as governance, risk, compliance, security operations, incident response, identity and access management, infrastructure security, or third-party risk.
  • Demonstrated experience coordinating complex security initiatives across technical teams and business units.
  • Working knowledge of networking, systems administration, endpoint security, identity and access control, cloud or hosted services, vulnerability management, and incident response practices.
  • Experience developing or implementing security policies, risk assessments, control documentation, audit responses, or remediation plans.
  • Excellent oral, written, and interpersonal communication skills, including the ability to explain technical concepts and risk in non-technical terms.
  • Strong analytical, organizational, and problem-solving skills; ability to manage concurrent priorities with appropriate attention to detail.
  • Ability to obtain and maintain CISSP certification within eighteen months of appointment if not already certified.
Preferred Qualifications
  • Master’s degree in cybersecurity, information systems, business administration, or a related field.
  • More than seven years of progressively responsible information security experience, including program or team leadership.
  • Current CISSP certification; additional relevant certification such as CISM, CRISC, GIAC, or a privacy credential.
  • Experience in higher education, government, or another complex regulated environment.
  • Experience with ISO 27002, ISO 27701, NIST Cybersecurity Framework, NIST security controls, PCI DSS, HIPAA, GLBA, or comparable requirements.
  • Experience supporting security incidents, audits, executive briefings, third-party risk assessments, and risk-register governance.
Position Type

Permanent Full-Time

Number of Hours Per Week

40

Number of Months Per Year

12

Open Date

08/24/2026

Open Until Filled

Yes

Background/E-Verify

Final candidates are subject to criminal & sex offender background checks. Some vacancies also require credit or motor vehicle checks.

Western Carolina University uses E-Verify to confirm employment eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.dhs.gov/E-Verify. Proper documentation of identity and employability are required at the time of employment.

Credential Verification

All new employees are required to have listed credentials/degrees verified within 30 days of employment. All new employees who will be teaching are required to provide official transcripts within 30 days of employment. Transcripts should be provided for the highest earned degree and/or the degree which is being used to satisfy credential/qualification requirements.

Equal Opportunity Employer

Western Carolina University is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race; color; ethnicity; religion; sex; pregnancy; sexual orientation; gender identity or expression; national origin; age; disability; genetic information; political affiliation; National Guard or veteran status, consistent with applicable federal, state and local laws, regulations, and policies, and the policies of The University of North Carolina. Persons with disabilities requiring accommodations in the application and interview process please call (828) 227-7218 or email at jobs@email.wcu.edu.

University Safety

The Western Carolina University Annual Safety Report is available online at University Annual Safety Report or in hard-copy by request at the office of the Vice Chancellor for Student Affairs, 227 HFR Administration Building, Cullowhee, NC 28723 (828-227-7147) or the Office of University Police, 111 Camp Annex, Cullowhee, NC 28723 (828-227-7301). The report, required of all universities participating in Title IV student financial aid programs, discusses crime statistics, procedures for reporting suspicious or criminal activity, security, police authority, crime prevention strategies, university policies on substance abuse and sexual offenses, workplace violence and fire safety.

Applicant Documents
  1. Cover Letter/Letter of Application
  2. Resume
  3. List of references

Optional Documents

  1. Optional Documents
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Research Security Specialist
Research Security Specialist

North Carolina State University • North Carolina

On-site
USD 130,000 - 150,000
Health benefits
Retirement programs
Paid time off
Academic Business Operations Analyst - #270009
Academic Business Operations Analyst - #270009

Western Carolina University • Cullowhee (NC)

On-site
USD 60,000 - 75,000
Assistant Director of Alumni Engagement - #202895
Assistant Director of Alumni Engagement - #202895

Western Carolina University • Cullowhee (NC)

On-site
USD 55,000 - 75,000
Assistant Director of Athletics Compliance - #270016
Assistant Director of Athletics Compliance - #270016

Western Carolina University • Cullowhee (NC)

On-site
USD 36,000 - 64,000
Dental insurance
Tuition waivers for up to three course
Paid holidays
Assistant Director of Athletics Equipment - #270019
Assistant Director of Athletics Equipment - #270019

Western Carolina University • Cullowhee (NC)

On-site
USD 44,000 - 64,000
Assistant Director of Admissions / Regional Recruiter (Asheville) - #002559
Assistant Director of Admissions / Regional Recruiter (Asheville) - #002559

Western Carolina University • Asheville (NC)

On-site
USD 50,000 - 70,000
Tuition waivers for up to three study-
Retirement plan contributions
Paid holidays and community service
Assistant Professor of Practice – Collection Development Librarian - #002825
Assistant Professor of Practice – Collection Development Librarian - #002825

Western Carolina University • Cullowhee (NC)

On-site
USD 70,000 - 90,000
Tuition waiver
Learning Technologist - #270002
Learning Technologist - #270002

Western Carolina University • Cullowhee (NC)

On-site
USD 70,000 - 90,000
Tuition waivers
Health insurance
Paid holidays
Assistant Director, Retention - #270020
Assistant Director, Retention - #270020

Western Carolina University • Cullowhee (NC)

On-site
USD 65,000 - 90,000
Administrative Assistant
Administrative Assistant

Western Carolina University • Cullowhee (NC)

On-site
USD 35,000 - 48,000