Assistant Vice President, Information Security

University of TampaTampa, FL
Onsite

About The Position

The University of Tampa's Information Technology and Security department is seeking an Assistant Vice President, Information Security (AVP). This role reports to the Vice President, Information Technology and Security (CIO/CISO) and is responsible for assisting in the development and execution of a comprehensive, multi-year security strategy. The strategy aims to protect students, faculty, staff, and institutional data against evolving threats, including those posed by artificial intelligence, identity-based attacks, and third-party risks. The AVP will handle executive duties such as briefing cabinet or board members, leading the ITS CCIRT team, and managing major incident investigations in a collaborative environment. This position requires a strong understanding of the interplay between business, academic, and security needs, as well as the ability to evaluate technology solutions and set risk-based criteria that foster innovation and productivity. Responsibilities also include leading or participating in audits, conducting risk assessments, and implementing improvements to the information security program, procedures, and data protection. This is a strategy-focused leadership role where success is measured by the ability to anticipate risks, align security investments with institutional priorities, and communicate effectively with executive audiences. The AVP will build a team capable of managing day-to-day operations.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field.
  • Ten (10) years of varied information technology experience, including extensive supervisory experience and at least seven (7) years of directly related information security experience.
  • Certified Information Systems Security Professional (CISSP) or an equivalent information security professional certification.
  • Demonstrated success developing and executing an information security strategy — not solely operating a program — including experience presenting to executive or board-level audiences.
  • Working knowledge of the security implications of enterprise AI adoption and AI-enabled threats, with the ability to translate both into practical policy and controls.
  • Deep working knowledge of the regulatory landscape governing higher education information security, including GLBA, FERPA, HIPAA, and PCI DSS, with demonstrated experience maintaining compliance across multiple frameworks simultaneously and translating regulatory requirements into practical controls, evidence, and audit readiness.
  • Familiarity or experience with ISO/IEC 27001:2022, ISO/IEC 22301:2019, and ISO/IEC 20000-1:2018 management systems, with the ability to become certified as a Lead Auditor in each.
  • Strong leadership and supervisory skills, including proven ability to delegate effectively — quickly distinguishing what requires direct involvement from what belongs with the team — and to develop staff capable of owning operations.
  • A collaborative, approachable working style by building trust across departments, listening well, and working as a partner rather than an enforcer.
  • A fast, decisive working pace with strong follow-through; comfortable making sound decisions with incomplete information and adjusting as facts develop.
  • Demonstrated skills in budget development, financial management, and resource management.
  • Excellent oral and written communication skills, including the ability to make complex security topics clear to non-technical audiences.
  • Excellent organizational and time management skills; demonstrated ability to prioritize and manage multiple projects simultaneously and meet established deadlines.
  • Willingness to embrace new technologies and innovative organizational practices.

Nice To Haves

  • Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Additional security certifications (e.g., CISM, CCSP, CRISC, GIAC, or AI security–related credentials).
  • Experience with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) or hands-on evaluation of enterprise AI platforms.
  • Experience with cloud security architecture, identity-centric security models, and zero trust implementation.
  • Knowledge of data privacy legislation (e.g., GDPR, state privacy laws) and data governance practices.
  • Computer forensics or incident response leadership experience.
  • Experience supporting HIPAA compliance in a campus health or clinic setting, including business associate and covered-entity considerations.
  • Higher education experience.

Responsibilities

  • Owns and maintains the university's multi-year information security strategy and roadmap, aligning it with institutional goals, the enterprise risk register, and the realities of a private, residential, four-year university environment.
  • Sets and sequences security priorities using risk-based judgment: distinguishing the initiatives that require the AVP's direct leadership from those that should be delegated to capable staff and empowering the team accordingly.
  • Communicates security posture, risk trends, and program progress to the VP and Cabinet-level audiences in clear, non-technical, decision-ready terms.
  • Integrates security considerations into strategic and tactical planning, budget preparation, and major initiatives across ITS and the university — acting as a partner in enabling institutional goals, not a gatekeeper.
  • Develops the annual security budget and multi-year investment plan, making defensible trade-off recommendations and demonstrating return on security investment.
  • Continuously scans emerging threats, technologies, and higher education security trends, translating them into concrete, prioritized action for the university.
  • Partners with university AI governance efforts, contributing security expertise to AI acceptable use policy, data classification guidance for AI tools, and the review and approval of AI platforms and integrations.
  • Builds and matures defenses against AI-enabled threats, including AI-generated phishing, deepfake-driven social engineering and fraud, and automated credential attacks.
  • Assesses the security implications of enterprise AI adoption — including generative AI platforms, AI agents, and AI features embedded in existing vendor products — and establishes controls proportionate to institutional risk.
  • Evaluates and adopts the responsible use of AI within the security program itself, including AI-assisted detection, response, and security awareness capabilities.
  • Leads third-party and vendor AI risk review as part of the university's technology approval and procurement processes.
  • Coordinates the development, implementation, and administration of security policies, standards, and programs for ITS and other areas of the university as applicable.
  • Leads the Computer Security Incident Response Team (CSIRT) and co-leads the Business Continuity Emergency Incident Response Team (BCEIRT), ensuring plans are tested, current, and understood.
  • Oversees a modern defensive posture spanning identity and access management, cloud and SaaS security, endpoint protection, email security, data loss prevention, and vulnerability management, with progress toward zero trust principles.
  • Coordinates the assessment of systems and network security risks, including risk analysis, threat assessments, and contingency planning.
  • Completes incident reports and investigations of policy violations and suspected material incidents, including any required regulatory notifications.
  • Participates in project development across ITS to ensure security best practices are built in from the start.
  • Manages the ISO/IEC 27001 ISMS, maintaining and improving documentation, processes, policies, plans, and corrective actions.
  • Compiles evidence of compliance with the major regulations and requirements affecting the university — including GLBA, FERPA, HIPAA, PCI DSS, and applicable data privacy laws — recognizing that university data spans multiple regulated categories and frameworks concurrently.
  • Participates in multiple annual audits across the university's ISO management systems, penetration tests, third-party security assessments, PCI compliance audits, and GLBA audits.
  • Oversees effective, engaging security awareness programs — including AI-era threat education — that measurably change behavior across students, faculty, and staff.
  • Builds, develops, and retains a high-performing security team, delegating operational ownership with clear accountability and coaching staff toward greater autonomy.
  • Serves as an approachable, visible member of the ITS leadership team and a trusted, down-to-earth partner to departments across campus.
  • Facilitates and directs the timely dissemination of security information to the university community.
  • Contributes to a work environment that encourages knowledge of, respect for, and development of skills to engage with those of other cultures and backgrounds.
  • Attends conferences and training as required to maintain proficiency.

Benefits

  • FREE Tuition
  • Generous paid leave
  • Wellness initiatives
  • 100% Employer-Funded Health Reimbursement Account
  • 100% Employer-Paid Short & Long Term Disability Insurance
  • 100% Employer-Funded Employee Assistance Program
  • Discounted On-Campus Dining Meal Plans
  • FREE On-Campus Parking
  • FREE Access to Campus Amenities (pool, library, campus events and more)
  • Fitness Center
  • Pet Insurance
  • Flexible Spending Accounts
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service