Chief Information Security Officer

California State UniversityAllen, TX
$8,333 - $12,500

About The Position

This position serves as the University Information Security, Risk, and Policy Officer (ISO/CRO/CPO), responsible for all duties in that capacity. The role involves maintaining and administering the University Information Security Program, providing leadership in establishing and maintaining the University's security architecture, controls, policies, standards, processes, and procedures. The position offers regular assessments of the University's security posture, the operation of existing controls, and progress on improvements through metrics and reporting to the CIO, IT Leadership, and University Leadership. It also performs activities required by CSU, federal, state, or other regulations to achieve or maintain University compliance. The role includes annual and scheduled reviews of University procedural documents related to information security, compliance, and risk management, as well as maintaining and administering the University Information Security Awareness Program and supporting procedures and documentation for security, risk management, and compliance. Collaboration with the system-wide Information Security Council (ISC) on CSU system compliance and risk matters is also a key function.

Requirements

  • Bachelor's degree required.
  • Eight to ten years of experience in a combination of IT Security, IT Risk Management, and General IT positions.
  • At least 4 years of experience in a leadership role.
  • Proven and extensive experience in planning, organizing, developing, and implementing IT security strategies and related initiatives.
  • Proficiency in IT security management, industry best practices, and standards.
  • Proven ability to identify, prioritize and communicate the impact of IT security risks to leadership, stakeholders, and users.
  • Extensive experience in developing and implementing IT security policies, standards, and guidelines.
  • Substantial knowledge and exposure in developing and testing business continuity and disaster recovery plans.
  • Considerable experience in and knowledge of IT security auditing.
  • Proven ability to measure, monitor, and report on the success of IT security-related initiatives.
  • Understanding of effective IT security architectures, concepts, techniques, and tools.
  • Understanding and experience managing network and system security components such as firewalls, intrusion detection/prevention systems, vulnerability scanning, etc.
  • In-depth knowledge of applicable IT security-related laws and regulations.
  • Proven ability to work effectively in a coordinating role across multiple constituencies to achieve tactical and strategic goals.
  • Excellent oral and written communication skills.
  • Self-motivated and self-directed/driven.
  • Excellent analytical, evaluative, and problem-solving capabilities.
  • Strong leadership, management, and team-building skills.
  • Positive attitude, proven ability to work successfully with diverse populations, and demonstrated commitment to promoting and enhancing diversity and inclusion.
  • Must be authorized to work for any employer in the United States.
  • Background check (including a criminal records check) must be completed satisfactorily.
  • Compliance with California Child Abuse and Neglect Reporting Act requirements.
  • Potential requirement to file a Statement of Economic Interest annually and complete related training.

Nice To Haves

  • Advanced degree preferred.
  • Certifications such as CISSP (Certified Information System Security Professional), CISM (ISACA Certified Information Security Manager), or CISA (ISACA Certified Information Security Auditor) are preferred.
  • Experience working in an IT higher education institution preferred.

Responsibilities

  • Coordinate the development of CSU Channel Islands information security policies, standards, and procedures, working with key ITS offices, data custodians, and governance groups. Ensure university policies support compliance with system and external requirements and oversee the dissemination of policies, standards, and procedures to the university community.
  • Coordinate the development and delivery of an education and training program on information security and privacy matters for employees, students, and other authorized users.
  • Serve as the university compliance officer with respect to CSU Channel Islands, state, and federal information security policies and regulations. Work with campus designated privacy officers on compliance issues and prepare and submit required reports to external agencies.
  • Develop and implement an ongoing risk assessment program targeting information security and privacy matters. Provide security risk assessments to academic and business units and assist with the development, deployment, and monitoring of protective measures. Work with the CIO, IT committees, University executives, Deans, and administrators to ascertain University security priorities. Advise on budget and funding issues for identified priorities. Direct complex security development projects and manage security systems to ensure secure IT functions supporting teaching, learning, scholarship, and administration.
  • Oversee the monitoring of security controls and provide metrics and reporting to ensure controls are performing as designed and to correct deficiencies. Develop, implement, and maintain an Incident Reporting and Response Process to address security incidents, breaches, policy violations, or complaints. Serve as the official campus contact point for information security, privacy, and copyright infringement incidents, including relationships with law enforcement entities.
  • Monitor and evaluate data from security event information sources and/or network logs to promptly identify, evaluate, and respond to information security incidents. Provide regular assessments of information security operations with efficacy metrics. Participate in incident handling on short notice during off-shift hours. Contribute to security systems design, draft formal incident reports, and prepare vulnerability reporting metrics, threat intelligence, and other analysis. Interface with stakeholders to facilitate coordinated security operations. Promote greater awareness of information security practices through thought leadership activities and conduct user awareness training as needed.
  • Work collaboratively with ITS staff to ensure proper enforcement of CSU and CI policies and practices regarding information security. Assist end-users with information security-related issues and/or questions. Collaborate with Procurement and Risk Management offices to enforce secure procurement practices of IT services and resources, including contract review and analysis. Provide consultative and training support to ensure user satisfaction and effective and secure use of university systems.
  • Participate as a member of the ITS team to ensure the successful operation of the work unit in supporting the security of university systems and meeting users' needs. Effectively communicate technical terms and requirements to functional users. Cooperatively work with ITS teams in support of the implementation of CSU ICSUAM 8000 Series Information Security policies.
  • Act as the designee representing Channel Islands on Information Security matters. Serve as the campus contact point for external auditors and agencies, survey requests, etc., on security and privacy matters.
  • Attend CSU system-wide meetings and represent ITS as required. Perform other duties as required.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service