> Markdown version of [/jobs/ext/1484960-assistant-vice-provost-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/1484960-assistant-vice-provost-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Assistant Vice Provost & Chief Information Security Officer - **Company:** Oregon State University - **Location:** Corvallis, OR, United States (Remote available) - **Experience:** Expert - **Salary:** $202,375.0 - $240,000.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Infrastructure as a Service (IaaS), Identity and Access Management, Machine Learning, Platform as a Service (PAAS), PCI Data Security Standards, Security Information and Event Management, Software Vulnerability Management, Multi-Cloud, Generative AI, Cyber Threat Analysis, Information Technology - **Published:** July 29, 2026 - **Apply:** https://dejobs.org/x/x/E3B245CC5614418087D7584EFD46F58E/job/ ## About the Role * A bachelor's degree in Information Security, Computer Science, Information Technology, Business Administration, or a related field. * Minimum of 10 years of progressively responsible leadership experience in information security, cybersecurity, or a closely related field. * Demonstrated knowledge of and experience with common information security frameworks, including NIST CSF, NIST RMF, NIST 800-53, ISO/IEC 27001, or COBIT. * Proven experience developing and executing enterprise-wide cybersecurity strategies that balance institutional risk tolerance with operational flexibility and mission-driven innovation. * Demonstrated experience with security operations, threat intelligence, vulnerability management, and incident response in complex, multi-system environments. * Extensive knowledge of applicable regulatory and compliance requirements, including FERPA, HIPAA, GLBA, PCI DSS, NIST 800-171, and federal research security mandates. * Demonstrated experience with cloud computing security (IaaS, PaaS, SaaS) and securing hybrid and multi-cloud technology environments. * Highly effective written and verbal communication skills, with a proven ability to translate complex cybersecurity and AI risk concepts for technical and non-technical audiences at all levels, including boards, executives, faculty, and students. * Demonstrated ability to build trusted, collaborative relationships across diverse institutional stakeholders * Strong financial acumen with experience in budget management, resource planning, and aligning security investments with strategic institutional priorities. * Proven commitment to promoting and enhancing inclusive excellence in the workplace. This position is designated as a critical or security-sensitive position; therefore, the incumbent must successfully complete a criminal history check and be determined to be position qualified as per University Standard: 05-010 et seq. Incumbents are required to self-report convictions and those in youth programs may have additional criminal history checks every 24 months. This position requires driving a university vehicle or a personal vehicle on behalf of the university; therefore, the incumbent must successfully complete a motor vehicle history check, possess and maintain a current, valid driver's license in their state of residence, be determined to be position qualified and self-report convictions as per University Policy 05-030. Final candidates for this position must complete a sexual misconduct reference check, per University Policy 05-010. An offer of employment will be contingent upon satisfactory results from the sexual misconduct reference check., * A master's degree in Information Security, Computer Science, Information Technology, Business Administration, or a related field. * Minimum of 5 years in a senior cybersecurity leadership role, with demonstrated experience managing and developing high-performing security teams in complex, matrixed organizational environments. * Active professional certification: CISSP, CCISO, CISM, CISA, or equivalent advanced credential. * Demonstrated knowledge of or experience with AI security risks, AI governance frameworks (e.g., NIST AI RMF), and the security implications of AI/ML technologies, including generative AI tools and platforms. * Experience in higher education information security, with demonstrated understanding of the unique regulatory, research, and governance environment of a research-intensive (R1) land-grant university. * Experience with federal research security requirements, including NSPM-33, CUI handling, and export control compliance. * Demonstrated experience developing and implementing AI governance or AI security programs, including policies and risk frameworks for generative AI and machine learning platforms. * Familiarity with identity and access management (IAM) strategies for large, diverse, and decentralized user populations. * Experience with SOC management, including 24/7 monitoring, threat intelligence platforms, and SIEM technologies. * Experience leading organizational change initiatives and transforming security culture in complex, decentralized environments. * Familiarity with EDUCAUSE HEISC and REN-ISAC threat intelligence communities. * Experience with privacy program management and collaboration with institutional Privacy Officers. ## Description Reporting to the Vice Provost for University Information & Technology and Chief Information Officer, the Assistant Vice Provost & Chief Information Security Officer (CISO) serves as a senior member of the CIO's Executive Leadership Team and a trusted advisor to university leadership at the highest levels. This position operates with significant institutional visibility, engaging regularly with the Provost's Office, General Counsel, Internal Audit, Risk Management, the Board of Trustees, federal agencies, and external partners. The CISO must be equally effective in the executive meetings and in the field, translating complex cybersecurity risk into clear, actionable guidance for audiences ranging from front-line staff and faculty to university executives and governing boards. The CISO is a connector and a convener, working across every college, department, research unit, and administrative function at OSU to build shared security culture, co-develop practical solutions, and ensure that cybersecurity is understood as a university-wide responsibility rather than an IT-only function. Internally, the CISO cultivates trusted relationships at all levels of the organization, from individual contributors and department administrators to deans, vice provosts, and executive leadership. Externally, the CISO represents OSU with federal agencies, law enforcement, peer research universities, and national cybersecurity communities, ensuring OSU benefits from the best intelligence, partnerships, and practices available in the field. In a rapidly evolving threat landscape, increasingly shaped by the proliferation of artificial intelligence, nation-state actors, and the unique vulnerabilities of the research enterprise, the CISO must be a forward-thinking, adaptive leader. The CISO ensures OSU's cybersecurity program keeps pace with AI-driven threats and emerging attack vectors, maintaining digital resilience across a complex and decentralized institution. While this role does not lead a dedicated AI governance function, the CISO plays a critical role in evaluating AI tools and practices deployed across the university, ensuring they align with OSU's security standards and do not introduce unacceptable risk to institutional systems, research data, or community members. The CISO brings together strategy and operations, vision and execution, building a cybersecurity program that is proactive, resilient, and reflective of OSU's values as an open, innovative, and mission-driven institution. In addition, this position provides leadership and operational oversight for the Office of Information Security (OIS), supporting the development, implementation, and continuous improvement of institutional information security practices, risk management, and compliance efforts. Please note all OSU IT team members are expected to meet the following commitments: AI Statement: OSU IT embraces the transformative potential of artificial intelligence (AI) to drive innovation, enhance efficiency, and create meaningful impact across our teaching, research, and administrative functions. As a member of the OSU IT community, the person in this position is expected to thoughtfully engage with AI tools and practices, champion their ethical and responsible use, and actively contribute to the development of AI-driven solutions that uphold our institutional values and advance the university's mission., * Enterprise Cybersecurity Strategy & AI Security Leadership: Provide executive-level leadership for OSU's enterprise-wide information security program; develop a multi-year strategy grounded in the NIST Cybersecurity Framework and RMF; lead security governance for the responsible adoption of AI and emerging technologies; and serve as the university's foremost authority on cyber risks. * Security Operations, Threat Intelligence & Incident Response: Direct the Security Operations Center and 24/7 threat detection; serve as OSU's IT Incident Manager for critical incidents; lead threat intelligence on AI-enabled and nation-state threats targeting higher education; and oversee vulnerability and third-party risk management. * Policy, Compliance, Risk Governance: Lead enterprise cybersecurity policy and a comprehensive Governance, Risk & Compliance program; ensure compliance with FERPA, HIPAA, GLBA, PCI DSS, NIST 800-53/171, and federal research security mandates; and establish OSU's framework for the secure adoption of AI. * Security Awareness, Education & Community Engagement: Champion a university-wide culture of cybersecurity awareness; design education programs for students, faculty, staff, and researchers; address AI-related security risks; and partner with academic units on curricula, experiential learning, and student engagement. * External Partnerships & Professional Leadership: Build partnerships with federal agencies (CISA, NSF, NIH, DOD), law enforcement, and peer R1 institutions; represent OSU on state and national cybersecurity advisory bodies; and engage with EDUCAUSE, REN-ISAC, and research consortia., This position will work a typical Monday - Friday schedule and will be based on the Corvallis campus. This position may at times require work outside of normal business hours and/or weekends. Inclement Weather This position is deemed essential, and the incumbent may be expected to report to work during inclement weather, emergencies, and other University work curtailments or closures. Modality Hybrid: This position is designated as hybrid, working both on-site and remotely. The exact amount of on-site and remote work and schedule will be discussed with the supervisor. Hybrid work is dependent on business needs. Travel This position may require occasional duties/business trips to other OSU locations away from the OSU Corvallis campus. ## Related Videos - [Making Teaching Code Less Academic and More Market-Ready - Peter Ruppel](https://www.wearedevelopers.com/videos/1911-making-teaching-code-less-academic-and-more-market-ready-peter-ruppel) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Your imaginations is (no longer) the limit: how Generative AI empowers people to be creative](https://www.wearedevelopers.com/videos/741-your-imaginations-is-no-longer-the-limit-how-generative-ai-empowers-people-to-be-creative) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production)