> Markdown version of [/jobs/ext/2218124-deputy-chief-information-security-officer](https://www.wearedevelopers.com/jobs/ext/2218124-deputy-chief-information-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Deputy Chief Information Security Officer - **Company:** The Western Carolina University - **Location:** Cullowhee, NC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Information Systems, Decision Support Systems, Identity and Access Management, PCI Data Security Standards, Phishing, Software Vulnerability Management, Information Technology, CIS Benchmarks, ISO/IEC 27002 - **Published:** August 25, 2026 - **Apply:** https://jobs.wcu.edu/postings/35166/pre_apply ## About the Role * Security leadership and operational judgment * Governance, risk, compliance, and control assessment * Incident coordination and decision support * Policy and procedure development * Third-party, software, and project security review * Clear executive, technical, and campus communication * Collaboration, consultation, and customer service * Planning, prioritization, documentation, and accountability, * Bachelor's degree in cybersecurity, computer science, information systems, business analytics, or a related field. * Five years of progressively responsible experience across multiple information security functions, such as governance, risk, compliance, security operations, incident response, identity and access management, infrastructure security, or third-party risk. * Demonstrated experience coordinating complex security initiatives across technical teams and business units. * Working knowledge of networking, systems administration, endpoint security, identity and access control, cloud or hosted services, vulnerability management, and incident response practices. * Experience developing or implementing security policies, risk assessments, control documentation, audit responses, or remediation plans. * Excellent oral, written, and interpersonal communication skills, including the ability to explain technical concepts and risk in non-technical terms. * Strong analytical, organizational, and problem-solving skills; ability to manage concurrent priorities with appropriate attention to detail. * Ability to obtain and maintain CISSP certification within eighteen months of appointment if not already certified., * Master's degree in cybersecurity, information systems, business administration, or a related field. * More than seven years of progressively responsible information security experience, including program or team leadership. * Current CISSP certification; additional relevant certification such as CISM, CRISC, GIAC, or a privacy credential. * Experience in higher education, government, or another complex regulated environment. * Experience with ISO 27002, ISO 27701, NIST Cybersecurity Framework, NIST security controls, PCI DSS, HIPAA, GLBA, or comparable requirements. * Experience supporting security incidents, audits, executive briefings, third-party risk assessments, and risk-register governance. ## Description The primary location of this position is on-site in Cullowhee, NC. This position is designated as being exempt from the State of North Carolina Human Resources Act (EHRA). The Deputy Chief Information Security Officer (Deputy CISO) reports to the Chief Information Security & Privacy Officer. The position provides senior operational and program leadership for the IT Security Office and serves as the principal delegate for assigned security matters. The Deputy CISO translates institutional security and privacy priorities into coordinated operations, supports continuity of leadership, and works across the Division of IT and the university to reduce technology risk. The position leads or coordinates security governance, risk assessment, regulatory and standards compliance, security awareness, security operations oversight, and security review of technology projects and third-party services. The Deputy CISO advises technical and non-technical stakeholders, documents risk-based recommendations, tracks corrective actions, and escalates significant risks and incidents to the CISPO., * Technology risk assessments across university systems, business units, and third parties. This includes maintaining the enterprise risk register, developing assessment methodologies, and ensuring risks are documented with accountable owners and remediation plans. * Audit preparation and response, including internal audit engagements, external audits, and reviews conducted by the Office of the State Auditor. The Deputy CISO serves as the primary coordinator for audit evidence, response, and remediation tracking. * Regulatory compliance across the frameworks that apply to the university, including the FTC Safeguards Rule (GLBA), FERPA, UNC System policies, and applicable state and federal requirements. The Deputy CISO maintains the compliance mapping and reporting cadence. * The human risk program, including phishing simulations, security awareness training, and security communications to the university community. * The technology risk governance framework, including the development and maintenance of information security policies, standards, and control frameworks aligned to recognized industry frameworks such as NIST CSF and CIS Controls. * The Deputy CISO's work directly informs prioritization for the broader technology organization. The risk view produced by the function drives remediation sequencing, planning priorities, and investment decisions across IT. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)