Chief Information Security, Compliance and Risk Officer/CISO

California State University
Boulder, CO, United States
3 days ago
Apply on jobs.chronicle.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$174,000.0 - $212,400.0
Working hours
Shift work

Tech stack

Cyber Security Information Systems Data Security IT Management Information Systems Security Architecture Professional PCI Data Security Standards Information Technology

Job description

The scope of responsibilities for this position includes the making or participating in the making of decisions that may have a material financial benefit on the incumbent. Therefore, you will be required to file an initial “Conflict of Interest Form 700: Statement of Economic Interests” within thirty (30) days from date of hire and on an annual basis; and complete the CSU sponsored ethics on-line training within thirty (30) days of appointment, and at least once during each consecutive period of two calendar years following the appointment.

The person holding this position is considered a limited mandated reporter under the California Child Abuse and Neglect Reporting Act and must comply with the requirement outlined in CSU Executive Order 1083, revised July 21, 2017.

This position is designated as a Campus Security Authority (CSA) position under the federal Jeanne Clery Disclosure of Campus Security Policy and Campus Crime Statistics Act. CSAs are responsible for reporting allegations of Clery Act Crimes reported to them or that they witness. CSA training is required.

Applicants will be required to disclose whether they have received a final administrative decision or final judicial decision determining that they have committed sexual harassment within the last 7 years only after a determination is made that they meet the minimum qualifications for the position, and before an offer of employment is extended. Applicants who reach the final stages of the application process must also sign a release form that authorizes the release of information by the applicant’s current and/or former employers to the CSU concerning any substantiated allegations of misconduct.

Multiple positions may be hired from this recruitment based on the strength of the applicant pool.

If you are applying for a staff position, please note that you are not eligible to work concurrently in a staff position and an Academic Student position such as a Graduate Assistant, Teaching Associate, Instructional Student Assistant, or Student Assistant position.

Regular attendance is considered an essential job function; the inability to meet attendance requirements may preclude the employee from retaining employment.

Employee/applicant who applies for a position may be required to successfully complete job-related performance test(s) as part of the selection process.

Online application/resume must be received by electronic submission on the final filing date by 9:00 PM (Pacific Standard Time)/midnight (Eastern Standard Time). Applicants who fail to complete all sections of the online application form will be disqualified from consideration.

California State University, Fullerton is not currently sponsoring any new H-1B petitions for staff, management, or faculty positions.

Requirements

Department: The Division of Information Technology (IT) strives to be a strategic, innovative, and best-in-class IT organization that provides a leading-edge technology environment for students, faculty, and staff to advance the University’s mission, vision, and goals. We are seeking an exceptional individual to join our IT Information Security department as the Chief Information Security, Compliance and Risk Officer/CISO (Administrator III). The ideal candidate in this role should have a positive attitude, an active, energetic mind, and a leadership style that is characterized by highly ethical practices and a commitment to inclusivity, openness, flexibility, integrity, and kindness., Bachelor’s degree from an accredited four-year college or university in computer science, information systems, cybersecurity, public administration, business administration, or a related field. Eight or more years of progressively responsible experience in information security, cyber risk, or IT compliance, including significant leadership experience managing teams and programs.

Demonstrated experience setting strategic direction and roadmap for a cybersecurity, compliance, or risk program in a complex, multi-stakeholder environment. Demonstrated knowledge of information security and privacy regulations and frameworks applicable to higher education (e.g., Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standard (PCI DSS), California Consumer Privacy Act (CCPA), General Data Protection Regulation (GDPR), National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), NIST 800-53, International Organization for Standardization (ISO) 27001). Experience leading or supporting cybersecurity incident response at an executive level, including coordination with legal, communications, and external partners. Demonstrated ability to translate complex technical, policy, and regulatory concepts into clear guidance for executive leadership and non-technical audiences. Strong interpersonal, written, and verbal communication skills, including the ability to facilitate cross-functional collaboration and build consensus.

A background check (including a criminal records check) must be completed satisfactorily and is required for employment. CSU will make a conditional offer of employment, which may be rescinded if the background check reveals disqualifying information, and/or it is discovered that the candidate knowingly withheld or falsified information. Failure to complete the background check satisfactorily may affect the continued employment of a current CSU employee who was conditionally offered the position.

Preferred Qualifications: Master’s degree in information assurance, cybersecurity, public administration, business administration, law, or a related field. Professional certification(s) in one or more of the following: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Cybersecurity and Infrastructure Security Agency (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in the Governance of Enterprise IT (CGEIT), Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Data Privacy Solutions Engineer (CDPSE), or equivalent. Experience working in higher education, particularly within the California State University (CSU) system or another large public university environment. Direct experience serving as a CISO, Chief Privacy Officer, or equivalent senior executive in cybersecurity, compliance, or risk. Experience with audit response and engagement with internal, external, and systemwide auditors.

About the company

Cal State Fullerton is a leading campus of the CSU, serving as an intellectual and cultural center for Southern California and driver of workforce and economic development. We are an emerging national model for supporting student success through innovative high-impact educational and co-curricular experiences, including faculty-student collaborative research.

California State University, Fullerton offers a comprehensive and competitive benefits package. From our health plans and continuing education opportunities to our flexible spending accounts, survivor protection, leave programs and competitive retirement/savings plans, the CSU offers benefits that matter to you at each stage of your career.

Cal State Fullerton recognizes the balance of work and personal challenges. We support these multiple roles, promote flexibility, and strive to enhance the overall experience for our employees.

At Cal State Fullerton, we take immense pride in our campus, where every employee is driven by a shared purpose: to transform lives through the power of education. We are committed to fostering an exceptional employee experience where you will be a catalyst for change.

California State University, Fullerton (CSUF) is a diverse community of individuals who represent many perspectives, beliefs and identities, committed to fostering an inclusive, respectful, and intellectually vibrant environment. We cultivate a culture of open dialogue, mutual respect, and belonging to support educational excellence and student success. Through academic programs, student organizations and activities, faculty initiatives, and community partnerships, we encourage meaningful engagement with diverse perspectives. As a higher education institution, we are dedicated to advancing knowledge and empowering individuals to reach their full potential by prioritizing inclusive curriculum development, faculty and staff training, student mentorship, and comprehensive support programs. At CSUF, excellence is built on merit, talent, diversity, accessibility, and equal opportunity for all.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.chronicle.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 ¡ World Congress 2024

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah ¡ World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 ¡ LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell ¡ World Congress 2026 Europe

Videos

See all

Related articles

See all