Chief Information Security, Compliance and Risk Officer/CISO
Auto Req. ID: 561240
About the Role
California State University, Fullerton (Cal State Fullerton) is a leading public university committed to student success, academic excellence, and inclusive excellence. The university fosters a collaborative environment that supports teaching, research, and service while promoting innovation and professional growth. Cal State Fullerton is both a Hispanic-Serving Institution and an Asian American and Native American Pacific Islander-Serving Institution, and a recipient of the Seal of Excelencia (2021 and 2024) from Excelencia in Education.
The Division of Information Technology (IT) strives to be a strategic, innovative, and best-in-class IT organization that provides a leading-edge technology environment for students, faculty, and staff to advance the University’s mission, vision, and goals. We are seeking an exceptional individual to join our IT Information Security department as the Chief Information Security, Compliance and Risk Officer/CISO (Administrator III). The ideal candidate should have a positive attitude, an active, energetic mind, and a leadership style characterized by highly ethical practices and a commitment to inclusivity, openness, flexibility, integrity, and kindness.
Responsibilities
- Plan, develop, implement, and monitor the institutional information security, privacy, digital compliance, and cyber risk programs.
- Oversee the institutional cyber risk management, policy, and governance program.
- Work collaboratively with campus partners to establish campus security standards, coordinate audit responses, and corrective actions, and oversee third-party and cloud risks.
- Own the cybersecurity incident response program, lead executive-level response to high-impact incidents, and provide guidance for business continuity and disaster recovery.
- Establish and report meaningful measures of program effectiveness.
- Direct campus-wide security, privacy, compliance, and risk awareness training and communication.
- Serve as a campus representative to the Cal State University (CSU) System on matters related to information security, privacy, and accessibility.
- Establish and steward the multi-year vision, strategy, and capability roadmap for security, privacy, compliance, and risk across the University, aligned with CSU systemwide policy, applicable regulatory frameworks, and campus strategic priorities.
- Lead the Information Security and Compliance Office, investing in workforce development and service delivery, and build the office's multi-year resource forecast, including funding, staffing, and tools.
- Handle highly confidential and sensitive institutional information and may participate in emergency or crisis-management activities.
- Other duties as assigned.
Requirements
- Bachelor's degree from an accredited four-year college or university in computer science, information systems, cybersecurity, public administration, business administration, or a related field.
- Eight or more years of progressively responsible experience in information security, cyber risk, or IT compliance, including significant leadership experience managing teams and programs.
- Demonstrated experience setting strategic direction and roadmap for a cybersecurity, compliance, or risk program in a complex, multi-stakeholder environment.
- Demonstrated knowledge of information security and privacy regulations and frameworks applicable to higher education (e.g., Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act (GLBA), Payment Card Industry Data Security Standard (PCI DSS), California Consumer Privacy Act (CCPA), General Data Protection Regulation (GDPR), National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF), NIST 800-53, International Organization for Standardization (ISO) 27001).
- Experience leading or supporting cybersecurity incident response at an executive level, including coordination with legal, communications, and external partners.
- Demonstrated ability to translate complex technical, policy, and regulatory concepts into clear guidance for executive leadership and non-technical audiences.
- Strong interpersonal, written, and verbal communication skills, including the ability to facilitate cross-functional collaboration and build consensus.
- A background check (including a criminal records check) must be completed satisfactorily and is required for employment.
Preferred Qualifications
- Master's degree in information assurance, cybersecurity, public administration, business administration, law, or a related field.
- Professional certification(s) in one or more of the following: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Cybersecurity and Infrastructure Security Agency (CISA), Certified in Risk and Information Systems Control (CRISC), Certified in the Governance of Enterprise IT (CGEIT), Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), Certified Data Privacy Solutions Engineer (CDPSE), or equivalent.
- Experience working in higher education, particularly within the California State University (CSU) system or another large public university environment.
- Direct experience serving as a CISO, Chief Privacy Officer, or equivalent senior executive in cybersecurity, compliance, or risk.
- Experience with audit response and engagement with internal, external, and systemwide auditors.
License/Certifications
- A valid California driver’s license.
Pay
Classification Range: $6,891 - $22,119 per month (Hiring range depending on qualifications, not anticipated to exceed $14,500 - $17,700 per month).
Schedule
Monday - Friday, 8:00 AM - 5:00 PM; occasional early morning, evening and/or weekend hours.
Benefits
- An array of health plans that include prescription drug coverage
- Dental and Vision coverage
- Income protection benefits including life insurance and disability
- Retirement plan through CalPERS
- Tuition waiver for employees and dependents if eligible
- FlexCash (in lieu of health and dental)
- Employee Assistance Programs
- 15 paid holidays