Full-Time

Assistant Vice President

Information Security

University of Tampa

University of Tampa

Private university in Tampa, FL

No salary listed

Tampa, FL, USA

In Person

Occasional evenings and weekends may be required.

Bachelor's, Master's

Category
IT & Security (1)
Required Skills
Incident Response
ISO/IEC 27001
Vulnerability Analysis
Penetration Testing
Data Governance

Get referred to University of Tampa

See people who can refer or advise you

Requirements
  • A bachelor's degree in Information Technology, Cybersecurity, or a related field is required.
  • Ten years of varied information technology experience, including extensive supervisory experience and at least seven years of directly related information security experience, is required.
  • A Certified Information Systems Security Professional certification or an equivalent information security professional certification is required.
  • Demonstrated success developing and executing an information security strategy, including presenting to executive- or board-level audiences, is required.
  • Working knowledge of the security implications of enterprise artificial intelligence adoption and artificial-intelligence-enabled threats, with the ability to translate them into practical policy and controls, is required.
  • Deep working knowledge of the regulatory landscape governing higher education information security, including the Gramm-Leach-Bliley Act, Family Educational Rights and Privacy Act, Health Insurance Portability and Accountability Act, and Payment Card Industry Data Security Standard, is required.
  • Familiarity or experience with ISO/IEC 27001:2022, ISO/IEC 22301:2019, and ISO/IEC 20000-1:2018 management systems, with the ability to become certified as a Lead Auditor in each, is required.
  • Strong leadership and supervisory skills, including the ability to delegate effectively and develop staff capable of owning operations, are required.
  • A collaborative and approachable working style, including building trust across departments and working as a partner rather than an enforcer, is required.
  • A fast, decisive working pace with strong follow-through and the ability to make sound decisions with incomplete information is required.
  • Demonstrated skills in budget development, financial management, and resource management are required.
  • Excellent oral and written communication skills, including the ability to explain complex security topics to non-technical audiences, are required.
  • Excellent organizational and time management skills, including the ability to prioritize and manage multiple projects simultaneously and meet established deadlines, are required.
  • Willingness to embrace new technologies and innovative organizational practices is required.
Responsibilities
  • Own and maintain the university's multi-year information security strategy and roadmap, aligning it with institutional goals, the enterprise risk register, and the realities of a private residential four-year university environment.
  • Set and sequence security priorities using risk-based judgment, distinguishing initiatives requiring direct leadership from those that should be delegated to staff.
  • Communicate security posture, risk trends, and program progress to the Vice President and Cabinet-level audiences in clear, non-technical, decision-ready terms.
  • Integrate security considerations into strategic and tactical planning, budget preparation, and major initiatives across Information Technology and Security and the university.
  • Develop the annual security budget and multi-year investment plan, make trade-off recommendations, and demonstrate return on security investment.
  • Continuously scan emerging threats, technologies, and higher education security trends and translate them into prioritized university actions.
  • Partner with university artificial intelligence governance efforts on acceptable-use policy, data-classification guidance, and review and approval of artificial intelligence platforms and integrations.
  • Build and mature defenses against artificial-intelligence-generated phishing, deepfake-driven social engineering and fraud, and automated credential attacks.
  • Assess the security implications of enterprise artificial intelligence adoption, including generative artificial intelligence platforms, artificial intelligence agents, and artificial intelligence features embedded in vendor products, and establish proportionate controls.
  • Evaluate and adopt responsible uses of artificial intelligence within the security program, including artificial-intelligence-assisted detection, response, and security awareness capabilities.
  • Lead third-party and vendor artificial intelligence risk reviews as part of technology approval and procurement processes.
  • Coordinate the development, implementation, and administration of security policies, standards, and programs for Information Technology and Security and other university areas.
  • Lead the Computer Security Incident Response Team and co-lead the Business Continuity Emergency Incident Response Team, ensuring plans are tested, current, and understood.
  • Oversee a defensive posture spanning identity and access management, cloud and software-as-a-service security, endpoint protection, email security, data loss prevention, and vulnerability management, with progress toward zero-trust principles.
  • Coordinate assessments of systems and network security risks, including risk analysis, threat assessments, and contingency planning.
  • Complete incident reports and investigations of policy violations and suspected material incidents, including required regulatory notifications.
  • Participate in Information Technology and Security project development to ensure security best practices are incorporated from the start.
  • Manage the ISO/IEC 27001 Information Security Management System, maintaining and improving documentation, processes, policies, plans, and corrective actions.
  • Compile evidence of compliance with regulations and requirements affecting the university, including the Gramm-Leach-Bliley Act, Family Educational Rights and Privacy Act, Health Insurance Portability and Accountability Act, Payment Card Industry Data Security Standard, and applicable data privacy laws.
  • Participate in annual audits, penetration tests, third-party security assessments, Payment Card Industry compliance audits, and Gramm-Leach-Bliley Act audits.
  • Oversee security awareness programs, including artificial-intelligence-era threat education, for students, faculty, and staff.
  • Build, develop, and retain a high-performing security team, delegate operational ownership with clear accountability, and coach staff toward greater autonomy.
  • Serve as a visible member of the Information Technology and Security leadership team and a partner to departments across campus.
  • Facilitate and direct the timely dissemination of security information to the university community.
  • Contribute to a work environment that supports respect for and development of skills related to other cultures and backgrounds.
  • Attend conferences and training as required to maintain proficiency.
Desired Qualifications
  • A master's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
  • Additional security certifications such as Certified Information Security Manager, Certified Cloud Security Professional, Certified in Risk and Information Systems Control, Global Information Assurance Certification, or artificial-intelligence-security-related credentials.
  • Experience with artificial intelligence governance frameworks such as the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework or ISO/IEC 42001, or hands-on evaluation of enterprise artificial intelligence platforms.
  • Experience with cloud security architecture, identity-centric security models, and zero-trust implementation.
  • Knowledge of data privacy legislation such as the General Data Protection Regulation and state privacy laws, and data governance practices.
  • Computer forensics or incident response leadership experience.
  • Experience supporting Health Insurance Portability and Accountability Act compliance in a campus health or clinic setting, including business associate and covered-entity considerations.
  • Higher education experience.

University of Tampa is a private university in Tampa, Florida. It offers undergraduate and graduate programs across liberal arts, sciences, business, and professional fields.

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

Get referred to University of Tampa

See people who can refer or advise you