Deputy Chief Information Security Officer
Western Carolina University
Deputy Chief Information Security OfficerApplication materials must be submitted online. Review of applications will begin immediately and will continue until a candidate has been selected for hire. In order to complete the application, applicants must include: a cover letter addressing qualifications as related to the job requirements, a current resume, a list of three recent (within past five years) professional references which include name, title, email, and relationship. For questions or additional information please contact View email address on click.appcast.io primary location of this position is on-site in Cullowhee, NC. This position is designated as being exempt from the State of North Carolina Human Resources Act (EHRA). The Deputy Chief Information Security Officer (DeputyCISO) reports to the Chief Information Security & Privacy Officer. The position provides senior operational and program leadership for the IT Security Office and serves as the principal delegate for assigned security matters. The DeputyCISO translates institutional security and privacy priorities into coordinated operations, supports continuity of leadership, and works across the Division of IT and the university to reduce technology risk.The DeputyCISO leads or coordinates security governance, risk assessment, regulatory and standards compliance, security awareness, security operations oversight, and security review of technology projects and third-party services. The DeputyCISO advises technical and non-technical stakeholders, documents risk-based recommendations, tracks corrective actions, and escalates significant risks and incidents to the CISPO.Technology risk assessments across university systems, business units, and third parties. This includes maintaining the enterprise risk register, developing assessment methodologies, and ensuring risks are documented with accountable owners and remediation plans.Audit preparation and response, including internal audit engagements, external audits, and reviews conducted by the Office of the State Auditor. The DeputyCISO serves as the primary coordinator for audit evidence, response, and remediation tracking.Regulatory compliance across the frameworks that apply to the university, including the FTC Safeguards Rule (GLBA), FERPA, UNC System policies, and applicable state and federal requirements. The DeputyCISO maintains the compliance mapping and reporting cadence.The human risk program, including phishing simulations, security awareness training, and security communications to the university community.The technology risk governance framework, including the development and maintenance of information security policies, standards, and control frameworks aligned to recognized industry frameworks such as NIST CSF and CIS Controls.Minimum Qualifications: Bachelor's degree in cybersecurity, computer science, information systems, business analytics, or a related field. Five years of progressively responsible experience across multiple information security functions, such as governance, risk, compliance, security operations, incident response, identity and access management, infrastructure security, or third-party risk. Demonstrated experience coordinating complex security initiatives across technical teams and business units. Working knowledge of networking, systems administration, endpoint security, identity and access control, cloud or hosted services, vulnerability management, and incident response practices. Experience developing or implementing security policies, risk assessments, control documentation, audit responses, or remediation plans. Excellent oral, written, and interpersonal communication skills, including the ability to explain technical concepts and risk in non-technical terms. Strong analytical, organizational, and problem-solving skills; ability to manage concurrent priorities with appropriate attention to detail. Ability to obtain and maintain CISSP certification within eighteen months of appointment if not already certified.Preferred Qualifications: Master's degree in cybersecurity, information systems, business administration, or a related field. More than seven years of progressively responsible information security experience, including program or team leadership. Current CISSP certification; additional relevant certification such as CISM, CRISC, GIAC, or a privacy credential. Experience in higher education, government, or another complex regulated environment. Experience with ISO 27002, ISO 27701, NIST Cybersecurity Framework, NIST security controls, PCI DSS, HIPAA, GLBA, or comparable requirements. Experience supporting security incidents, audits, executive briefings, third-party risk assessments, and risk-register governance.Position Type: Permanent Full-TimeNumber of Hours Per Week: 40Number of Months Per Year: 12Open Date: 08/24/2026Close DateOpen Until Filled: YesBackground/E-Verify: Final candidates are subject to criminal & sex offender background checks. Some vacancies also require credit or motor vehicle checks. Western Carolina University uses E-Verify to confirm employment eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit Proper documentation of identity and employability are required at the time of employment.Credential Verification: All new employees are required to have listed credentials/degrees verified within 30 days of employment. All new employees who will be teaching are required to provide official transcripts within 30 days of employment. Transcripts should be provided for the highest earned degree and/or the degree which is being used to satisfy credential/qualification requirements.EOE: Western Carolina University is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race; color; ethnicity; religion; sex; pregnancy; sexual orientation; gender identity or expression; national origin; age; disability; genetic information; political affiliation; National Guard or veteran status, consistent with applicable federal, state and local laws, regulations, and policies, and the policies of The University of North Carolina. Persons with disabilities requiring accommodations in the application and interview process please call View phone number on click.appcast.io or email at View email address on click.appcast.io Safety: The Western Carolina University Annual Safety Report is available online at University Annual Safety Report or in hard-copy by request at the office of the Vice Chancellor for Student Affairs, 227HFR Administration Building, Cullowhee, NC 28723 View phone number on click.appcast.io) or the Office of University Police, 111 Camp Annex, Cullowhee, NC 28723 View phone number on click.appcast.io). The report, required of all universities participating in Title IV student financial aid programs, discusses crime statistics, procedures for reporting suspicious or criminal activity, security, police authority, crime prevention strategies, university policies on substance abuse and sexual offenses, workplace violence and fire safety.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Deputy Chief Information Security Officer. Be the first to apply!
