Job description
Job no: 531644
Work type: Officer of Administration
Location: Eugene, OR
Categories: Executive/Management/Director, Information Technology
Department:Information Services
Department: Information Services
Appointment Type and Duration: Regular, Ongoing
Salary: Commensurate with experience
Compensation Band: OS-OA13-Fiscal Year 2022-2023
FTE: 1
Application Review Begins
May 15, 2023; position open until filled
Special Instructions to Applicants
The University of Oregon has engaged Opus Partners to assist this search. Craig Smith, Partner, and Jeffrey Stafford, Senior Associate, are leading the search. To seek additional information, or nominate qualified candidates, please email Jeffrey Stafford at Jeffrey.stafford@opuspartners.net. To be considered for the position, candidates must formally apply via Opus Partners and must provide a resume and cover letter addressing the responsibilities, expectations, and requirements of the role.
Department Summary
Information Services (IS) is the central information technology organization at the University of Oregon, delivering a broad range of technology and services to the University. IS consists of four major functional areas, each led by a direct report to the VP-CIO: Customer Experience, which serves as the key contact point for interactions with campus clients and customers; Enterprise Solutions, which manages and supports applications, integration services, identity management and data management; Information Security, which helps protect virtual or physical information; and Technology Infrastructure, which provides engineering and support for research IT services and high-performance computing, networking, compute, storage, voice, data centers, audio-visual and classroom technologies, and UO staff supporting Link Oregon, Oregon’s state-wide research and education network.
IS has developed its IT governance practices to sustain alignment between University priorities and its values, resources, and measures of success. The IT Steering Committee, the highest governance entity, helps IS leadership continue to position the organization for optimal impact.
UO Information Security Office
ISO comprises four teams, each focusing on a set of principles and practices established by the NIST Cybersecurity Framework (v.1.1) that Information Services has established as the operational framework for the University’s approach to information security:
Information Security Services & Operations (ISSO) –
ISSO focuses on the identify, protect, and detect functions of the NIST cybersecurity framework. The ISS deploys technologies to protect the University’s resources and communication channels. This team oversees the identification of institutional assets, updates their risk representation, and provides services to protect them. Programs managed by this function include vulnerability management, email security and phishing protection, threat defense tools like intrusion defense (IDS) and intrusion protection (IPS) systems, security incident event management (SIEM). The ISS team works with the community to advise regarding the buildout and operation of secure infrastructure to support the university academic, research, and administrative missions.
Cyber Security Operations Center (CSOC) –
CSOC focuses on the detect, respond, and recover functions of the NIST framework. The CSOC manages the University threat-intelligence feeds for indications of compromise, threat hunting, starting incident-response functions, and guiding the recovery after an incident. The group is staffed using university students who rotate through three roles: a) CSOC Analyst, b) Incident Response Analyst and c) Compliance Analyst, during the time they are part of the group.
Information Security Risk & Compliance (ISRC) –
ISRC focuses on supporting all five functions of the NIST cybersecurity framework from the point of view of compliance and controls development. The ISRC works on the creation of policies, standards, controls, guidelines, and procedures that support the information security program. The group works with the University contracts management teams in performing risk and compliance capabilities assessments related to information security for third-party vendors and research contracts. In addition, the team manages UO’s cybersecurity awareness and training program and collaborates with compliance management for GLBA, HIPAA, FERPA, PCI, Red Flag, NIST, and other regulatory requirements relevant to the University.
Information Technology Disaster Recovery (ITDR) Program –
ITDR is a new function of the ISO created in 2022 as the result of one of the objectives identified during an internal information security program review. The ITDR function will define the set of procedures and supporting documentation that enables the University to restore core IT services as part of its overall business continuity plan. The program will identify critical applications and dependencies, define an appropriate (and desired) recovery timeline based on a business impact analysis, and create a step-by-step incident-response plan for those critical applications. The program manager assigned to this function will work with all IT solutions and services providers to build IS’ ITDR plan and make it actionable.
The Information Security Office works closely with other areas within Information Systems. Chief among these are Enterprise Solutions, which is responsible for identity and access management; Customer Experience, which includes endpoint management; and Technology Infrastructure, which has operational responsibility for network security. The CISO works closely with the peers who lead these areas on strategy and on shared commitments to implementation.
ISO’s annual expense budget, including payroll, is $3M. Its professional staff sustain hybrid working arrangements and are supported by ~12 students who work largely in the cybersecurity operations center. The University has invested significantly in ISO resources over the last several years in terms of both staff and systems as well as student support.
A subcommittee of the IT Steering Committee, the Information Security and Privacy Governance subcommittee, enables the Chief Information Security Officer to understand, shape, and align with overall governance and University priorities and initiatives.
Position Summary
Collaborating broadly with administrative and business functions across the University, the CISO sustains overall responsibility for developing and maintaining the University’s information security road-map for ensuring the security of campus-wide technology services, computer systems, data networks, and data. With colleagues in IS leadership, the CISO also develops and oversees effective disaster-recovery policies and standards to align with enterprise business-continuity management program goals. The CISO oversees the development of implementation plans and procedures to ensure that business-critical services are recovered in the event of a security event. In addition, the CISO provides direction, support, and in-house consulting in these areas.
The CISO will develop and lead outreach, communication, and education efforts to raise campus-wide awareness of information security risk, requirements, and solutions; provide strategic and technical guidance and assistance in the design and implementation of appropriate security processes for campus- wide information systems; recommend and monitor computing practices to prevent and recover from security breaches; and oversee the response to breaches when they occur.
The CISO serves as the primary information security liaison to federal, state, local, and professional organizations. This position serves on the Information Services (IS) Leadership Team and supervises information-security staff, leads cross-functional teams, and manages the budget of the Information Security Office.
In addition to their work with IT governance, the CISO contributes to overall University planning around enterprise risk management through their engagement with the Strategic Enterprise Risk Management and Compliance (SERMC) Committee, chaired by the University’s VP & Chief Resilience Officer, and its workgroups. The CISO also leads the University Data Security Incident Response Team. In addition to the CISO, its members include a member of the Office of General Counsel, the University Registrar, HIPAA Compliance Officer, Chief Human Resources Officer, AVP for Business Affairs, Media Relations, and Chief Auditor, and a representative of the Office of Safety & Risk Services.
Responsibilities
Leadership
- Provide vision and leadership to ensure the University’s information security and identity management programs achieve the mission of adequately protecting information assets, appropriately balancing security strategies and University priorities in ways consistent with the risk posture of the University and incorporating evolving directions and best practices in information security and identity management consistent with industry standards
- Embrace accountability for the enterprise information-security environment, including the development of policy, standards, and metrics for evaluating the effectiveness of cybersecurity controls
- Advise the CIO and other University leaders on emerging legal and policy dimensions of information security and of current and emerging cybersecurity risks to the University’s mission, reputation, and operation
- Establish a roadmap for continual program improvements, metrics to track progress, and related reporting mechanisms
- Report to UO senior management on the status of the University’s information-security programs, risk awareness, events and incidents, and trends
- Stay abreast of information security issues and trends, emerging solutions, and regulatory changes, especially those affecting higher education, and incorporate all into strategic direction-setting and resource deployment
- Report regularly to the University community on developments in information security to increase understanding of, engagement in, and compliance with established standards and emerging best practices in information security and identity management
Collaboration
- Maintain a close working relationship with key University Offices, including the Office of General Counsel, Safety and Risk Services, Human Resources, Research, Communications, Procurement, and Advancement to review information security and identity management programs in light of legal and other business considerations and to enhance institutional focus on strategically conceived, sustainably implemented programs that effectively manage the University’s cyber risks
- Set priorities for and direct the investigation and implementation of new information-security solutions that have a university-wide impact
- Ensure that ISO is contributing to efficient and effective evaluation of vendors whose solutions and services create risk to the University or may impact the University’s management of risk
- Advise on the design and value of cyberinsurance policies and of risk-mitigation activities that complement third-party coverages
- Serve as a subject matter expert for regulatory requirements and compliance issues as applied to technology (e.g. DMCA, FISMA, FERPA, GDPR, HEOA P2P, HIPAA, HITECH, PCI)
- Represent the University in national conversations relevant to information security and identity management where the benefits realized through knowledge-sharing, resource development, and vendor engagement rebound to UO
Service Delivery
- Manage the overall direction and priorities of the information-security program, including policy development, awareness, security assessments, vendor risk evaluation, risk mitigation, network traffic analysis, and regulatory compliance
- Establish identity standards and practices suitable for diverse communities interacting with University systems and services and ensure the application of University identity-management policies, procedures, and practices
- Advise campus-wide stakeholders on managing effective security and identity management practices, designing and implementing engaging education and training programs to deliver information
- Lead the University’s response during a significant security incident and effectively engage with and provide updates to highest-level stakeholders
- Work with schools, divisions, and institutes to ensure the protection of data in compliance with University policy
Management
- Ensure the staff in the Information Security Office experience IS, and the University of Oregon more broadly, as a stimulating and rewarding environment in which they can develop professionally and personally according to their abilities and ambition
- Provide guidance and direction to ISO staff, demonstrating the expected standard for technological excellence and a professional, customer-focused approach
- Continue to develop the culture and values of the ISO to align with and contribute to the University’s initiatives in diversity, equity, and inclusion
- As a member of the IS Leadership Team contribute to its ongoing development, excellence, and ongoing maturation as UO’s enterprise IT organization
- Perform various management functions related to unit management including budgeting, procurement, contract negotiations, and personnel evaluations and actions
Minimum Requirements
- Master’s degree and 8 years of related experience, or a bachelor’s degree and 10 years of related experience, or an equivalent combination of related education and experience
Professional Competencies
- Knowledge of management and administration principles and practices for managing direct reports along with effective interpersonal communication, human relations, and team-building skills
- Extensive background in and understanding of the spectrum of information technologies relevant to a research university and of the place of information security within enterprise investments in information technology systems, services, and staff
- Broad and current grasp of information security risks, challenges, developments, and best practices
- The ability to build and navigate relationships with a broad array of constituents
- A track record of advancing equity, inclusivity, and diversity in and through the staff and activities of an information-technology organization
- Proven ability to develop and assess budgets, technical proposals, contracts, and applicable institutional policies
- Track record of excellent customer service and support
- Knowledge of relevant information systems and project management principles and practices
- Demonstrated negotiation skills
- Ability to develop cooperative agreements and MOUs/SLAs with appropriate partners
- Ability to explain technical issues and policies to non-technical stakeholders
- Effective communication skills
Preferred Qualifications
- Information-security leadership experience in a research university environment
- Professional credentials relevant to information security (CISSP, etc.)
FLSA Exempt: Yes
All offers of employment are contingent upon successful completion of a background inquiry.
University of Oregon students and employees are required to be vaccinated against COVID-19. For additional information see: https://hr.uoregon.edu/uo-covid-19-vaccination-requirement-employee-process.
The University of Oregon is proud to offer a robust benefits package to eligible employees, including health insurance, retirement plans and paid time off. For more information about benefits, visit http://hr.uoregon.edu/careers/about-benefits.
The University of Oregon is an equal opportunity, affirmative action institution committed to cultural diversity and compliance with the ADA. The University encourages all qualified individuals to apply, and does not discriminate on the basis of any protected status, including veteran and disability status. The University is committed to providing reasonable accommodations to applicants and employees with disabilities. To request an accommodation in connection with the application process, please contact us at uocareers@uoregon.edu or 541-346-5112.
UO prohibits discrimination on the basis of race, color, sex, national or ethnic origin, age, religion, marital status, disability, veteran status, sexual orientation, gender identity, and gender expression in all programs, activities and employment practices as required by Title IX, other applicable laws, and policies. Retaliation is prohibited by UO policy. Questions may be referred to the Title IX Coordinator, Office of Civil Rights Compliance, or to the Office for Civil Rights. Contact information, related policies, and complaint procedures are listed on the statement of non-discrimination.
In compliance with federal law, the University of Oregon prepares an annual report on campus security and fire safety programs and services. The Annual Campus Security and Fire Safety Report is available online at https://clery.uoregon.edu/annual-campus-security-and-fire-safety-report.
Advertised: 17 Apr 2023 Pacific Daylight Time
Applications close:
abouteureka.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, abouteureka.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, abouteureka.com is the ideal place to find your next job.