Role Snapshot
The Deputy Chief Information Security Officer provides senior operational and program leadership for the IT Security Office at Western Carolina University, serving as the principal delegate for assigned security matters and supporting the Chief Information Security & Privacy Officer. This role translates institutional security and privacy priorities into coordinated operations while reducing technology risk across the division and university.
Key Responsibilities: Lead or coordinate security governance, risk assessment, regulatory compliance, security awareness programs, and security review of technology projects and third-party services. Manage technology risk assessments, audit preparation and response, regulatory compliance tracking, incident coordination, and policy development to drive remediation sequencing and investment decisions across IT.
Skills & Tools: Security leadership and operational judgment, governance and risk assessment expertise, incident coordination and decision support, policy development, third-party and project security review capabilities, and clear executive and technical communication skills. Strong collaboration, customer service orientation, and planning and accountability capabilities required.
Qualifications: Not specified in job description. Typically requires 7+ years of information security experience with demonstrated leadership in risk management, compliance, and security governance frameworks such as NIST CSF and CIS Controls.
Compensation: $180K–$280K/yr (estimated)
Job Description
The primary location of this position is on-site in Cullowhee, NC. This position is designated as being exempt from the State of North Carolina Human Resources Act (EHRA).
The Deputy Chief Information Security Officer (Deputy CISO) reports to the Chief Information Security & Privacy Officer. The position provides senior operational and program leadership for the IT Security Office and serves as the principal delegate for assigned security matters. The Deputy CISO translates institutional security and privacy priorities into coordinated operations, supports continuity of leadership, and works across the Division of IT and the university to reduce technology risk.
The position leads or coordinates security governance, risk assessment, regulatory and standards compliance, security awareness, security operations oversight, and security review of technology projects and third-party services. The Deputy CISO advises technical and non-technical stakeholders, documents risk-based recommendations, tracks corrective actions, and escalates significant risks and incidents to the CISPO.
Description of Work
The Deputy Chief Information Security Officer (Deputy CISO) reports to the Chief Information Security & Privacy Officer. The position provides senior operational and program leadership for the IT Security Office and serves as the principal delegate for assigned security matters. The Deputy CISO translates institutional security and privacy priorities into coordinated operations, supports continuity of leadership, and works across the Division of IT and the university to reduce technology risk.
The position leads or coordinates security governance, risk assessment, regulatory and standards compliance, security awareness, security operations oversight, and security review of technology projects and third-party services. The Deputy CISO advises technical and non-technical stakeholders, documents risk-based recommendations, tracks corrective actions, and escalates significant risks and incidents to the CISPO.
Description of Work
- Technology risk assessments across university systems, business units, and third parties. This includes maintaining the enterprise risk register, developing assessment methodologies, and ensuring risks are documented with accountable owners and remediation plans.
- Audit preparation and response, including internal audit engagements, external audits, and reviews conducted by the Office of the State Auditor. The Deputy CISO serves as the primary coordinator for audit evidence, response, and remediation tracking.
- Regulatory compliance across the frameworks that apply to the university, including the FTC Safeguards Rule (GLBA), FERPA, UNC System policies, and applicable state and federal requirements. The Deputy CISO maintains the compliance mapping and reporting cadence.
- The human risk program, including phishing simulations, security awareness training, and security communications to the university community.
- The technology risk governance framework, including the development and maintenance of information security policies, standards, and control frameworks aligned to recognized industry frameworks such as NIST CSF and CIS Controls.
- The Deputy CISO's work directly informs prioritization for the broader technology organization. The risk view produced by the function drives remediation sequencing, planning priorities, and investment decisions across IT.
Required Knowledge, Skills, and Abilities
- Security leadership and operational judgment
- Governance, risk, compliance, and control assessment
- Incident coordination and decision support
- Policy and procedure development
- Third-party, software, and project security review
- Clear executive, technical, and campus communication
- Collaboration, consultation, and customer service
- Planning, prioritization, documentation, and accountability

