Chief Information Security Officer
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Job Description
The University of Alberta has engaged DHR International Canada Inc. to manage this search. Reporting to the Chief Information Officer (CIO), Associate Vice-President of Information Services & Technology (IST), the Chief Information Security Officer (CISO) provides leadership to discrete functions, operations, programs or services within the cybersecurity and IT compliance areas of the university. The CISO is a Director within IST, reporting to the CIO alongside the other IST portfolio directors, and works in close collaboration with them so that security is built into how systems and services are designed, implemented and supported. Directors are expected to generate excitement, engagement, support and momentum for their area’s initiatives. As leaders, they straddle the worlds of operational and strategic leadership, translating strategic vision into operational/action plans for their staff.
The CISO leads the development and implementation of a comprehensive security strategy to safeguard University assets, information, and infrastructure. This role operates within a complex academic environment, supporting institutional goals while ensuring compliance with regulatory requirements and emerging security threats. The University of Alberta is an internationally recognized institution and with extensive research programs and as such this role will need to understand regional, national and international cybersecurity policies and trends. Artificial intelligence is reshaping both the threat landscape and the university’s operating environment. The CISO will lead the institution’s approach to securing and governing its use across teaching, research and administration, while enabling the innovation that AI makes possible.
Responsibilities
Key Accountabilities
Leader (Operations/Program/Service)
- Develop, analyze, oversee, and continuously improve the security architecture and control framework that protect the university’s information, systems and research, and support the organization’s goals and service needs;
- Execute a comprehensive, clear cybersecurity strategy that exhibits effective planning and ensures agility;
- Establish a multi-year cybersecurity roadmap that supports maturing the security function, services, and partnerships across the university;
- Set cybersecurity standards in consultation with IST leaders, faculties and other stakeholders, ensuring the standards are practical to implement and that the university is enabled to meet them;
- Partner with the CIO and other university leaders to enable secure and responsible adoption of artificial intelligence and machine learning technologies, including AI risk assessment, security review and guardrails for their use;
- Collaborate with other leaders to identify opportunities to innovate service delivery, develop information capabilities, and improve operational performance and processes;
- Oversee the security of IT infrastructure, cloud services, and software development ensuring cost effectiveness, efficiency, integration, security, accessibility, and sustainability;
- In collaboration with university partners, lead investigations into real and potential IT threats and breaches;
- Track, analyze, and monitor technology performance metrics to continually improve performance outcomes and deliverables;
- Provide senior leadership and expertise in the development of information technology policies and procedures;
- Establish and lead security governance for artificial intelligence, including risk assessment of AI tools and vendors, safeguards for institutional and research data used with generative and agentic AI, monitoring for unsanctioned AI use, and alignment with recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001);
- Prepare the university for AI-enabled threats, such as AI-generated phishing and impersonation and the faster discovery and exploitation of software vulnerabilities, and apply AI responsibly to strengthen threat detection, response and team capacity;
- Lead cybersecurity awareness and education programs for students, faculty and staff, including the safe and responsible use of AI tools;
- Partner with the Safeguarding Research Office to ensure cybersecurity is properly managed in the research context, including protection of sensitive research and support for federal research security requirements such as the Policy on Sensitive Technology Research and Affiliations of
- Concern, while preserving academic openness;
- Provide executive oversight of third-party and supply chain risk, business continuity and disaster recovery, and ransomware resilience programs; and
- Set identity and access management and zero trust principles for the university, in partnership with IST and faculty IT teams.
Strategic Influencer
- Contribut