Assistant Vice President, Information Security

Posted 2 Days Ago
Be an Early Applicant
Tampa, FL, USA
In-Office
Expert/Leader
Edtech • Professional Services
The Role
Lead and execute a multi-year university information security strategy, manage the ISMS (ISO/IEC 27001), direct incident response and CSIRT, assess AI and third-party risks, ensure regulatory compliance (GLBA, FERPA, HIPAA, PCI DSS), oversee security operations and awareness, build and develop a high-performing security team, and communicate security posture to executive and board-level audiences.
Summary Generated by Built In
If you are a current University of Tampa student, please search for and apply to student jobs here via Workday. Job applications for current students will not be considered if submitted through the external career center.

Position Details

Information Technology and Security at The University of Tampa has a position available for an Assistant Vice President, Information Security, reporting to the Vice President, Information Technology and Security. The AVP is responsible for assisting the VP information Technology & Security (CIO/CISO) with establishing and executing a multi-year security strategy that protects students, faculty, staff, and institutional data in a threat landscape increasingly shaped by artificial intelligence, identity-based attacks, and third-party risk.  This role handles executive duties such as briefing cabinet or board members, leading the ITS CCIRT team and major incident investigations in a collaborative team environment.  It calls for a keen understanding of the intersection between business, academic and security requirements as well as evaluating technology solutions that departments wish to purchase, setting risk-based criteria that enables innovation and productivity.  Additionally, this position leads or participates in audits, conducts risk assessments, and creates corrective actions or improvements to optimize the information security program, procedures, or data protection.  

This is a strategy-first leadership role. The AVP leads the Information Security department and the university's certified ISO/IEC 27001 Information Security Management System (ISMS), but success in this position is measured by the ability to anticipate where risk is moving, align security investments with institutional priorities, and communicate clearly with executive-level audiences — not solely by day-to-day operational execution, which the AVP is expected to build a team capable of running.

This position is designated as an essential employee and may be required to report to work as scheduled when university offices are closed due to severe weather or other conditions.

Strategic Leadership
•    Owns and maintains the university's multi-year information security strategy and roadmap, aligning it with institutional goals, the enterprise risk register, and the realities of a private, residential, four-year university environment.
•    Sets and sequences security priorities using risk-based judgment: distinguishing the initiatives that require the AVP's direct leadership from those that should be delegated to capable staff and empowering the team accordingly.
•    Communicates security posture, risk trends, and program progress to the VP and Cabinet-level audiences in clear, non-technical, decision-ready terms.
•    Integrates security considerations into strategic and tactical planning, budget preparation, and major initiatives across ITS and the university — acting as a partner in enabling institutional goals, not a gatekeeper.
•    Develops the annual security budget and multi-year investment plan, making defensible trade-off recommendations and demonstrating return on security investment.
•    Continuously scans emerging threats, technologies, and higher education security trends, translating them into concrete, prioritized action for the university.

Artificial Intelligence and Emerging Technology
•    Partners with university AI governance efforts, contributing security expertise to AI acceptable use policy, data classification guidance for AI tools, and the review and approval of AI platforms and integrations.
•    Builds and matures defenses against AI-enabled threats, including AI-generated phishing, deepfake-driven social engineering and fraud, and automated credential attacks.
•    Assesses the security implications of enterprise AI adoption — including generative AI platforms, AI agents, and AI features embedded in existing vendor products — and establishes controls proportionate to institutional risk.
•    Evaluates and adopts the responsible use of AI within the security program itself, including AI-assisted detection, response, and security awareness capabilities.
•    Leads third-party and vendor AI risk review as part of the university's technology approval and procurement processes.

Security Operations and Incident Response
•    Coordinates the development, implementation, and administration of security policies, standards, and programs for ITS and other areas of the university as applicable.
•    Leads the Computer Security Incident Response Team (CSIRT) and co-leads the Business Continuity Emergency Incident Response Team (BCEIRT), ensuring plans are tested, current, and understood.
•    Oversees a modern defensive posture spanning identity and access management, cloud and SaaS security, endpoint protection, email security, data loss prevention, and vulnerability management, with progress toward zero trust principles.
•    Coordinates the assessment of systems and network security risks, including risk analysis, threat assessments, and contingency planning.
•    Completes incident reports and investigations of policy violations and suspected material incidents, including any required regulatory notifications.
•    Participates in project development across ITS to ensure security best practices are built in from the start.

Compliance and the ISMS
•    Manages the ISO/IEC 27001 ISMS, maintaining and improving documentation, processes, policies, plans, and corrective actions.
•    Compiles evidence of compliance with the major regulations and requirements affecting the university — including GLBA, FERPA, HIPAA, PCI DSS, and applicable data privacy laws — recognizing that university data spans multiple regulated categories and frameworks concurrently.
•    Participates in multiple annual audits across the university's ISO management systems, penetration tests, third-party security assessments, PCI compliance audits, and GLBA audits.

Awareness, Culture, and Team
•    Oversees effective, engaging security awareness programs — including AI-era threat education — that measurably change behavior across students, faculty, and staff.
•    Builds, develops, and retains a high-performing security team, delegating operational ownership with clear accountability and coaching staff toward greater autonomy.
•    Serves as an approachable, visible member of the ITS leadership team and a trusted, down-to-earth partner to departments across campus.
•    Facilitates and directs the timely dissemination of security information to the university community.
•    Contributes to a work environment that encourages knowledge of, respect for, and development of skills to engage with those of other cultures and backgrounds.
•    Attends conferences and training as required to maintain proficiency.

Required Qualifications
•    Bachelor's degree in Information Technology, Cybersecurity, or a related field.
•    Ten (10) years of varied information technology experience, including extensive supervisory experience and at least seven (7) years of directly related information security experience.
•    Certified Information Systems Security Professional (CISSP) or an equivalent information security professional certification.
•    Demonstrated success developing and executing an information security strategy — not solely operating a program — including experience presenting to executive or board-level audiences.
•    Working knowledge of the security implications of enterprise AI adoption and AI-enabled threats, with the ability to translate both into practical policy and controls.
•    Deep working knowledge of the regulatory landscape governing higher education information security, including GLBA, FERPA, HIPAA, and PCI DSS, with demonstrated experience maintaining compliance across multiple frameworks simultaneously and translating regulatory requirements into practical controls, evidence, and audit readiness.
•    Familiarity or experience with ISO/IEC 27001:2022, ISO/IEC 22301:2019, and ISO/IEC 20000-1:2018 management systems, with the ability to become certified as a Lead Auditor in each.
•    Strong leadership and supervisory skills, including proven ability to delegate effectively — quickly distinguishing what requires direct involvement from what belongs with the team — and to develop staff capable of owning operations.
•    A collaborative, approachable working style by building trust across departments, listening well, and working as a partner rather than an enforcer.
•    A fast, decisive working pace with strong follow-through; comfortable making sound decisions with incomplete information and adjusting as facts develop.
•    Demonstrated skills in budget development, financial management, and resource management.
•    Excellent oral and written communication skills, including the ability to make complex security topics clear to non-technical audiences.
•    Excellent organizational and time management skills; demonstrated ability to prioritize and manage multiple projects simultaneously and meet established deadlines.
•    Willingness to embrace new technologies and innovative organizational practices.

Preferred Qualifications
•    Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
•    Additional security certifications (e.g., CISM, CCSP, CRISC, GIAC, or AI security–related credentials).
•    Experience with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) or hands-on evaluation of enterprise AI platforms.
•    Experience with cloud security architecture, identity-centric security models, and zero trust implementation.
•    Knowledge of data privacy legislation (e.g., GDPR, state privacy laws) and data governance practices.
•    Computer forensics or incident response leadership experience.
•    Experience supporting HIPAA compliance in a campus health or clinic setting, including business associate and covered-entity considerations.
•    Higher education experience.

Work Schedule
Monday–Friday, 8:30 a.m. to 5:00 p.m.
Summer: Monday–Thursday, 8:00 a.m. to 5:30 p.m.
Occasional evenings and weekends may be required.

The University of Tampa offers great benefits to include:

  • FREE Tuition

  • Generous paid leave

  • Wellness initiatives

  • 100% Employer-Funded Health Reimbursement Account

  • 100% Employer-Paid Short & Long Term Disability Insurance

  • 100% Employer-Funded Employee Assistance Program

  • Discounted On-Campus Dining Meal Plans

  • FREE On-Campus Parking

  • FREE Access to Campus Amenities (pool, library, campus events and more)

  • Fitness Center

  • Pet Insurance

  • Flexible Spending Accounts

  • And more!

Background Check Requirement

Finalists may be required to submit to a criminal background check. Some positions may also require a motor vehicle report and/or a credit report.

Submission Guidelines

To receive full consideration for employment with The University of Tampa, please be sure to submit/upload required documents for this position at time of application submission.  Required documents should be submitted in the attachment box at the bottom of the "My Experience" page of the application before continuing through the application.

Background Check Requirements

Finalists may be required to submit to a criminal background check. Some positions may also require a motor vehicle report and/or a credit report.

Additional Information

This description is intended to be generic in nature. It is not to determine specific duties and responsibilities for any particular position. Essential functions and overtime eligibility may vary based on the specific task assigned to the position.

Skills Required

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field.
  • Ten years of varied information technology experience, including extensive supervisory experience and at least seven years of directly related information security experience.
  • Certified Information Systems Security Professional (CISSP) or equivalent information security professional certification.
  • Demonstrated success developing and executing an information security strategy, including presenting to executive or board-level audiences.
  • Working knowledge of security implications of enterprise AI adoption and AI-enabled threats and ability to translate into policy and controls.
  • Deep working knowledge of GLBA, FERPA, HIPAA, PCI DSS and ability to maintain compliance across multiple frameworks.
  • Familiarity or experience with ISO/IEC 27001:2022, ISO/IEC 22301:2019, ISO/IEC 20000-1:2018 and ability to become certified as a Lead Auditor in each.
  • Strong leadership and supervisory skills with proven ability to delegate and develop staff.
  • Demonstrated skills in budget development, financial management, and resource management.
  • Excellent oral and written communication skills, with ability to explain complex security topics to non-technical audiences.
  • Excellent organizational and time management skills; ability to prioritize and manage multiple projects and meet deadlines.
  • Willingness to embrace new technologies and innovative organizational practices.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Tampa, FL
1,000 Employees

What We Do

The University of Tampa is a private, residential university located in Tampa, Florida, that offers a wide range of academic programs and experiential learning opportunities.

Similar Jobs

Optum Logo Optum

Pharmacy Manager - Community

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Leesburg, FL, USA
160000 Employees
113K-193K Annually

Pluralsight Logo Pluralsight

Senior Manager, Marketing Operations

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
122K-160K Annually

Pluralsight Logo Pluralsight

VP, Marketing Operations & Digital Platform

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
227K-270K Annually

Pluralsight Logo Pluralsight

Principal Product Designer

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
148K-195K Annually

Similar Companies Hiring

Quantum Rise Thumbnail
Software • Professional Services • Natural Language Processing • Machine Learning • Consulting • Automation • Artificial Intelligence
Chicago, Illinois
20 Employees
Learneo Thumbnail
Software • Machine Learning • Edtech • Artificial Intelligence
DE
397 Employees
CodePath.org Thumbnail
Edtech • Social Impact
San Francisco, CA
55 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account