Chief Information Security Officer
University System of New HampshireAbout the role
As a member of the USNH/UNH CIO’s leadership team, the Chief Information Security Officer (CISO) sets the strategic direction for cybersecurity, risk management, and information assurance across a complex R1 research environment and multi-campus university system. The CISO partners with senior academic, research, administrative, and external stakeholders to protect the confidentiality, integrity, and availability of institutional data, research assets, and digital services, while enabling the open, collaborative, and innovative culture that defines a top-tier research university.
This role is uniquely focused on the challenges of an R1 institution: safeguarding federally funded and export-controlled research, meeting evolving compliance mandates (NIST SP 800-171/CMMC, NIH/NSF data security requirements, GLBA, HIPAA, FERPA, PCI DSS, GDPR), defending against threat actors targeting higher education via a range of potential actions, and securing a highly decentralized environment of researchers, students, academic, and administrative units. The CISO leads enterprise cybersecurity strategy and operations, while collaborating closely with leadership of networking, data governance, and AI functions to ensure security is embedded across the institutional ecosystem.
Duties/Responsibilities
Strategic Leadership (25%)
Set and execute the enterprise information security strategy, aligning cybersecurity priorities with the academic, research, and business mission of USNH and UNH.
Serve as a member of the CIO’s leadership team, contributing to enterprise IT direction, governance, and resource allocation.
Build and sustain trusted relationships with senior leaders across academic affairs, the office of research, finance, HR, general counsel, internal audit, the medical and clinical enterprise, and external partners (federal sponsors, peer institutions, REN-ISAC, EDUCAUSE, law enforcement).
Communicate complex cyber risk topics clearly to the Board, executive leadership, faculty governance, and the broader campus community; serve as a public-facing voice on cybersecurity matters when appropriate.
Foster a security-aware culture through training, awareness campaigns, and partnership with academic units rather than top-down enforcement.
Cybersecurity of the Network (in Collaboration with Networking Services) (10%)
The CISO does not directly manage networking services or operations but is accountable for the cybersecurity posture of the network and works in close partnership with IT executives and leaders responsible for LAN, WAN, wireless, and telecommunications.
Define security requirements, standards, and architecture principles for the campus, research, and cloud network environments.
Partner with Networking Services on the design and implementation of network segmentation, zero trust network access (ZTNA), micro-segmentation for sensitive research enclaves, secure remote access, and protections for IoT, OT, and lab/instrumentation networks.
Lead network-focused threat detection, monitoring, vulnerability management, intrusion detection/prevention, and incident response in collaboration with network engineering teams.
Jointly evaluate and approve network technologies, vendors, and changes that have material security implications.
Coordinate on protection of research computing networks, HPC environments, and federated/Internet2 connections.
Research Security and Compliance (R1 Focus) (10%)
Lead the institution’s response to evolving research security requirements, including NSPM-33, controlled unclassified information (CUI), CMMC, export controls (EAR/ITAR), and sponsor-specific data security plans.
Partner with SPA and RCC to operate secure research enclaves and reference architectures that enable faculty to pursue funded research without friction while meeting federal and sponsor obligations.
Partner with the Office of Sponsored Research, Research Computing, and faculty PIs on data security plans, DMPs, and secure data sharing across institutions.
Maintain compliance programs spanning HIPAA (clinical and human-subjects research), FERPA, GLBA, PCI DSS, GDPR, and state privacy laws.
Collaboration on Data Governance and AI Security (15%)
Partner with IT executives responsible for data and analytics, data trustees, and data governance committees to ensure data classification, handling, retention, and access standards are operationalized with appropriate technical controls.
Co-develop policies and contro
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s