Chief Information Security Officer (CISO)
George Mason UniversityAbout the role
Department: Information Technology
Classification: Administrative Faculty
Job Category: Administrative or Professional Faculty
Job Type: Full-Time
Work Schedule: Full-time (1.0 FTE, 40 hrs/wk)
Location: Fairfax, VA
Workplace Type: Hybrid Eligible
Salary: Salary commensurate with education and experience
Criminal Background Check: Yes
Security Clearance Check: Yes
About the Department:
Mason's Information Technology Services (ITS) organization provides information technology resources, systems, services, tools, and training to the university community. ITS's mission is to advance Mason’s strategic goals, support learning, enable scholarly endeavors, and improve institutional management by effectively leveraging the resources of ITS's supporting groups. The organization consists of six groups: Enterprise Infrastructure Services; Enterprise Applications; Learning Support Services; IT Security (ITSO); Enterprise Service Delivery; Academic Strategies; and dotted line reporting to Research Computing.
About the Position:
George Mason University recognizes the importance of information security and has a targeted focus on data as an asset. The Chief Information Security Officer (CISO) ensures that Mason has the right leadership, processes, technology, and tools to effectively meet current and future information security threats. The CISO provides vision and leadership to oversee and enhance an information security program for the university’s central systems and its decentralized computing environment, while also supporting information technology risk and compliance objectives in the process. The CISO reports to Mason’s Vice President for Information Technology and Chief Information Officer (CIO) and will be a member of the ITS leadership team.
The CISO provides leadership for the development of information security strategy, policy, standards, architecture, processes, and assessments to ensure that information assets and critical processes are adequately protected with acceptable levels of controls. The CISO builds and implements a broad-based strategic roadmap for security. The CISO has substantial influence and direction over IT Security, Network Security, and the budget issues that arise in determining necessary Information Security steps. The CISO manages the information security organization, including its staff; evolving the overall information security management program; enforcing adoption of standards and practices; and balancing information security requirements with other business objectives.
Responsibilities:
Policy and Program Leadership:
- Develops, communicates, and oversees the implementation of a strategic, comprehensive information security and risk roadmap for Mason and for ITS. Provides leadership across the university in information technology security processes, policies, practices, and services;
- Works with Mason leadership to identify risks to the confidentiality, integrity, and availability of university systems and data;
- Provides leadership in the enforcement of security and associated policies;
- Provides leadership to the ITSO in the analysis, discussion, and development of security policy, standards, and practices, and guides the acquisition of advanced security technology;
- Provides guidance and influences the university with regard to network and computing security needs in selecting hardware and software technologies, choosing between commercial and open source software, and determining whether services should be local or cloud-based; and
- Collaborates with and supports IT colleagues to monitor, assess, and test security solutions.
Compliance, Audit, and Standards:
- Develops and enhances an information security governance framework to guide Mason’s information security compliance efforts; aligning with George Mason risk posture and strategic goals;
- Coordinates and tracks information security related audits at all internal, state, and federal levels and provides guidance, evaluation, and advocacy on institutional audit responses;
- Ensures that the ITSO provides timely and documented responses to security concerns of IT projects via Mason’s Architectural Standards Review Board or project management processes as part of a holistic risk management program;
- Assists with the assessment of business requirements, advises administration and campus personnel on
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s