University of Alberta
Chief Information Security Officer
Edmonton, Alberta · On-site · Posted today
Opens iaejup.fa.ocs.oraclecloud.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- On-site
- Source
- Oracle (employer's hiring system)
Skills mentioned
Cybersecurity, Machine Learning, Zero Trust, Incident Response, ISO 27001, Supply Chain
About the role
The University of Alberta has engaged DHR International Canada Inc. to manage this search. To explore this exciting opportunity further, please contact or submit your resume to uofaciso@dhrglobal.com.
Reporting to the Chief Information Officer (CIO), Associate Vice-President of Information Services & Technology (IST), the Chief Information Security Officer (CISO) provides leadership to discrete functions, operations, programs or services within the cybersecurity and IT compliance areas of the university. The CISO is a Director within IST, reporting to the CIO alongside the other IST portfolio directors, and works in close collaboration with them so that security is built into how systems and services are designed, implemented and supported. Directors are expected to generate excitement, engagement, support and momentum for their area’s initiatives. As leaders, they straddle the worlds of operational and strategic leadership, translating strategic vision into operational/action plans for their staff.
The CISO leads the development and implementation of a comprehensive security strategy to safeguard University assets, information, and infrastructure. This role operates within a complex academic environment, supporting institutional goals while ensuring compliance with regulatory requirements and emerging security threats. The University of Alberta is an internationally recognized institution and with extensive research programs and as such this role will need to understand regional, national and international cybersecurity policies and trends. Artificial intelligence is reshaping both the threat landscape and the university’s operating environment. The CISO will lead the institution’s approach to securing and governing its use across teaching, research and administration, while enabling the innovation that AI makes possible.
Key Accountabilities
Leader (Operations/Program/Service):
- Develop, analyze, oversee, and continuously improve the security architecture and control framework that protect the university’s information, systems and research, and support the organization’s goals and service needs;
- Execute a comprehensive, clear cybersecurity strategy that exhibits effective planning and ensures agility;
- Establish a multi-year cybersecurity roadmap that supports maturing the security function, services, and partnerships across the university;
- Set cybersecurity standards in consultation with IST leaders, faculties and other stakeholders, ensuring the standards are practical to implement and that the university is enabled to meet them;
- Partner with the CIO and other university leaders to enable secure and responsible adoption of artificial intelligence and machine learning technologies, including AI risk assessment, security review and guardrails for their use;
- Collaborate with other leaders to identify opportunities to innovate service delivery, develop information capabilities, and improve operational performance and processes;
- Oversee the security of IT infrastructure, cloud services, and software development ensuring cost effectiveness, efficiency, integration, security, accessibility, and sustainability;
- In collaboration with university partners, lead investigations into real and potential IT threats and breaches;
- Track, analyze, and monitor technology performance metrics to continually improve performance outcomes and deliverables;
- Provide senior leadership and expertise in the development of information technology policies and procedures;
- Establish and lead security governance for artificial intelligence, including risk assessment of AI tools and vendors, safeguards for institutional and research data used with generative and agentic AI, monitoring for unsanctioned AI use, and alignment with recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001);
- Prepare the university for AI-enabled threats, such as AI-generated phishing and impersonation and the faster discovery and exploitation of software vulnerabilities, and apply AI responsibly to strengthen threat detection, response and team capacity;
- Lead cybersecurity awareness and education programs for students, faculty and staff, including the safe and responsible use of AI tools;
- Partner with the Safeguarding Research Office to ensure cybersecurity is properly managed in the research context, including protection of sensitive research and support for federal research security requirements such as the Policy on Sensitive Technology Research and Affiliations of
- Concern, while preserving academic openness;
- Provide executive oversight of third-party and supply chain risk, business continuity and disaster recovery, and ransomware resilience programs; and
- Set identity and access management and zero trust principles for the university, in partnership with IST and faculty IT teams.
Strategic Influencer:
- Contributes expertise and insight to the development of university, portfolio and area strategies;
- Champions the development of proactive strategies or initiatives. Educates the university on emerging trends in cyber security and IT compliance, including the security and privacy implications of artificial intelligence; anticipates impacts of these trends on future service delivery and addresses any workforce planning requirements;
- Provides comprehensive advice, recommendations and perspectives on current organizational activities and issues related to cyber security and IT compliance;
- Contributes security and risk expertise to university AI governance and advisory bodies, working with academic, research, privacy, legal, and Indigenous data governance partners;
- Contributes to quarterly risk updates provided through the board audit platform, and participates directly in the annual Cybersecurity Report and Roadmap presented to the Board of Governors;
- The CISO should be visible and engaged across campus, participating in committees, town halls, and student/faculty initiatives; and
- Works collaboratively with colleagues to identify joint objectives and initiatives.
Innovator:
- Proactively identifies the need for change within one’s own area. Searches beyond own area and the university for new methods, trends and innovative approaches. Challenges the status quo.
- Develops, tests, and delivers new methods or approaches;
- Creates a safe environment that supports taking responsible risks and learns from setbacks and mistakes;
- Champions change and innovation; anticipates barriers to the flow of new ideas; proactively addresses issues and resistance; and
- Demonstrates resilience and positivity in an environment which may present resistance to innovation and change.
Issue Resolver:
- Analyses complex situations to find solutions. Gathers, interprets, synthesizes and evaluates information from a wide range of sources and perspectives. Reasons critically and thinks conceptually based on a thorough understanding of the context;
- Champions innovative and novel solutions to support the cyber security and IT compliance needs of the university; and
- Creates practical and pragmatic solutions that are reasonable to implement. Engage others, including functional experts, in collaborative problem solving when necessary.
Communicator:
- Demonstrates persuasive, engaging, clear and credible communication to gain support and commitment in varied situations from a wide variety of audiences;
- Demonstrates flexibility in approach and language use when delivering to varied audiences (e.g. use of examples, analogies, storytelling);
- Skillfully handles complex, on-the-spot questions from audiences. Addresses any conflict with well-considered responses. Communicates strategically, considering optimal timing, style, channel, medium and form of communication;
- Ensures communication plans are developed for area initiatives and implemented so stakeholders are informed in a timely, consistent and accurate manner.
Education:
- Bachelor’s degree in management information science, computer science, information systems, cybersecurity or a related field, or an equivalent combination of education and experience.
- Professional Certification (e.g., CISSP, CISM, CISA, CRISC) is desirable, as are AI governance credentials (e.g., IAPP AIGP).
Experience:
- Minimum 10 years in IT and information security, including incident response, in a higher education environment preferred.
- 5+ years of progressive people management experience
- Demonstrated success in leading security programs in complex organizations.
- Familiarity with higher education IT environments and research data security.
- Experience developing and executing multi-year security roadmaps.
- Deep knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls).
- Experience with risk assessment, incident response, and compliance (e.g., Alberta’s Protection of
- Privacy Act and Access to Information Act, PCI DSS, GDPR).
- Experience working with governance bodies, faculty, and student groups.
- Experience working within shared governance models and respecting academic decision-making processes.
- Experience securing or governing AI and machine learning systems, or an equivalent record of assessing emerging technology risk, including familiarity with frameworks such as NIST AI RMF and ISO/IEC 42001.
- Experience supporting research security and protecting sensitive research data in a research-intensive environment, including awareness of Government of Canada research security policy.
- Experience with third-party risk, business continuity and disaster recovery, and ransomware resilience.
- Experience with identity and access management and zero trust architectures.
- Experience working within an IT organization to embed security in architecture, project delivery and operations, and setting standards through consultation so that they are practical to adopt.
This position is excluded from the bargaining unit.
In accordance with the Handbook of Terms and Conditions of Employment for Non-Union Employees, this position has a comprehensive benefits package and an annual salary which will be commensurate with qualifications.
Please submit applications directly to uofaciso@dhrglobal.com
Job ID or-iaejup-fa-ocs-oraclecloud-com-uoa-careers-4423 · Original posting ↗