SonicJobs Logo
Left arrow iconBack to search

Assistant Vice President, Information Security

University of Tampa
Posted 2 days ago, valid for 17 days
Location

Tampa, FL, US

Salary

Competitive

Contract type

Full Time

Disability Insurance
Employee Assistance
Flexible Spending Account

By applying, a University of Tampa account will be created for you. University of Tampa's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The University of Tampa is seeking an Assistant Vice President for Information Security, requiring a Bachelor's degree and ten years of IT experience, including seven years in information security.
  • The role involves developing a multi-year security strategy, overseeing security operations, and leading the Information Security department while ensuring compliance with various regulations.
  • Candidates must possess a Certified Information Systems Security Professional (CISSP) certification and demonstrate success in presenting security strategies to executive audiences.
  • The position offers a salary range of $150,000 to $175,000, with additional benefits such as free tuition, generous paid leave, and wellness initiatives.
  • This essential role may require reporting to work during university closures and emphasizes strategic leadership in navigating emerging threats and aligning security investments with institutional priorities.

If you are a current University of Tampa student, please search for and apply to student jobs here via Workday. Job applications for current students will not be considered if submitted through the external career center.

Position Details

Information Technology and Security at The University of Tampa has a position available for an Assistant Vice President, Information Security, reporting to the Vice President, Information Technology and Security. The AVP is responsible for assisting the VP information Technology & Security (CIO/CISO) with establishing and executing a multi-year security strategy that protects students, faculty, staff, and institutional data in a threat landscape increasingly shaped by artificial intelligence, identity-based attacks, and third-party risk.  This role handles executive duties such as briefing cabinet or board members, leading the ITS CCIRT team and major incident investigations in a collaborative team environment.  It calls for a keen understanding of the intersection between business, academic and security requirements as well as evaluating technology solutions that departments wish to purchase, setting risk-based criteria that enables innovation and productivity.  Additionally, this position leads or participates in audits, conducts risk assessments, and creates corrective actions or improvements to optimize the information security program, procedures, or data protection.  


This is a strategy-first leadership role. The AVP leads the Information Security department and the university's certified ISO/IEC 27001 Information Security Management System (ISMS), but success in this position is measured by the ability to anticipate where risk is moving, align security investments with institutional priorities, and communicate clearly with executive-level audiences — not solely by day-to-day operational execution, which the AVP is expected to build a team capable of running.


This position is designated as an essential employee and may be required to report to work as scheduled when university offices are closed due to severe weather or other conditions.


Strategic Leadership
•    Owns and maintains the university's multi-year information security strategy and roadmap, aligning it with institutional goals, the enterprise risk register, and the realities of a private, residential, four-year university environment.
•    Sets and sequences security priorities using risk-based judgment: distinguishing the initiatives that require the AVP's direct leadership from those that should be delegated to capable staff and empowering the team accordingly.
•    Communicates security posture, risk trends, and program progress to the VP and Cabinet-level audiences in clear, non-technical, decision-ready terms.
•    Integrates security considerations into strategic and tactical planning, budget preparation, and major initiatives across ITS and the university — acting as a partner in enabling institutional goals, not a gatekeeper.
•    Develops the annual security budget and multi-year investment plan, making defensible trade-off recommendations and demonstrating return on security investment.
•    Continuously scans emerging threats, technologies, and higher education security trends, translating them into concrete, prioritized action for the university.


Artificial Intelligence and Emerging Technology
•    Partners with university AI governance efforts, contributing security expertise to AI acceptable use policy, data classification guidance for AI tools, and the review and approval of AI platforms and integrations.
•    Builds and matures defenses against AI-enabled threats, including AI-generated phishing, deepfake-driven social engineering and fraud, and automated credential attacks.
•    Assesses the security implications of enterprise AI adoption — including generative AI platforms, AI agents, and AI features embedded in existing vendor products — and establishes controls proportionate to institutional risk.
•    Evaluates and adopts the responsible use of AI within the security program itself, including AI-assisted detection, response, and security awareness capabilities.
•    Leads third-party and vendor AI risk review as part of the university's technology approval and procurement processes.


Security Operations and Incident Response
•    Coordinates the development, implementation, and administration of security policies, standards, and programs for ITS and other areas of the university as applicable.
•    Leads the Computer Security Incident Response Team (CSIRT) and co-leads the Business Continuity Emergency Incident Response Team (BCEIRT), ensuring plans are tested, current, and understood.
•    Oversees a modern defensive posture spanning identity and access management, cloud and SaaS security, endpoint protection, email security, data loss prevention, and vulnerability management, with progress toward zero trust principles.
•    Coordinates the assessment of systems and network security risks, including risk analysis, threat assessments, and contingency planning.
•    Completes incident reports and investigations of policy violations and suspected material incidents, including any required regulatory notifications.
•    Participates in project development across ITS to ensure security best practices are built in from the start.


Compliance and the ISMS
•    Manages the ISO/IEC 27001 ISMS, maintaining and improving documentation, processes, policies, plans, and corrective actions.
•    Compiles evidence of compliance with the major regulations and requirements affecting the university — including GLBA, FERPA, HIPAA, PCI DSS, and applicable data privacy laws — recognizing that university data spans multiple regulated categories and frameworks concurrently.
•    Participates in multiple annual audits across the university's ISO management systems, penetration tests, third-party security assessments, PCI compliance audits, and GLBA audits.


Awareness, Culture, and Team
•    Oversees effective, engaging security awareness programs — including AI-era threat education — that measurably change behavior across students, faculty, and staff.
•    Builds, develops, and retains a high-performing security team, delegating operational ownership with clear accountability and coaching staff toward greater autonomy.
•    Serves as an approachable, visible member of the ITS leadership team and a trusted, down-to-earth partner to departments across campus.
•    Facilitates and directs the timely dissemination of security information to the university community.
•    Contributes to a work environment that encourages knowledge of, respect for, and development of skills to engage with those of other cultures and backgrounds.
•    Attends conferences and training as required to maintain proficiency.


Required Qualifications
•    Bachelor's degree in Information Technology, Cybersecurity, or a related field.
•    Ten (10) years of varied information technology experience, including extensive supervisory experience and at least seven (7) years of directly related information security experience.
•    Certified Information Systems Security Professional (CISSP) or an equivalent information security professional certification.
•    Demonstrated success developing and executing an information security strategy — not solely operating a program — including experience presenting to executive or board-level audiences.
•    Working knowledge of the security implications of enterprise AI adoption and AI-enabled threats, with the ability to translate both into practical policy and controls.
•    Deep working knowledge of the regulatory landscape governing higher education information security, including GLBA, FERPA, HIPAA, and PCI DSS, with demonstrated experience maintaining compliance across multiple frameworks simultaneously and translating regulatory requirements into practical controls, evidence, and audit readiness.
•    Familiarity or experience with ISO/IEC 27001:2022, ISO/IEC 22301:2019, and ISO/IEC 20000-1:2018 management systems, with the ability to become certified as a Lead Auditor in each.
•    Strong leadership and supervisory skills, including proven ability to delegate effectively — quickly distinguishing what requires direct involvement from what belongs with the team — and to develop staff capable of owning operations.
•    A collaborative, approachable working style by building trust across departments, listening well, and working as a partner rather than an enforcer.
•    A fast, decisive working pace with strong follow-through; comfortable making sound decisions with incomplete information and adjusting as facts develop.
•    Demonstrated skills in budget development, financial management, and resource management.
•    Excellent oral and written communication skills, including the ability to make complex security topics clear to non-technical audiences.
•    Excellent organizational and time management skills; demonstrated ability to prioritize and manage multiple projects simultaneously and meet established deadlines.
•    Willingness to embrace new technologies and innovative organizational practices.


Preferred Qualifications
•    Master's degree in Computer Science, Cybersecurity, Information Systems, or a related field.
•    Additional security certifications (e.g., CISM, CCSP, CRISC, GIAC, or AI security–related credentials).
•    Experience with AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) or hands-on evaluation of enterprise AI platforms.
•    Experience with cloud security architecture, identity-centric security models, and zero trust implementation.
•    Knowledge of data privacy legislation (e.g., GDPR, state privacy laws) and data governance practices.
•    Computer forensics or incident response leadership experience.
•    Experience supporting HIPAA compliance in a campus health or clinic setting, including business associate and covered-entity considerations.
•    Higher education experience.


Work Schedule
Monday–Friday, 8:30 a.m. to 5:00 p.m.
Summer: Monday–Thursday, 8:00 a.m. to 5:30 p.m.
Occasional evenings and weekends may be required.

The University of Tampa offers great benefits to include:

  • FREE Tuition

  • Generous paid leave

  • Wellness initiatives

  • 100% Employer-Funded Health Reimbursement Account

  • 100% Employer-Paid Short & Long Term Disability Insurance

  • 100% Employer-Funded Employee Assistance Program

  • Discounted On-Campus Dining Meal Plans

  • FREE On-Campus Parking

  • FREE Access to Campus Amenities (pool, library, campus events and more)

  • Fitness Center

  • Pet Insurance

  • Flexible Spending Accounts

  • And more!

Background Check Requirement

Finalists may be required to submit to a criminal background check. Some positions may also require a motor vehicle report and/or a credit report.

Submission Guidelines

To receive full consideration for employment with The University of Tampa, please be sure to submit/upload required documents for this position at time of application submission.  Required documents should be submitted in the attachment box at the bottom of the "My Experience" page of the application before continuing through the application.

Background Check Requirements

Finalists may be required to submit to a criminal background check. Some positions may also require a motor vehicle report and/or a credit report.

Additional Information

This description is intended to be generic in nature. It is not to determine specific duties and responsibilities for any particular position. Essential functions and overtime eligibility may vary based on the specific task assigned to the position.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a University of Tampa account will be created for you. University of Tampa's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.