Job Description
The University of Alberta has engaged DHR International Canada Inc. to manage this search. To explore this exciting opportunity further, please contact or submit your resume to uofaciso@dhrglobal.com.
Reporting to the Chief Information Officer (CIO), Associate Vice-President of Information Services & Technology (IST), the Chief Information Security Officer (CISO) provides leadership to discrete functions, operations, programs or services within the cybersecurity and IT compliance areas of the university. The CISO is a Director within IST, reporting to the CIO alongside the other IST portfolio directors, and works in close collaboration with them so that security is built into how systems and services are designed, implemented and supported. Directors are expected to generate excitement, engagement, support and momentum for their area’s initiatives. As leaders, they straddle the worlds of operational and strategic leadership, translating strategic vision into operational/action plans for their staff.
The CISO leads the development and implementation of a comprehensive security strategy to safeguard University assets, information, and infrastructure. This role operates within a complex academic environment, supporting institutional goals while ensuring compliance with regulatory requirements and emerging security threats. The University of Alberta is an internationally recognized institution and with extensive research programs and as such this role will need to understand regional, national and international cybersecurity policies and trends. Artificial intelligence is reshaping both the threat landscape and the university’s operating environment. The CISO will lead the institution’s approach to securing and governing its use across teaching, research and administration, while enabling the innovation that AI makes possible.
Responsibilities
Key Accountabilities
Leader (Operations/Program/Service)
- Develop, analyze, oversee, and continuously improve the security architecture and control framework that protect the university’s information, systems and research, and support the organization’s goals and service needs;
- Execute a comprehensive, clear cybersecurity strategy that exhibits effective planning and ensures agility;
- Establish a multi-year cybersecurity roadmap that supports maturing the security function, services, and partnerships across the university;
- Set cybersecurity standards in consultation with IST leaders, faculties and other stakeholders, ensuring the standards are practical to implement and that the university is enabled to meet them;
- Partner with the CIO and other university leaders to enable secure and responsible adoption of artificial intelligence and machine learning technologies, including AI risk assessment, security review and guardrails for their use;
- Collaborate with other leaders to identify opportunities to innovate service delivery, develop information capabilities, and improve operational performance and processes;
- Oversee the security of IT infrastructure, cloud services, and software development ensuring cost effectiveness, efficiency, integration, security, accessibility, and sustainability;
- In collaboration with university partners, lead investigations into real and potential IT threats and breaches;
- Track, analyze, and monitor technology performance metrics to continually improve performance outcomes and deliverables;
- Provide senior leadership and expertise in the development of information technology policies and procedures;
- Establish and lead security governance for artificial intelligence, including risk assessment of AI tools and vendors, safeguards for institutional and research data used with generative and agentic AI, monitoring for unsanctioned AI use, and alignment with recognized frameworks (e.g., NIST AI RMF, ISO/IEC 42001);
- Prepare the university for AI-enabled threats, such as AI-generated phishing and impersonation and the faster discovery and exploitation of software vulnerabilities, and apply AI responsibly to strengthen threat detection, response and team capacity;
- Lead cybersecurity awareness and education programs for students, faculty and staff, including the safe and responsible use of AI tools;
- Partner with the Safeguarding Research Office to ensure cybersecurity is properly managed in the research context, including protection of sensitive research and support for federal research security requirements such as the Policy on Sensitive Technology Research and Affiliations of
- Concern, while preserving academic openness;
- Provide executive oversight of third-party and supply chain risk, business continuity and disaster recovery, and ransomware resilience programs; and
- Set identity and access management and zero trust principles for the university, in partnership with IST and faculty IT teams.
Strategic Influencer
- Contributes expertise and insight to the development of university, portfolio and area strategies;
- Champions the development of proactive strategies or initiatives. Educates the university on emerging trends in cyber security and IT compliance, including the security and privacy implications of artificial intelligence; anticipates impacts of these trends on future service delivery and addresses any workforce planning requirements;
- Provides comprehensive advice, recommendations and perspectives on current organizational activities and issues related to cyber security and IT compliance;
- Contributes security and risk expertise to university AI governance and advisory bodies, working with academic, research, privacy, legal, and Indigenous data governance partners;
- Contributes to quarterly risk updates provided through the board audit platform, and participates directly in the annual Cybersecurity Report and Roadmap presented to the Board of Governors;
- The CISO should be visible and engaged across campus, participating in committees, town halls, and student/faculty initiatives; and
- Works collaboratively with colleagues to identify joint objectives and initiatives.
Innovator
- Proactively identifies the need for change within one’s own area. Searches beyond own area and the university for new methods, trends and innovative approaches. Challenges the status quo.
- Develops, tests, and delivers new methods or approaches;
- Creates a safe environment that supports taking responsible risks and learns from setbacks and mistakes;
- Champions change and innovation; anticipates barriers to the flow of new ideas; proactively addresses issues and resistance; and
- Demonstrates resilience and positivity in an environment which may present resistance to innovation and change.
Issue Resolver
- Analyses complex situations to find solutions. Gathers, interprets, synthesizes and evaluates information from a wide range of sources and perspectives. Reasons critically and thinks conceptually based on a thorough understanding of the context;
- Champions innovative and novel solutions to support the cyber security and IT compliance needs of the university; and
- Creates practical and pragmatic solutions that are reasonable to implement. Engage others, including functional experts, in collaborative problem solving when necessary.
Communicator
- Demonstrates persuasive, engaging, clear and credible communication to gain support and commitment in varied situations from a wide variety of audiences;
- Demonstrates flexibility in approach and language use when delivering to varied audiences (e.g. use of examples, analogies, storytelling);
- Skillfully handles complex, on-the-spot questions from audiences. Addresses any conflict with well-considered responses. Communicates strategically, considering optimal timing, style, channel, medium and form of communication;
- Ensures communication plans are developed for area initiatives and implemented so stakeholders are informed in a timely, consistent and accurate manner.
Education
QUALIFICATIONS
- Bachelor’s degree in management information science, computer science, information systems, cybersecurity or a related field, or an equivalent combination of education and experience.
- Professional Certification (e.g., CISSP, CISM, CISA, CRISC) is desirable, as are AI governance credentials (e.g., IAPP AIGP).
Experience
- Minimum 10 years in IT and information security, including incident response, in a higher education environment preferred.
- 5+ years of progressive people management experience
- Demonstrated success in leading security programs in complex organizations.
- Familiarity with higher education IT environments and research data security.
- Experience developing and executing multi-year security roadmaps.
- Deep knowledge of cybersecurity frameworks (e.g., NIST, ISO 27001, CIS Controls).
- Experience with risk assessment, incident response, and compliance (e.g., Alberta’s Protection of
- Privacy Act and Access to Information Act, PCI DSS, GDPR).
- Experience working with governance bodies, faculty, and student groups.
- Experience working within shared governance models and respecting academic decision-making processes.
- Experience securing or governing AI and machine learning systems, or an equivalent record of assessing emerging technology risk, including familiarity with frameworks such as NIST AI RMF and ISO/IEC 42001.
- Experience supporting research security and protecting sensitive research data in a research-intensive environment, including awareness of Government of Canada research security policy.
- Experience with third-party risk, business continuity and disaster recovery, and ransomware resilience.
- Experience with identity and access management and zero trust architectures.
- Experience working within an IT organization to embed security in architecture, project delivery and operations, and setting standards through consultation so that they are practical to adopt.
This position is excluded from the bargaining unit.
In accordance with the Handbook of Terms and Conditions of Employment for Non-Union Employees , this position has a comprehensive benefits package and an annual salary which will be commensurate with qualifications.
Please submit applications directly to uofaciso@dhrglobal.com
About Us
The University of Alberta, its buildings, labs and research stations are primarily located on the territory of Néhiyaw (Cree), Niitsitapi (Blackfoot), Métis, Nakoda (Stoney), Dene, Haudenosaunee (Iroquois) and Anishinaabe (Ojibway/Saulteaux), lands that are now known as part of Treaties 6, 7 and 8 and homeland of the Métis. The University of Alberta respects the sovereignty, lands, histories, languages, knowledge systems and cultures of all First Nations, Métis, and Inuit.
The University of Alberta is a community of knowledge seekers, change makers and world shapers who lead with purpose each and every day. We are home to over 14,000 faculty and staff, more than 40,000 students and a growing community of 300,000 alumni worldwide.
Your work will have a meaningful influence on a fascinating cross-section of people - from our students and community members, to our renowned researchers and innovators, making discoveries and generating solutions that make the world healthier, safer, stronger and more just. Learn more .
All qualified candidates are encouraged to apply; however, Canadians and permanent residents will be given priority. If suitable Canadian citizens or permanent residents cannot be found, other individuals will be considered.
At the University of Alberta, we are committed to creating an inclusive and accessible hiring process for all candidates. If you require accommodations to participate in the interview process, please let us know at the time of booking your interview and we will make every effort to accommodate your needs.
We thank all applicants for their interest; however, only those individuals selected for an interview will be contacted.
All University employees have a responsibility to foster a workplace that prioritizes safety in all its forms - physical, cultural, and psychological. This is achieved by promoting a safe environment, adhering to all safety laws, policies and procedures, completing all required safety training, identifying hazards and implementing controls, reporting incidents, and contributing to a culture of belonging and respect, while endeavoring to ensure that all colleagues feel valued and safe to express their thoughts, perspectives and concerns.
The University of Alberta is committed to creating a university community where everyone feels valued, barriers to success are removed, and thriving connections are fostered. We welcome applications from all qualified persons. We encourage women, First Nations, Métis and Inuit persons, members of visible minority groups, persons with disabilities, persons of any sexual orientation or gender identity and expression, and all those who may contribute to the further diversification of ideas and the University to apply.
L’Université de l’Alberta s’engage à créer une communauté universitaire où chaque personne se sent valorisée, où les obstacles à la réussite sont éliminés et où des connexions enrichissantes peuvent se développer. Nous accueillons les demandes de toutes les personnes qualifiées. Nous encourageons les femmes; Premières nations, Métis et Inuits; membres des groupes minoritaires visibles; personnes handicapées; personnes de toute orientation sexuelle ou identité et expression de genre; et toutes les personnes qui peuvent contribuer à la diversification des idées et à l'université à postuler.
About The Team
Information Services & Technology (IST) is the central support group for the university's technological landscape. IST plays a pivotal role in ensuring the evolution and smooth operation of technology for teaching, learning, research and working at the University of Alberta. Beyond having expansive technical expertise, IST fosters a supportive environment where our staff values include compassion, connection, collaboration, creativity and courage. If you are passionate about leveraging technology to empower education, research and to drive institutional excellence, join us and be part of shaping the future of the University of Alberta through innovative IT solutions.