## Posting Summary: The University of Virginia Information Technology Services (ITS) seeks an experienced, innovative Deputy Chief Information Security Officer to lead efforts to enhance the overall information security architecture of the University. The University of Virginia is heavily dependent on effective and innovative uses of information technology to accomplish its critical teaching, research, administrative, and outreach functions. However, as never before, the ability to use information technology safely and reliably to maximum effect is at risk due to the rapidly evolving Internet threat environment. In its reliance on the Internet, Higher Education in general and the University are subject to the same sophisticated attacks and the same classes of attackers (e.g., individuals pursuing a cause, organized crime, nation states) that plague the more global cyber environment. Dealing realistically with cybersecurity as the threat continues to change and expand represents a significant challenge. To address needs in this area, the University is embarking on a multi-year Program to enhance its overall information security architecture. The incumbent will report directly to the UVA Chief Information Security Officer, and support the efforts of the Information Security Policy and Records Management team and ITS by providing leadership as well as coordinating the day-to-day operations related to the planning and implementation of a number of security related enhancement projects. The incumbent will lead efforts to implement information security tools, including IDS/IPS, vulnerability management, two-factor authentication, and log correlation and analysis. The chosen candidate will also help lead the automation of the risk assessment program and incident response efforts. ## University Leadership Characteristics: *For Thomas Jefferson, learning was an integral part of life. The "academical village" was created around the assumption that learning is a lifelong and shared process, and that interaction between scholars and students enlivens the pursuit of knowledge.* ## EO/AA Statement: The University of Virginia is an equal opportunity and affirmative action employer. Women, minorities, veterans and persons with disabilities are encouraged to apply. A graduate degree in computer science, information systems management, business administration or related fields is preferred. ## If any experience is required, please specify kind of experience: Experience in creating opportunities for professionals from various disciplines or groups to collaborate and communicate. Experience in assisting with project oversight or initiatives under the direction of senior leadership or management. ## If any experience is preferred, please specify kind of experience: It is highly desirable that the candidate have experience in Advanced Windows and Linux system administration, identity and access management, and information security incident responses. Experience working in a higher education or a research environment. ## If yes, what is the preferred License or Certification. One or more professional security certifications such as Certified Information Security Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are strongly preferred. ## Required Knowledge, Skills and Abilities: Expert level knowledge of program/project management methodologies, information security concepts, and technology and implementation concerns. ## Preferred Knowledge, Skills and Abilities: Knowledge of information security concepts (e.g. Confidentiality, Integrity, Availability), information security frameworks (e.g. NIST, ISO, FISMA), and information security technologies (firewalls, IDS/IPS, SIEM, application whitelisting, OS, vulnerability management). Demonstrated ability to apply legal and regulatory requirements (e.g. HIPAA, FERPA, PCI, GLBA), PKI concepts, and threat modeling. *Required Applicant Documents:* CV / ResumeCover LetterContact information for 3 References - name, email, phone *Drug Testing Required?(Typically positions involved in patient contact, mass transportation or law enforcement are included):* No *Posting Number:* 0618046

