What are the responsibilities and job description for the Deputy Chief Information Officer and Chief Information Security & Privacy Officer position at illinois?
Duties & Responsibilities
University & Program Leadership
- Prioritize privacy and security risk management in alignment with institutional risk frameworks and institutional missions.
- Lead the development of multi-year roadmaps for information security, identity and access management, and privacy across on-premise, cloud, and third-party platforms.
- Serve as the primary institutional advocate for privacy, promoting awareness and integration of privacy principles into technology, processes, and training.
- Advise university counsel, senior leadership, and stakeholders on information security and privacy matters.
- Direct the Identity, Privacy, and Cybersecurity group, including budget oversight and personnel management.
- Collaborate with other Technology Services groups and staff to enhance risk mitigation strategies.
- Support strategic planning and ensure alignment with organizational goals.
- Partner with university leaders, governance bodies, and technologists to strengthen foundational IT capabilities through strategic investments and resource planning.
- Supervises and supports staff through regular guidance, coaching, and performance management to ensure quality service and operational excellence.
- Travel may be required.
Risk Management & Incident Response
- Oversee and mature risk management processes across the university and the University of Illinois System.
- Lead campus-wide information security and privacy incident response programs.
- Serve as the official point of contact for security incidents, including coordination with law enforcement.
- Collaborate with university counsel and System leadership on policy violations and external complaints.
- Monitor compliance with privacy laws and regulations including FERPA, HIPAA, GDPR, and institutional policies.
- Maintain awareness of emerging threats and develop strategies to mitigate their impact on university operations.
Institutional Compliance & Policy
- Lead the development and maintenance of institutional policies, standards, and procedures related to information security and privacy.
- Ensure policies reflect current legislation and regulatory requirements relevant to a Research 1 institution.