← All roles
CISO

Chief Information Security Officer

University of Virginia · Education · 10,000+ employees

Charlottesville, VA · Hybrid · full_time

CLI Career Level

Enterprise CISO

Moderate confidence

Opportunity Score

90/100

Exceptional

Moderate confidence

Executive Fit

Sign in

Add your background to score this role against you

Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.

First seen Aug 17, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — CISO (US)

CLI Take

Scope matches the title

CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it reports to Vice President and Chief Information Officer and carries NIST 800-171 and FERPA accountability. Reporting to the Vice President and Chief Information Officer (CIO) rather than directly to the President or Board Total compensation and team size are not disclosed and remain the main open questions before pursuing it.

Why this role scores the way it does

90/100 — exceptional opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. 5 of 10 dimensions are not disclosed, which lowers confidence rather than the score.

Career level read

Enterprise CISO — The employer lists this as “Chief Information Security Officer”. CLI reads it as Enterprise CISO because the role shows reports to a C-level executive, 10,000+ employee organization.

Moderate confidence

What makes it attractive

  • CLI's analysis of the posting describes a strategic build or transformation mandate.
  • The role carries more scope than the employer's title suggests.
  • Employer profile: 10,000+ employee organization, government ownership, not applicable, revenue 1b 10b.
  • The role reports to a C-level executive.
  • Signals worth probing: Reporting to the Vice President and Chief Information Officer (CIO) rather than directly to the President or Board.

What to probe before applying

  • No material concerns identified in the posting.

Scoring components · Exceptional

Compensation versus comparable rolesNot disclosed · excluded from the score

Compensation is not disclosed and there is no comparable set to place it against.

Reporting level71 · weight 12%

The role reports to a C-level executive.

Functional and geographic scopeNot disclosed · excluded from the score

Scope: no enterprise, global or multi-unit remit is described.

Quality of the mandate100 · weight 12%

CLI's analysis of the posting describes a strategic build or transformation mandate.

Executive and board exposureNot disclosed · excluded from the score

Executive and board exposure: not disclosed.

Role authority versus title100 · weight 10%

The role carries more scope than the employer's title suggests.

Company scale and trajectory100 · weight 10%

Employer profile: 10,000+ employee organization, government ownership, not applicable, revenue 1b 10b.

Team ownershipNot disclosed · excluded from the score

Team size: not disclosed.

Budget ownershipNot disclosed · excluded from the score

Budget ownership: not disclosed.

Risk signals75 · weight 5%

Signals worth probing: Reporting to the Vice President and Chief Information Officer (CIO) rather than directly to the President or Board.

Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.

Sign in to see how this role scores against your background, and add your career goal to evaluate career value.

Compensation

No compensation disclosed and insufficient comparable data to estimate.

Sample size not yet sufficient for a market comparison

See the full benchmark bands by level and region

The mandate

Establish and maintain a university-wide information security management program to protect data and assets. The leader must align the university's risk posture with compliance requirements while fostering a culture of continuous learning and user-centered security practices across a complex academic environment.

Reports to the VP and CIO as a critical member of the IT Services (ITS) leadership team. Remit covers university-wide information security management, risk, operations, and incident response across academic and administrative units.

Scope

  • Reports to Vice President and Chief Information Officer

Domains and regulation

  • Enterprise Security
  • Cyber Defense
  • GRC
  • Incident Response
  • Cloud Security
  • Research Data Security
  • Infrastructure Security
  • NIST 800-171
  • FERPA

Requirements

Must have

  • At least 10 years of experience in risk management, information security, and IT jobs
  • At least 5 years of experience in a senior leadership role
  • Knowledge of security frameworks such as ISO/IEC 27001, NIST 800-53, and NIST CSF
  • Experience with Cloud Computing (IaaS/PaaS/SaaS) and vendor negotiations

Preferred / bonus

  • Bachelor’s degree in IT, Computer Science, or related field (advanced degree preferred)
  • Strong understanding of the higher education sector's policy and regulatory environment (preferred)

Only must-have items are scored as hard constraints in Executive Fit.

Likely challenges

Signals worth probing

Not stated in the posting: Compensation range not disclosed; Specific team size (headcount) not disclosed; Specific budget authority not disclosed; Direct reporting line to the Board not explicitly stated (reports to CIO).

About University of Virginia

The University of Virginia is a public research university and the flagship institution of the Commonwealth of Virginia. It operates a major academic medical center, extensive research facilities, and a global academic program. A security leader would oversee a complex environment comprising thousands of faculty, staff, and students, alongside a large-scale healthcare infrastructure.

Industry
Education
Headcount
10,000+ employees
Headquarters
Charlottesville, Virginia
Founded
1819
Ownership
Government
Funding
Not applicable
Revenue
$1B – $10B

Full company profile for University of Virginia →

View original job description
The University of Virginia (UVA), one of the nation’s leading public institutions, seeks an experienced, dynamic, and mission-driven leader to be the next Chief Information Security Officer (CISO). Reporting to the Vice President and Chief Information Officer (CIO), the CISO will provide strategic leadership and oversight to a diverse portfolio. They will lead high-performing teams and work collaboratively across a large, complex institution.The CISO must enjoy engaging with the University community, drawing on strong communication skills, a natural ability to build relationships, and comfort explaining complex technical concepts to faculty and staff at all levels. The complexity of this position requires strong leadership, collaboration and partnership skills, and the ability to balance the urgency surrounding the risk of emerging threats with university strategies and business needs.Position SummaryAs a critical member of the Information Technology Services (ITS) leadership team, this pivotal role is responsible for establishing and maintaining a university-wide information security management program to ensure that the university’s data and assets are adequately protected. The CISO must stay current with the evolving threat landscape (particularly involving AI-based threats), ensure staff are upskilling to keep pace, and challenging the status quo to ensure the University maximizes its investment in its information security resources. The candidate will work closely with IT leadership, administrative leaders, and academic faculties across Grounds to identify, evaluate, and report on information security risks in a manner that meets compliance and regulatory requirements and aligns with and supports the risk posture of the University.Key Responsibilities IncludeInformation Security Program LeadershipTeam LeadershipPolicy, Compliance and AuditCommunity and Partner EngagementRisk Management, Security Operations, Projects, and Incident ResponseAttributes, Competencies, And QualificationsThe successful candidate will bring a distinctive blend of leadership, strategic perspective, and technical expertise to advance the institution’s information security strategy, strengthen organizational resilience, and build trusted partnerships across the univeristy.The Ideal Candidate Will Demonstrate The Following AttributesCurious — Asks thoughtful questions, listens actively, and seeks understanding before taking action.Entrepreneurial — Embraces new ideas, explores innovative solutions, and remains open to different approaches.Resourceful — Identifies practical solutions, navigates constraints effectively, and remains focused despite obstacles.Collaborative — Builds strong relationships, values consultation, and engages stakeholders in developing solutions.Adaptable — Questions existing processes constructively and adjusts effectively as priorities and circumstances evolve.User-Centered — Considers the impact of security practices and technologies on users' ability to work effectively and achieve their goals.Growth-Oriented — Fosters a culture of continuous learning, encourages skill development, and helps teams embrace new approaches as needs change.In addition, the successful candidate will possess many of the following compencies and qualifications:A bachelor’s degree in Information Technology, Computer Science, Information Systems, or a related field (advanced degree preferred).Professional security management certification is strongly desired, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), or other similar credentials.At least 10 years of experience in a combination of risk management, information security, and IT jobs (at least five must be in a senior leadership role).Knowledge of common information security management frameworks, such as ISO/IEC 27001, and NIST 800-53, 800-171, and Cybersecurity Framework (CSF).Familiarity with AI and machine learning-based tools used across the information security lifecycle.Experience with contract and vendor negotiations and management, including managed services.Experience with Cloud Computing/IaaS/PaaS/SaaS technologies and services.Strong understanding of the higher education sector's policy, regulatory, and legislative environment is preferred.Excellent written and verbal communication skills, interpersonal, relationship-building, and collaborative skills, and the ability to communicate security and risk-related concepts to technical and nontechnical audiences at all levels.The CISO role is based in Charlottesville, VA, with an expectation of strong in-person presence to effectively engage with leadership and stakeholders. A hybrid work model is available, with flexibility to work remotely when appropriate and consistent with the needs of the organization.The full position description can be viewed here.To ApplyThe University of Virginia has retained Opus Partners to support this recruitment. Katie Dean, Senior Partner, and Abigail Maynard, Manging Associate, are leading the search. Applications (resume and letter of interest), confidential inquiries, and nominations should be sent to Abigail Maynard at abigail.maynard@opuspartners.net.The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Learn more about UVA’s commitment to non-discrimination and equal opportunity employment.The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Learn more about UVA’s commitment to non-discrimination and equal opportunity employment.

Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.