← All rolesCISO
Chief Information Security & Privacy Officer
University of Illinois Urbana-Champaign · Education · 10,000+ employees
Urbana, IL · Hybrid · full_time
Listed by the employer as “Deputy Chief Information Officer, Chief Information Security & Privacy Officer”. Title normalized for comparability.
CLI Career Level
Senior Director-equivalent
Moderate confidence
Opportunity Score
78/100
Above average
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 17, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — CISO (US)
CLI Take
Narrower than the title suggests
Titled “Deputy Chief Information Officer, Chief Information Security & Privacy Officer”, but the described remit reads Senior Director-equivalent; the seniority of the title is not matched by the scope on the page. The role carries more scope than the employer's title suggests, and it reports to Chief Information Officer and carries FERPA and HIPAA accountability. Team size is not disclosed and remains the main open question before pursuing it.
Why this role scores the way it does
78/100 — above average opportunity quality. CLI reads this as a Senior Director-equivalent mandate. Strongest signal: The role carries more scope than the employer's title suggests. 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Senior Director-equivalent — The employer lists this as “Deputy Chief Information Officer, Chief Information Security & Privacy Officer”. CLI reads it as Senior Director-equivalent because the role shows reports to a C-level executive, 10,000+ employee organization.
Moderate confidence
What makes it attractive
- The role carries more scope than the employer's title suggests.
- Employer profile: 10,000+ employee organization, government ownership, not applicable, revenue 1b 10b.
- The role reports to a C-level executive.
- CLI's analysis reads this as steady-state ownership rather than a build mandate.
What to probe before applying
- No material concerns identified in the posting.
Scoring components · Above average
Compensation versus comparable roles55 · weight 15%
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
Reporting level71 · weight 12%
The role reports to a C-level executive.
Functional and geographic scopeNot disclosed · excluded from the score
Scope: no enterprise, global or multi-unit remit is described.
Quality of the mandate70 · weight 12%
CLI's analysis reads this as steady-state ownership rather than a build mandate.
Executive and board exposureNot disclosed · excluded from the score
Executive and board exposure: not disclosed.
Role authority versus title100 · weight 10%
The role carries more scope than the employer's title suggests.
Company scale and trajectory100 · weight 10%
Employer profile: 10,000+ employee organization, government ownership, not applicable, revenue 1b 10b.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals100 · weight 5%
No adverse signals identified in the posting.
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$210,000 – $265,000 base salary, disclosed by employer
Sample size not yet sufficient for a market comparison
Direct oversight of the Identity, Privacy, and Cybersecurity group budget.
See the full benchmark bands by level and region
The mandate
The CISO/PO will provide campus-wide leadership for a comprehensive cybersecurity, identity and access management, and privacy program. They are responsible for setting multiyear roadmaps, leading institutional incident response, and ensuring compliance with evolving regulations for a major Research 1 institution.
Reporting to the CIO, this leader directs the Identity, Privacy, and Cybersecurity group with institutional remit over 59,000 students and 15 colleges. The role covers enterprise security, privacy, and identity management across academic, research, and administrative functions.
Scope
- Reports to Chief Information Officer
Domains and regulation
- Enterprise Security
- Cyber Defense
- Incident Response
- Identity
- Privacy
- GRC
- Research Data Security
- Cloud Security
- FERPA
- HIPAA
- SOC 2
Requirements
Must have
- Bachelors degree.
- Ten years of professional experience in IT, IT administration, or risk management.
- Significant responsibility in cybersecurity/information security.
- Five years of management experience in information technology.
- Demonstrated experience leading organization-wide and complex, cross-organizational initiatives.
- Demonstrated experience in budgetary and programmatic planning.
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Navigating security and privacy compliance within a Research 1 (R1) institution's academic and research missions.
- Overseeing security posture across diverse on-premise, cloud, and third-party platforms.
- Leading campus-wide incident response and serving as the primary point of contact for law enforcement and external complaints.
- Managing multi-year roadmaps for identity and access management in a complex, decentralized university environment.
Not stated in the posting: Board exposure not explicitly mentioned (though advisory to senior leadership is stated)..
About University of Illinois Urbana-Champaign
The University of Illinois Urbana-Champaign is a major public research university and the flagship institution of the University of Illinois system. It serves over 50,000 students and manages a significant research enterprise, including advanced computing facilities like the National Center for Supercomputing Applications. The security environment involves protecting a massive distributed network, sensitive academic research, and complex regulatory compliance requirements.
- Industry
- Education
- Headcount
- 10,000+ employees
- Headquarters
- Urbana, IL
- Founded
- 1867
- Ownership
- Government
- Funding
- Not applicable
- Revenue
- $1B – $10B
Full company profile for University of Illinois Urbana-Champaign →
View original job description
Office of the Chief Information OfficerThe University of Illinois Urbana-Champaign seeks an exceptional Chief Information Security and Privacy Officer to provide campus-wide leadership for a comprehensive cybersecurity, identity and access management, and privacy program that supports the university’s academic, research, and administrative missions. The ideal candidate is a strategic, collaborative leader with deep experience in cybersecurity and risk management, proven ability to guide policy and governance in a complex environment, and a deep commitment to operational excellence. This individual will set multiyear roadmaps, lead institutional incident response, partner closely with university counsel and campus leadership, and ensure compliance with evolving regulatory requirements for a major Research 1 institution. Candidates should bring substantial management experience; demonstrated success communicating with both technical and non-technical audiences; and the judgment, integrity, and relationship-building skills required to advance a resilient, forward-looking security posture for the university. Hybrid work options may be available for this position, with the ability to be on-site at the University of Illinois Urbana-Champaign campus as needed per the University’s Workplace Flexibility policy. Sponsorship for work authorization is not available for this position.Why Work at Technology Services?Highlights of Employee BenefitsJob Summary The Chief Information Security and Privacy Officer (CISO/PO) provides institution-wide leadership in developing and implementing comprehensive strategies for information security and privacy at the University of Illinois Urbana-Champaign. This executive role supports academic, research, and administrative functions while ensuring compliance with applicable laws, regulations, policies, and industry best practices. Duties & Responsibilities University & Program Leadership Prioritize privacy and security risk management in alignment with institutional risk frameworks and institutional missions. Lead the development of multi-year roadmaps for information security, identity and access management, and privacy across on-premise, cloud, and third-party platforms. Serve as the primary institutional advocate for privacy, promoting awareness and integration of privacy principles into technology, processes, and training. Advise university counsel, senior leadership, and stakeholders on information security and privacy matters. Direct the Identity, Privacy, and Cybersecurity group, including budget oversight and personnel management. Collaborate with other Technology Services groups and staff to enhance risk mitigation strategies. Support strategic planning and ensure alignment with organizational goals. Partner with university leaders, governance bodies, and technologists to strengthen foundational IT capabilities through strategic investments and resource planning. Supervises and supports staff through regular guidance, coaching, and performance management to ensure quality service and operational excellence. Travel may be required. Risk Management & Incident Response Oversee and mature risk management processes across the university and the University of Illinois System. Lead campus-wide information security and privacy incident response programs. Serve as the official point of contact for security incidents, including coordination with law enforcement. Collaborate with university counsel and System leadership on policy violations and external complaints. Monitor compliance with privacy laws and regulations including FERPA, HIPAA, GDPR, and institutional policies. Maintain awareness of emerging threats and develop strategies to mitigate their impact on university operations. Institutional Compliance & Policy Lead the development and maintenance of institutional policies, standards, and procedures related to information security and privacy. Ensure policies reflect current legislation and regulatory requirements relevant to a Research 1 institution. Minimum Qualifications Bachelors degree. Ten years of professional experience in IT, IT administration, or risk management, with significant responsibility in cybersecurity/information security. Five years of management experience in information technology. Demonstrated experience leading organization-wide initiatives. Demonstrated experience in budgetary and programmatic planning. Demonstrated experience managing complex, cross-organizational initiatives. Leadership experience in information security. Preferred Qualifications Advanced degree in information technology, information security, privacy, or a related field. Five years of experience in one or more domains of information security or privacy. Leadership experience in a complex institution encompassing teaching, research, or administration. Demonstrated commitment to diversity, equity, and inclusion in service delivery. Professional certifications such as CISSP, CRISC, CISM, CIPP/US, or CIPM. Knowledge, Skills and Abilities Demonstrated ability to maintain high security/privacy controls when dealing with sensitive information. Strong communication and interpersonal skills to communicate effectively with all levels of campus community, both verbally and in writing. Strong knowledge of institutional funding, financial management, and budgeting within a complex IT environment. Highly developed standards of professional conduct and customer service including, but not limited to: accountability, acceptance of new challenges and responsibilities, and a focus on customer needs and prompt, accurate resolution of issues. Demonstrated ability to lead and mentor staff, set priorities, and oversee cybersecurity needs across campus. Understanding of privacy management programs. Appointment InformationThis is a 100% full-time Academic Professional position, appointed on a 12-month basis. The expected start date is as soon as possible after the closing date. The budgeted salary range for the position is $210,000 to $265,000. Salary is commensurate with experience. Hybrid work options may be available for this position, with the ability to be on-site at the University of Illinois Urbana-Champaign campus as needed per the University’s Workplace Flexibility policy. Sponsorship for work authorization is not available for this position.Application Procedures & Deadline InformationNext Generation Leadership Partners has been retained to support this search. All inquiries, expression of interest and applications should be directed to them. Applications must be received by 6:00 pm (Central Time) on October 15, 2026. Applicants should submit a resume and cover letter to Next Generation via this site - https://recruitcrm.io/apply/17881899121780065590vKq . Applications not submitted through Next Generation will not be considered.To make confidential inquiries or provide a candidate nomination - please contact Phil Goldstein at phil@nextgenpartnersllc.com .At the University of Illinois Urbana-Champaign — the state’s flagship public university and one of the world’s leading research institutions — every staff member helps shape what’s next. Founded in 1867, Illinois is home to a vibrant community of 59,000 students from all 50 states and 129 countries, supported by 15 colleges and instructional units, more than 20 research institutes, and one of the most comprehensive student service ecosystems in the nation. Whether you’re empowering first-generation students, fueling breakthrough innovation, or strengthening communities across Illinois and beyond, your work here has a far-reaching and deeply meaningful impact. The university offers a highly competitive benefits package designed to support your well-being, growth, and financial security. Join a top 10 public university that has launched over 330 startups and continues to redefine excellence — where the Illinois Value Proposition ensures that your contributions are recognized, your potential is nurtured, and your career can thrive.Champaign-UrbanaArtificial Intelligence (AI) tools may be used in some portions of the candidate review process for this position; however, all employment decisions will be made by a person.This position is intended to be eligible for benefits . This includes Health, Dental, Vision, Life Insurance, a Retirement Plan, Paid time Off, and Tuition waivers for employees and dependents.The University of Illinois System is an equal opportunity employer, including but not limited to disability and/or veteran status, and complies with all applicable state and federal employment mandates. Please visit Required Employment Notices and Posters to view our non-discrimination statement and find additional information about required background checks, sexual harassment/misconduct disclosures, and employment eligibility review through E-Verify .Applicants with disabilities are encouraged to apply and may request a reasonable accommodation under the Americans with Disabilities Act (2008) to complete the application and/or interview process. Accommodations may also be requested on the basis of pregnancy, childbirth, and related conditions, or religion. Requests may be submitted through the reasonable accommodation portal , or by contacting the Office for Access & Equity at 217-333-0885, option #1, or accessibility@illinois.edu .Requisition ID: req17965Job Category: Professional and Administrative
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.