Chief Information Security Officer
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Location: Albany or New York City, NY Category: Professional Positions Job Type: Full-time Job Description: The Chief Information Security Officer (CISO) serves as the leading authority on information security within the State University of New York (SUNY) System. The CISO establishes and advances systemwide information security governance by translating Board-approved policies into actionable standards, procedures, and guidance that are implementable across diverse campus environments.
This includes aligning SUNY’s cybersecurity program with recognized frameworks (e.g., NIST), and developing and maintaining core governance functions such as compliance attestation, standards management, third-party risk oversight, incident coordination, and campus support. Collectively, these activities form an integrated approach to managing shared cybersecurity risk across institutions with varied operations, resources, and technical environments.
The CISO also plays a central role in shaping SUNY’s long-term cybersecurity strategy. This includes evaluating and defining the appropriate balance between centralized services and campus-level responsibilities; guiding the development of a sustainable security operations model; and ensuring coordination across key capabilities such as identity and access management, logging, threat detection, and incident response. In addition, the CISO serves as a senior advisor to system leadership on emerging and enterprise-level risks, including artificial intelligence governance, large-scale data initiatives, identity management, and third-party/vendor risk.
The role emphasizes strategic coordination across policy, funding, and operational domains to ensure that cybersecurity capabilities are scalable, sustainable, and aligned with systemwide priorities.
- Develop and execute a comprehensive cybersecurity strategy aligned with SUNY’s mission, goals, and risk tolerance while providing strategic guidance to SUNY leadership on emerging cybersecurity threats, trends, and industry best practices.
- Direct and implement a comprehensive cybersecurity risk management framework that quantitatively assesses potential impacts on SUNY’s mission and operations.
- Advise on security-affecting decisions and initiatives to align with SUNY’s overall strategic objectives.
- Provide leadership and direction to IT and Security Operations teams to administer security operations effectively, including monitoring, threat intelligence, incident response, vulnerability management and collaboration & intelligence sharing with New York State and other partners.
- Establish strong and trusting relationships with leadership at SUNY campuses and SUNY affiliated entities.
- Maintain consistent engagement with leadership at SUNY campuses and SUNY affiliated entities that will foster collaboration and cooperation for SUNY cybersecurity priorities and strategies.
- Oversee incident response activities, ensuring timely notifications and effective response to security incidents and breaches.
- Collaborate with the SUNY Risk and Compliance Office to ensure risk assessments are performed and recommend measures to mitigate information security risks.
- Oversee the SUNY Information Security Working Group, a cybersecurity group comprising internal and external stakeholders to gain diverse insights on security strategies.
- Advise on University-wide initiative on matters related to Information Security.
- Provide guidance and advice around risk assessment and management processes across academic and administrative programs, ensuring alignment with organizational objectives.
- Engage with key functional programs and stakeholders to advocate for the uniform application of SUNY information security policies and standards across all technology-based projects, systems, and services, while ensuring SUNY’s compliance with relevant laws, regulations, and industry standards through enhancing and adapting the information security management framework.
- Foster awareness of information security threats and risks while promoting adherence to applicable laws and regulations.
- Coordinate with SUNY Counsel and functional office experts to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).