{"21544071":{"jobPath":"/jobs/21544071/financial-administrator-its-and-libraries","source":"naylor","job":"21544071","jobTitle":"Financial Administrator - ITS and Libraries"},"21547360":{"jobPath":"/jobs/21547360/security-lieutenant","source":"naylor","job":"21547360","jobTitle":"Security Lieutenant"},"21548251":{"jobPath":"/jobs/21548251/risk-manager","source":"naylor","job":"21548251","jobTitle":"Risk Manager"},"21544154":{"jobPath":"/jobs/21544154/lms-platform-administrator-health-sciences-it-edtech","source":"naylor","job":"21544154","jobTitle":"LMS PLATFORM ADMINISTRATOR, Health Sciences IT & EdTech"},"21544075":{"jobPath":"/jobs/21544075/senior-associate-athletics-director-governance-regulatory-affairs","source":"naylor","job":"21544075","jobTitle":"Senior Associate Athletics Director, Governance & Regulatory Affairs"},"21547227":{"jobPath":"/jobs/21547227/site-protection-security-system-technician","source":"naylor","job":"21547227","jobTitle":"Site Protection Security System Technician"},"21545248":{"jobPath":"/jobs/21545248/records-manager-and-information-governance-specialist","source":"naylor","job":"21545248","jobTitle":"Records Manager and Information Governance Specialist"},"21542132":{"jobPath":"/jobs/21542132/graduate-instructor-advanced-auditing","source":"naylor","job":"21542132","jobTitle":"Graduate Instructor- Advanced Auditing"},"21545317":{"jobPath":"/jobs/21545317/security-coordinator","source":"naylor","job":"21545317","jobTitle":"Security Coordinator"},"21544009":{"jobPath":"/jobs/21544009/security-officer-part-time","source":"naylor","job":"21544009","jobTitle":"Security Officer Part-Time"},"21548308":{"jobPath":"/jobs/21548308/assistant-professor-of-cyber-security","source":"naylor","job":"21548308","jobTitle":"Assistant Professor of Cyber Security"},"21547219":{"jobPath":"/jobs/21547219/adjunct-faculty-in-cybersecurity","source":"naylor","job":"21547219","jobTitle":"Adjunct Faculty in Cybersecurity"},"21550946":{"jobPath":"/jobs/21550946/project-scientist-series-uci-its-2025-26","source":"naylor","job":"21550946","jobTitle":"Project Scientist Series UCI ITS 2025-26"},"21550427":{"jobPath":"/jobs/21550427/research-resources-it-systems-analyst","source":"naylor","job":"21550427","jobTitle":"Research Resources IT Systems Analyst"},"21547174":{"jobPath":"/jobs/21547174/adjunct-faculty-in-information-technology","source":"naylor","job":"21547174","jobTitle":"Adjunct Faculty in Information Technology"},"21548120":{"jobPath":"/jobs/21548120/firewall-security-engineer-fortinet-cloud","source":"naylor","job":"21548120","jobTitle":"Firewall Security Engineer (Fortinet & Cloud)"},"21545354":{"jobPath":"/jobs/21545354/chief-information-security-officer-ciso","source":"naylor","job":"21545354","jobTitle":"Chief Information Security Officer (CISO)"},"21546442":{"jobPath":"/jobs/21546442/ai-governance-and-ops-coord-ent","source":"naylor","job":"21546442","jobTitle":"AI Governance and Ops Coord-ENT"},"21543033":{"jobPath":"/jobs/21543033/clinical-research-informatician-hdip-is-clinical-research-full-time-8-hour-days-exempt-non-union","source":"naylor","job":"21543033","jobTitle":"Clinical Research Informatician (HDIP) - IS Clinical Research - Full Time 8 Hour Days (Exempt) (Non-Union)"},"21544004":{"jobPath":"/jobs/21544004/senior-director-of-planning-analytics-and-risk-management","source":"naylor","job":"21544004","jobTitle":"Senior Director of Planning, Analytics, and Risk Management"},"21542654":{"jobPath":"/jobs/21542654/degree-audit-specialist","source":"naylor","job":"21542654","jobTitle":"Degree Audit Specialist"},"21547924":{"jobPath":"/jobs/21547924/union-security-officer-i-1209-dekalb","source":"naylor","job":"21547924","jobTitle":"Union Security Officer I - 1209 DeKalb"},"21542956":{"jobPath":"/jobs/21542956/senior-analyst-it-client-support","source":"naylor","job":"21542956","jobTitle":"Senior Analyst, IT Client Support"},"21550313":{"jobPath":"/jobs/21550313/security-officer-part-time","source":"naylor","job":"21550313","jobTitle":"Security Officer Part-Time"},"21550576":{"jobPath":"/jobs/21550576/dispatcher-security-guard","source":"naylor","job":"21550576","jobTitle":"Dispatcher, Security Guard"}}
Chief Information Security Officer (CISO) | Information Technology
The Rockefeller University
Application
Details
Posted: 05-Aug-25
Location: New York, New York
Internal Number: 1893
Organization Overview
The goal of Information Technology (IT) is to provide information resources and services to accelerate and support scientific research at The Rockefeller University. Our department is responsible for cyberinfrastructure,high-performance computing,bioinformatics,decision support,data analytics,cybersecurity,and the scientific and administrative software environment at the university. The department is in the midst of a major transition in culture,including the adoption of DevOps and Agile practices,the facilitation of self-service approaches,as well as a 'cloud first' deployment philosophy. Overview
Rockefeller University is seeking a strategic and forward-thinking Chief Information Security Officer (CISO) to lead and manage the university’s information security program. Reporting to the Chief Information Officer (CIO), and working with the IT leadership team and members of the university’s administration, the CISO will build upon the university’s current security strategy to safeguard sensitive research data, regulated information, and infrastructure across academic and administrative domains.
The ideal candidate will have experience in academic or research-intensive environments, a deep understanding of emerging cybersecurity threats—including those involving AI—and demonstrated success in integrating security practices within modern DevSecOps frameworks.
Responsibilities
Key responsibilities include, but are not limited to the following:
Define and lead the university’s enterprise-wide information security strategy to support and advance research and business goals.
Develop, implement, and maintain policies and procedures aligned with research compliance, grant requirements, and federal regulations (e.g., NIST 800-171, NIH GDS, , GDPR, FISMA).
Identify and assess cybersecurity risks to scientific data, research systems, and enterprise infrastructure. Work with stakeholders to communicate, manage, and mitigate risks.
Work with Human Resources, the Office of General Counsel, external partners, and other stakeholders to support litigation hold implementations.
Oversee cybersecurity incident response planning activities; investigate and manage response to security breaches as needed.
Continuously evaluate and improve defenses against evolving threats, including those driven by generative AI and adversarial ML techniques.
Implement scalable DevSecOps pipelines for secure code development, vulnerability scanning, and automated compliance testing.
Stay abreast of how AI is both leveraged for cyberattacks (e.g., phishing, deepfakes, LLM-based social engineering) and as a defensive tool (e.g., anomaly detection, threat intelligence).
Cultivate a campus-wide culture of cybersecurity awareness through regular training and communication.
Provide tailored guidance to faculty, lab managers, and data custodians handling sensitive and/or regulated datasets.
Manage audits and assessments of security posture and readiness.
Support and champion the university’s data classification program; additional duties and special projects as assigned.
Qualifications
REQUIRED QUALIFICATIONS:
Master’s degree in computer science, cybersecurity, information systems, or a related field. A minimum of ten (10) years of progressive experience in information security leadership roles.
Must possess a deep knowledge of cybersecurity frameworks (e.g., NIST CSF, ISO 27001), federal research security requirements, and risk management practices. Experience with implementing practical security controls in Bring-Your-Own-Device (“BYOD”) environments.
Prior experience with securing hybrid (cloud computing and on premises) computing and storage environments, and a desire to support the university’s goal to embrace a “cloud first” transformative strategy. Familiarity with the cybersecurity implications of artificial intelligence and machine learning.
A demonstrated ability to lead diverse technical teams and communicate effectively with researchers, faculty, executives, and auditors.
Prior direct support of scientific research infrastructure, including high-performance computing (HPC), lab systems, or genomic data platforms.
Prior hands-on experience integrating security into agile development environments.
PREFERRED QUALIFICATIONS:
Advanced degree is preferred.
Prior experience in an academic or biomedical research setting strongly preferred.
Experience deploying and managing DevSecOps pipelines and tools (e.g., CI/CD security scanning, container security, IaC validation) is preferred.
The Rockefeller University is an equal opportunity employer – veterans/individuals with disabilities. Qualified applicants will receive consideration for employment without regard to characteristics protected by applicable local, state or federal law, including but not limited to disability and protected veteran status.
The salary of the finalist selected for this role will be set based on various factors, including but not limited to organizational budgets, qualifications, experience, education, licenses, specialty, and training. The hiring range provided represents The Rockefeller University's good faith and reasonable estimate of the range of possible compensation at the time of posting.
The Rockefeller University is a world-renowned center for research and graduate education in the biomedical sciences, chemistry, bioinformatics and physics. The university's 72 laboratories conduct both clinical and basic research and study a diverse range of biological and biomedical problems with the mission of improving the understanding of life for the benefit of humanity.