Description JOB DEFINITION: Develops, implements, and monitors a strategic, comprehensive enterprise cybersecurity and IT risk management program; oversees the Agency's technology infrastructure, ensuring that systems and services operate reliably and securely; provides vision and leadership necessary to manage the risk to the organization and ensures business alignment, effective governance, system and product availability, integrity, and confidentiality; ensures compliance with regulations to protect IT systems and data; oversees and directs internal and external IT staff resources; responsible for the oversight and performance evaluation of all IT Vendors and the IT Manager. Examples of Duties EXAMPLE OF DUTIES: Duties include, but are not limited to: Drives strategic direction for the Agency's data and cybersecurity protection and oversee Technology governance. Develop and implement the Agency's IT strategy in alignment with overall business objectives and comprehensive cybersecurity strategies to protect the organization from cyber threats.
Collaborate with other executives to integrate technology into various business functions. Conduct regular risk assessments to identify vulnerabilities in technology systems used Agency-wide and develop strategies to mitigate these risks. Lead the response to cybersecurity incidents, including detection, containment, eradication, and recovery, while developing and maintaining incident response plans.
Define and maintain IT and cybersecurity policies, procedures, and standards to ensure compliance with relevant legal and regulatory requirements. Serves as the District's CISO. Develop and maintain IT and cybersecurity policies and procedures, incident response planning, and backup and disaster recovery planning, including periodic testing.
Responsible for vendor security oversight and periodic risk reporting to executive leadership. Manage relationships with third-party vendors and service providers to ensure the effectiveness of technology and security solutions; negotiate contracts. Builds and presents executive-level reporting for technology investment and risks to management and board of directors Develops and oversees effective disaster recovery policies and standards to align with company business continuity management program goals.
Coordinates development of implementation plans and procedures to ensure business critical services are recovered in the event of disasters or other incidents, and provides direction, support and in-house consulting in these areas. Provides project management and leadership to staff and external resources in support of established goals and objectives, improved efficiencies, and problem resolution. Analyze the costs, value and risks of information technology and security solutions to advise management and suggest actions.
Prepare annual technology and security budgets including capital expenditure requests. Maintains current knowledge of industry and regulatory trends and developments for the Agency's technology. Typical Qualifications QUALIFICATIONS: Schooling: Bachelor's degree from an accredited institution, with degree preferred in Computer Science, Information Technology, Cybersecurity, or a related field.
Master's degree preferred. Certification(s): Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) Certification. Experience: Minimum 10 years of experience in the field of IT and Cybersecurity with at least the last 2 years within the Director level.
Minimum of 5 of those years responsible for cybersecurity. Proficiency in cybersecurity frameworks (e.g., NIST, ISO 27001), risk management, and incident response methodologies. Demonstrated management skills, e.g., budget development and administration, policy development and implementation, personnel administration, staff training and development
Demonstrated ability to work with diverse people; effective oral and written communication skills. License(s): Possession of a valid driver's license for use in conjunction with the possible operation of Agency vehicles, with an acceptable driving record. Obtain certification for use of Aerial Lift and Scissor Lift heavy equipment.
Knowledge of: Strong leadership and team management skills with the ability to prioritize, triage, resolve, and escalate in an efficient and effective manner; excellent communication and interpersonal abilities to collaborate with various stakeholders; In-depth knowledge of current cybersecurity threats and trends; Ability to develop and implement effective IT and cybersecurity policies and procedures; tangible understanding of worse-case practices, concepts and real-world application; advanced real-world application with Windows system and networking management and automation. Ability to: Work independently with little direction; understand and effectively carry out general oral and written instructions; prepare and give executive-level reports and updates to management and board of directors; give understandable oral and written instructions; instruct, train and manage personnel in technical functions; direct department personnel toward given objectives; analyze and solve a variety of technical problems; ability to communicate with patience, tenacity, and follow-through while tracking, troubleshooting and bringing to resolution internal customer support calls; able to explain advanced computer concepts, procedures and policies to non-technical users. Supplemental Information Generally, work is within the Agency Operations Center in an environment where the temperature is controlled.
The majority of the IT Department members work within an open space or in the confines of a cubicle. The IT Department is located within an enclosed office area which is separate from other departments, and which cannot be easily accessed by members of the general public. Lighting is overhead, the IT Department has an air cooling and heating system which is separate from the rest of the Operations Center and can be adjusted by the members of the department.
There is a music/paging system which is on and operating throughout the work day. There are a number of pieces of office equipment that operate within the confines of the IT area, including, but not limited to: computers, computer printers, shredding machine, bursting machine, billing preparation/enveloping system, and the server room.