Director of Information Security
Job Description
Pay Grade: 880 (Competitive Pay Based on Experience)
Qualifications:
Education/Certification:
- Bachelor’s degree in Computer Science, or related field.
- Five years of relevant work experience, with a minimum of three years in a senior management position where professional and management capabilities are clearly demonstrated
- Knowledge of applicable data privacy practices and laws
- Knowledge of best practices for gathering, analyzing, and meeting business requirements
- Knowledge of planning, organizing, and developing IT security and access control systems
- Knowledge of technology environments, including information security, building security, and defense software
- Knowledge of advanced project management principles, including the ability to manage multiple projects of diverse scope and budget
- Knowledge of applicable federal and state laws regarding education, as well as District policies and procedures, and understanding regulations as they relate to security
- Excellent verbal and written communication skills
- Ability to communicate with a broad base of end users and multiple management layers
- Ability to manage multiple priorities effectively
- Ability to develop and maintain effective working relationships
- Develops and facilitates an information security governance structure that is in alignment with the overarching IT governance structure
- Leads strategic security planning to achieve business goals by prioritizing defense initiatives, coordinating the evaluation, deployment, and management of current and future security technologies using a risk-based methodology
- Develops and communicates security strategies and action plans to all stakeholders, including the executive team, staff, and customers
- Assists with the design and implementation of disaster recovery and business continuity plans, procedures, audits, and enhancements
- Develops, implements, maintains, and oversees enforcement of policies, procedures, and associated plans for system security administration and user system access based on industry-standard best practices
- Defines and implements technology security visions through routine written and in-person communications with IT steering committees and District stakeholders
- Works closely with the technical staff to fully secure information, computer, network, and processing systems
- Manages the administration of all computer security systems including all corresponding or associated software, including firewalls, intrusion detection systems, cryptography systems, and next generation anti-virus software
- Assesses and communicates all security risks associated with any purchases or practices the District performs
- Develops and maintains an up-to-date information security management framework based on the National Institute of Standards and Technology (NIST) Cybersecurity Framework or other appropriate control framework
- Continues to acquire professional knowledge and learn of developments on trends and risks in the security industry, including current and emerging technologies
- Selects, develops, and motivates qualified staff to effectively carry out department functions and provide for the continuity of managerial and specialized skills
- Manage, direct, and assign priorities and personnel to major projects to ensure attainment of district and department goals and objectives
- Budget and manage cost by participating in annual budgeting, ongoing forecasting and making prudent procurement decisions
- Establish and maintain a high level of customer trust and confidence in the team’s knowledge of and concern for educational and business needs
- Be customer service oriented and maintain a professional approach regarding all district matters
- Perform R&D, remain knowledgeable of emerging trends in technology, and keep abreast of innovative practices. Attain and keep current, relevant technology certifications
- Perform special projects, after-hours support and upgrades, and other duties as assigned
- Supervise and evaluate the performance of staff assigned to the area of Cybersecurity.
Mental Demands:
- Reading; ability to communicate effectively (verbal and written); maintain emotional control under stress; work with frequent interruptions
- Frequent standing, stooping, bending, kneeling, pushing and pulling; prolonged use of computer and repetitive hand motions; occasional lifting up to 50 pounds
SM120125