Information Security Manager - City

Oklahoma City

Apply for this job

Job Description

View More Jobs

Information Security Manager - City

Oklahoma City, OK, United States

(Hybrid)

Job Description

PAY AND FAIR LABOR STANDARDS ACT (FLSA) STATUS:Pay Range: 521Hourly Rate: $45.71 - $69.89 FLSA Status: ExemptThe normal starting pay for this position is the minimum of the pay range listed above. A higher rate of pay may be considered, dependent on the qualifications and experience of the selected applicant and/or the City's step placement policy.OVERAGE POSITIONThis position is an overage. Funding for this position will be re-evaluated on a fiscal year basis.APPLICATION, HIRING, AND BACKGROUNDWhen completing the application, applicants will be asked to respond to application questions. These application questions are based on the Job Requirements for the position. Completion of the application questions is required. Applicant responses to the application questions must specifically answer the questions asked. Responses to application questions must be supported by work history/information listed on the application/resume, sufficient to demonstrate qualifications for the position. Applicants may upload only two attachments. Attachments may include, but are not limited to a resume, cover letter, DD214 or NGB Form 22, transcripts, etc. Applicants may also choose to combine documents into one file for upload. Applications may not be reviewed if specific responses to application questions have not been provided.Each application submission is reviewed independently. For detailed information about the City's hiring and background processes, check out the: Quick Guide to Hiring and Background ChecksIf you have questions, check out the: Frequently Asked QuestionsTOTAL REWARDSAt the City of Oklahoma City, our Total Rewards package is designed to honor your service, fuel your growth, and support every part of your life. We offer:Competitive payAn average of $22,000 annually contributed toward your benefits and retirementA comprehensive package designed to support your health and wellness, financial security, work-life balance, and personal and professional growth and developmentExplore all the ways we invest in you: City of Oklahoma City Total RewardsPOSITION DESIGNATIONSThis job classification has been designated as a safety sensitive job classification in accordance with the Oklahoma Medical Marijuana and Patient Protection Act, 63 O.S., § 427.1 et seq., (OSCN 2019), effective August 29, 2019. This means employees in this job classification can be subject to disciplinary action up to and including termination if they test positive for marijuana components or metabolites, even if they possess a medical marijuana license.This job classification has been designated as a cyber security sensitive job classification effective June 26, 2023, in order to comply with United States Department of Justice, Federal Bureau of Investigation, Criminal Justice Information Services (CJIS) Division's Criminal Justice Information Services Security Policy (Version 5.9.2, 12/07/2022), 5.12 Policy Area 12 Personnel Security. The policy requires national fingerprint-based records checks be conducted prior to granting access to criminal justice information for all personnel who have unescorted access to unencrypted Criminal Justice Information (CJI) or unescorted access to physically security locations or controlled areas (during times of CJI processing). Employees in this job classification will be subject to a Criminal Justice Information Services (CJIS) Interstate Identification Index (III) Fingerprint Background check after receiving a conditional offer of employment. Additionally, employees in this job classification must complete the required CJIS Security and Privacy Training and pass the online certification test. JOB SUMMARYThe position is located in the Technology Security Division of the Information Technology Department within the City of Oklahoma City and reports to the Chief Information Security Officer. The Information Security Manager is primarily responsible for implementing new security efforts and managing existing city-wide security efforts; and managing risk assessment, risk mitigation and system recovery plans essential to ensure a desired level of information system readiness to support continuity of government operations.ESSENTIAL JOB FUNCTIONSIdentifies and fosters skills needed to implement, maintain, and use technology.Oversees and manages problem resolution for enterprise level issues.Assesses risk associated with technical decisions and making appropriate recommendations based on risk.Develops strategic vision for cybersecurity at the department level that aligns with business strategies.Conducts research and formulating new theories and concepts to solve problems with technology systems.Develops long-range goals, planning and methodologies for emerging technologies.Directs and coordinates all activities associated with providing cybersecurity support to City systems.Coordinates user training of City staff in security policy and compliance.Develops program goals and objectives and prepares various administrative reports and budgets.Collaborates with system users, departmental managers, technical staff, vendor representatives, and administrators from other agencies.Performs designee functions in the absence of the Chief Information Security Officer.Performs other duties as assigned.VETERANS PREFERENCEHonorably discharged veterans of the United States Active Duty Armed Forces, National Guard, and Reserve Forces who are not currently employed full-time by the City of Oklahoma City and who meet the qualifications for the position shall be given preference. To receive preference, veterans must submit verification of honorable discharge from the United States military service (Department of Defense Form DD214 or NGB Form 22) prior to the closing date of the vacancy announcement. MINIMUM QUALIFICATIONSMinimum of eight (8) years progressively responsible experience in Cybersecurity.Bachelor's degree or higher in Management Science and Computer Systems, Management Information Systems, Cybersecurity, or field related to the position; or equivalent combination of education and experience, substituting one year of experience in Cybersecurity for each year of education required.Possession of a current Cybersecurity certification.KNOWLEDGE, SKILLS, AND ABILITIESKnowledge of securing systems to include web, database, and remote access systems.Knowledge of Data Loss Prevention.Knowledge of penetration and vulnerability testing.Knowledge of Security Information and Event Management (SIEM) and other logging systems.Knowledge of Privileged Identity Management (PIM).Knowledge of Federal Regulatory bodies, such as NIST, TSA, CJIS, PCI, HIPAA.Knowledge of enterprise systems, implementation, and maintenance.Knowledge of enterprise level anti-virus and anti-malware solutions.Knowledge of leadership and management methods and techniques.Skill in project management, systems design and implementation.Skill in performing cost/benefit analysis.Skill in creating, identifying, and establishing policies, processes, and practices.Skill in direct supervision of professional and technical staff.Skill in the evaluation of information hardware and software products.Skill in analyzing, researching, interpreting, and reporting information security trends.Skill in conveying technical concepts, presentations, and information to non-technical personnel in a clear and understandable form, both verbally and in writing.Ability to understand technology and apply it to current business needs.Ability to determine potential financial impact associated with risks and vulnerabilities.PREFERRED QUALIFICATIONSDemonstrated proficiency in GRC frameworks, evidenced by active certifications such as CGRC (Certified in Governance, Risk and Compliance), CRISC (Certified in Risk and Information Systems Control), or CISA (Certified Information Systems).Proven ability to engage regulatory agencies, ensure compliance with industry standards (e.g., NIST RMF, ISO 27001, HIPAA, PCI-DSS), and act as primary liaison for auditors during compliance reviews and assessments.Proven ability to audit IT systems, data, and processes for compliance, risk, and security controls; plan, execute, and report on internal and external audits with timely remediation; and develop and maintain audit documentation, evidence collection, and control testing cadence to drive operational change and risk reduction.Demonstrated skill in conducting enterprise-wide risk assessments, defining and reporting on KRIs and KPIs to support risk-based decisions, and developing, implementing, and enforcing information security policies aligned with business objectives and regulatory requirementsProven experience leading cross-functional governance and compliance groups, translating complex security requirements for diverse stakeholders, and mentoring security professionals to foster continuous improvement and compliance.COMPETENCIESOne City, One Team (Teamwork/Team Oriented) (1) Recognizes, values, and leverages the ideas, opinions, and perspectives of others; (2) participates willingly and effectively as a team lead or team member; (3) builds consensus; fosters team commitment, spirit, pride, and trust; (4) collaborates with others to accomplish goals and objectives and achieve results; (5) expresses facts, ideas, messages, and information (technical and non-technical) to individuals or groups clearly, concisely, accurately, understandably, with honesty, tact, and diplomacy and in a manner that is appropriate for the intended audience; (6) actively listens, clarifies information as needed; (7) [Core Value One City, One Team] shares information, resources and solutions across departments; (8) [Core Value One City, One Team] asks for help early and offers it often; (9) [Core Value One City, One Team] collaborates across teams before decisions are made.Service First (Customer Centric) (1) Demonstrates comm

Newest government jobs in Oklahoma