Chief Information Security Officer



Job Details

Chief Information Security Officer
Employer

State of South Carolina

Salary

$71,982.00 - $133,179.00 Annually

Job Type

FTE - Full-Time

Job Number

76406

Department

Department of Revenue

Division

CISO

Opening Date

05/01/2018

Closing Date

Continuous

FLSA

Determined by Position

Bargaining Unit

n/a

Standard Header - 17May24

Job Responsibilities

Chief Information Security Officer (CISO): Under limited direction, manages the South Carolina Department of Revenue's information security program to prevent, detect, respond to and recover from unauthorized exposure of information assets. Develops, sustains and enforces the agency's information security strategy, policies and standards. Coordinates responses to threats to information assets. Manages compliance with requirements of federal, state and industry authorities. Informs senior management of information security risk status and engages them in security decisions. Oversees the agency's business continuity and disaster recovery program.

Governance, Risk and Compliance: Manages the agency's information security policies, standards, enterprise security plan, risk management,  metrics, reports and enforcement. Responsibility for compliance with external authorities, including: IRS, CJIS, PCI DSS, legislative and executive orders and the SC Division of Information Security. Responsibility for reviews, audits, assessments, findings, remediation and exceptions/variances.

Security Engineering and Operations: Manages all aspects of information security architecture, including planning, design, review and enforcement. Maintains accountability for the agency's Network and Security Operations Center (NSOC) to include monitoring for cyber intrusions, compliance with security policies, security device integrity and IT system health. Responsibility for detecting and responding to threatening events, including security events and IT operational events.

Security Leadership by Influence: Establishes direction and influences aspects of information security that are not performed under direct control of the CISO Division, including IT systems (CIO), employee awareness (Training), data privacy (Legal), vendor contracts (Procurement) and joint responsibilities with the SC Division of Information Security. 

Vendor and Partner Security: Establishes direction for information security aspects of vendor and partner relationships, including contracts, memorandums of understanding and statements of work. Responsible for information security oversight of vendors and partners, including requirements, evaluations, assessments and audits. 

Business Continuity: Oversees business continuity, disaster recovery and cyber security incident response processes to ensure that the agency is capable of responding to events that disrupt business or technical operations.

Staff Development: Develops information security staff skills and abilities. Develops information security staffing strategies, plans and practices to maintain a cyber security workforce. 

Minimum and Additional Requirements

A bachelors degree in engineering, computer science, information technology or a related field with a minimum of eight years of experience in information technology administration, project management or a related field. Four of the eight years must be in information security, information risk management, security compliance or information technology auditing. One of the following certifications is also required: CISSP, CISM, CRISC, CCISO.

Relevant experience may be substituted for bachelor's degree on a year-for-year basis.

Academic degrees must be from an accredited institution of higher learning.
 

Preferred Qualifications

Must provide leadership to interpret industry standards and governmental regulations.  Work in federal or state government or the financial industry is highly desirable.  Must possess a depth of knowledge and experience to make technical and administrative decisions with incomplete and subjective information and to respond to critical situations tha require immediate action.  Must work independently and be self-directed to set and meet objectives.  

KSA's: Broad managerial skills.  Ability to apply information security principles from an executive management point of view.  Ability to communicate security topics to all levels of audiences.  Expert security knowledge in the following areas: risk management, technical architecture, policies and controls, enterprise security plans, security assessments and audits, security governance, metrics and reporting, compliance with PCI DSS and NIST SP 800-53, vendor security management, SOC operations, incident response, employee security awareness, data privacy, and business continuity.  

Additional Comments

SCDOR employees are required to be in compliance with all SCDOR tax requirements and are subject to a National Criminal Background Check to include fingerprinting. 

During critical events, 24x7 support will be required.  

Standard Footer- 17May24

Benefits for State Employees

State Employees may be eligible for a variety of benefits associated with their employment. From a comprehensive health and dental insurance program, to generous annual and sick leave policies, to a solid and secure retirement system, the State of South Carolina offers a competitive benefits program for state employees. To learn more about the benefits of state employment, please explore the links below:

Healthcare Benefits
The State offers its employees comprehensive health insurance, along with a variety of supplemental insurance programs including dental, vision, life, long-term disability, and health savings accounts. South Carolina has long been committed to providing its employees the best insurance benefits at the greatest possible value. We've maintained that commitment, too, even in the face of healthcare costs that continue to soar.


Retirement Benefits
State employees are also offered a generous retirement program with options that can be tailored to meet employees' needs. South Carolina offers a traditional pension program, as well as deferred compensation options that give employees more control over their retirement investments. These programs are designed to help provide state employees secure retirement alternatives that will best meet their needs.

Workplace Benefits
In addition, state employees may be eligible for other benefits, such as tuition assistance; holidays, annual leave, and sick leave; and discounts on purchases, travel and
more. Check out the link above to see a summary of the other benefits that are available to state employees.

Note: The above benefits are available to most state employees, with the exception of those in temporary positions. Employees in temporary grant and time-limited positions may be eligible for all, some, or none of these benefits based on the benefits associated with each position. For these positions, please contact the hiring agency to determine what benefits may be available for the particular position.

Updated

01
Are you currently employed by the SC Department of Revenue?
  • Yes
  • No
02
Please type in your full legal name (First, Middle, Last) as it appears on your Driver's License or State issued Identification Card.
03
Do you have a bachelors degree in engineering, computer science, information technology or a related field
  • Yes
  • No
04
How many years of experience do you have in information technology administration, project management, or a related field?
  • 12 years or more
  • 10 - 11 years
  • 8 - 9 years
  • Less than 8 years
  • No Experience
05
Do you have four years of experience in information security, information risk management, security compliance, or information technology auditing?
  • Yes
  • No
06
Do you have any of the following certifications? Select all that apply.
  • CISSP
  • CISM
  • CRISC
  • CCISO
  • None of the above
07
Do you have previous work experience in federal or state government or the financial industry?
  • Yes
  • No

* Required Question

Employer
State of South Carolina
Address
O'Fallon Sta Dr
O'Fallon
O' Fallon, Missouri, 63366
Phone
(803) 896-5300
(803) 896-5308

The language used in this document does not create an employment contract between the employee and the agency. This document does not create any contractual rights or entitlements. The agency reserves the right to revise the content of this document, in whole or in part. No promises or assurances, whether written or oral, which are contrary to or inconsistent with the terms of this paragraph create any contract of employment.

Apply

OnlineApplication

Warning! You are using Internet Explorer 8. Some features of the Online Application are not fully supported in this version. Please upgrade to a later version of Internet Explorer for optimal performance.

Loading ...