Chief Information Security Officer (CISO)



Job Details

Chief Information Security Officer (CISO)
Employer

Orange County

Salary

$58.39 - $100.29 Hourly

Job Type

Full-Time Regular

Job Number

8014IT-0518-017 (O)

Department-xx

County Executive Office

Opening Date

05/18/2018

FLSA

Exempt

Bargaining Unit

N/A

Orange County Header- 26Dec24

Description


 
CHIEF INFORMATION SECURITY OFFICER
(Administrative Manager III, Specialty)

This recruitment is open to the public. This recruitment will be open for a minimum of five (5) business days and will remain open until the County's needs are met. Applicants are encouraged to apply immediately.

This recruitment will establish an open eligible list. This list will be used to fill current and future Administrative Manager III positions with this specialty. This recruitment may also be used to fill positions in similar and/or lower classifications throughout the County of Orange.

OFFICE OF INFORMATION TECHNOLOGY

The County of Orange, Office of Information Technology (OCIT) provides innovative Information Technology (IT) solutions across County departments and agencies for voice communications, network and Internet access, data center services, applications development and more. Key strategies for the department include implementation of a converged voice and data network, continuance of a managed services support model, technology centralization into shared services models, installing more citizen-centric access to County services and information, and raising cyber awareness, preparedness and response.

THE OPPORTUNITY

The Chief Information Security Officer (CISO) position reports directly to the Assistant Chief Information Officer (ACIO) and manages the design, development, implementation, operation and maintenance of Countywide information security programs which are designed to protect the confidentiality, integrity, and availability of all voice, data network, application and computer infrastructure and their associated information assets. The CISO is responsible for building a comprehensive security program and an accountable, information security-conscious culture and a security infrastructure built on policies and procedures that are compliant with applicable Federal, State, and local laws, ordinances, and guidelines. The CISO will provide strategic and operational IT leadership Countywide and will establish, support, and continuously improve enterprise Information Security technology, policies, practices, and standards.

This requires a specific knowledge of security operations, security management, and the use of threat intelligence into cybersecurity practice, policies and procedures. This position must be able to translate technical cybersecurity issues/concerns into possible business implications that are meaningful to executive management and the Board of Supervisors.

Additionally, the CISO oversees vulnerability assessments and penetration testing, performs incident response and security analysis, provides forensic investigation, assists with internal and external audits, and supports County departments in eDiscovery.

In addition, the CISO will perform, but is not limited to, the following duties:
  • Providing guidance and direction to County Departments on Cyber Security practices and procedures
  • Creating and implementing a strategy for the deployment of information security technologies
  • Performing IT security risk assessments and reporting on ways to minimize threats
  • Monitoring security vulnerabilities and cybersecurity threats in network and host environments
  • Managing development and implementation of cybersecurity threat intelligence services
  • Overseeing integration of cybersecurity operations management into network management practices
  • Tracking the latest IT security innovations and keeping abreast of the latest cybersecurity technologies
  • Ensuring business continuity, compliance, and governance is met
  • Developing and implementing business continuity plans to ensure service is continuous when a change strategy is introduced or a security breach occurs or in the event that the disaster recovery plan needs to be triggered
  • Communicating with key County stakeholders about IT security threats
  • Develop and improve cyber incident response management
  • Overseeing the investigation of reported security breaches
  • Implementing an effective process for the report of security incidents
  • Managing the IT security team, security experts and advisors
  • Complying with the latest regulations and compliance requirements
  • Managing the daily operation and implementation of the IT security strategies
  • Protecting the intellectual property of the County at all times
  • Devising risk based strategies and implementing IT solutions to minimize the risk of cyber-attacks
  • Reviewing, analyzing and overseeing the processing of the release of information in compliance with the California Public Records Act and eDiscovery activities associated with internal and external investigations
  • Developing and maintaining relationships with other government jurisdictions to include local intelligence fusion centers and law enforcement partners
DESIRABLE QUALIFICATIONS & CORE COMPETENCIES

The ideal candidate will possess a Bachelor's degree in information security, computer science, information systems, computer engineering, or a related field; be a Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM); and possess a minimum of seven (7) years experience in comprehensive security program management in planning, administering, and ensuring effective and secure large-scale information security operations covering applications, mainframe, servers, voice and data network, Internet, or other systems. In addition, the ideal candidate will possess extensive knowledge and/or experience in the following core competencies:
  • Information Technology Knowledge | Information Security Experience
    • Understanding and application of security and privacy technologies and current best practices
    • Understanding and application of cybersecurity, risk management and control frameworks (such as National Institute of Standards and Technology (NIST) Cybersecurity Framework, NIST Risk Management Framework, and NIST 800-53 controls)
    • Administering operations, services and activities of comprehensive information systems security programs
    • Understanding and application of advanced principles and best practices of system security design, development, analysis and testing
    • Understanding and application of advanced methods and techniques of evaluating information security and developing appropriate solutions; converged voice and data network security; architecture and design
    • Utilizing functional structures of various operating systems components and associated security features
    • Developing strategies for secure, cloud-based services
    • Possessing advanced project management principles and techniques including project budgeting, quality assessment and control and resource management
    • Working knowledge of regulatory requirements including Health Insurance Portability and Accountability Act (HIPAA), the Payment Card Industry Data Security Standard (PCI DSS), and Criminal Justice Information Services (CJIS)
  • Leadership | Supervisory Skills
    • Leading a high performance, results oriented team to implement organizational goals while balancing competing needs and objectives
    • Leading information security training for employees, contractors, partners, and other third parties as appropriate
    • Supervising various levels of managerial, supervisory, technical, and support staff as well as partnering with other Agencies, such as Human Resources, County Counsel, Risk Management, etc.
    • Monitoring compliance with the organization's information security policies and procedures among employees, contractors, partners, and other third parties and resolve potential issues as needed
  • Strategic Thinking and Planning | Organizational and Analytical Skills
    • Planning and leading the execution of challenging projects to ensure that projects are resourced, budgeted, scheduled, planned, and implemented in a timely manner
    • Interpreting and analyzing complex data to identify critical issues
    • Thinking logically and organizing thoughts and work priorities to accomplish work efficiently
  • Oral | Written Communication Skills
    • Developing and implementing written materials, policies, and procedures for Administrative Services staff
    • Implementing and acting as an advocate for security best practices and security awareness
    • Preparing and orally presenting training and support information to various groups
    • Developing clear requirements for internal information technology staff and third-party vendors
    • Communicating, coordinating, and collaborating effectively with all organizational levels, and the public

MINIMUM QUALIFICATIONS

Please click here to learn about the minimum qualifications, including the physical and mental requirements as well as the environmental conditions for the Administrative Manager III classification.

RECRUITMENT PROCESS

Human Resource Services | Application Screening (Refer/Non-Refer)
Applications and supplemental responses will be screened for qualifications that are highly desirable and most needed to successfully perform the duties of this job. Only those applicants that meet the qualifications as listed in the job bulletin will be referred to the next step.

Application Appraisal Panel | Application Rating (Refer/Non-Refer)
An Application Appraisal Panel (AAP) of job knowledge experts will thoroughly screen and evaluate application and supplemental questionnaire for job knowledge, competencies, and related experience described above. The information you provide will be used as a rating device, so please be descriptive in your response. "See Resume" is not a qualifying response and will not be evaluated in lieu of the required information. The most successful candidates will be referred to the next step in the process.

Structured Oral Interview (SOI) (Weighted 100%)
Applicants will be interviewed and rated by an oral interview panel of job knowledge experts. Each applicant's rating will be based on responses to a series of structured questions designed to elicit the candidate's qualifications for the job.

Based on the Department's needs, the selection procedures listed above may be modified. Applicants will be notified of any changes in the selection procedures.

Eligible List
Once the assessment has been completed, HRS will establish an eligible list of candidates. Candidates placed on the eligible list may be referred to a selection interview to be considered for present and future vacancies.

Duties

Email Notification
Email is the primary form of notification during the recruitment process. Please ensure your correct email address is included in our application and use only one email account.

NOTE: User accounts are established for one person only and should not be shared with another person. Multiple applications with multiple users may jeopardize your status in the recruitment process for any positions for which you apply.

Candidates will be notified regarding their status as the recruitment proceeds via email through the GovernmentJobs.com site. Please check your email folders, including spam/junk folders, and/or accept emails ending with "governmentjobs.com" and "ocgov.com." If your email address should change, please update your profile at www.governmentjobs.com.

Frequently Asked Questions

Click here for additional Frequently Asked Questions.

For specific information pertaining to this recruitment, please contact Emma Tameez at (714) 834-7390 or Emma.Tameez@ocgov.com.

Qualifications

Orange County, as an equal employment opportunity employer,
encourages applicants from diverse backgrounds to apply.

Orange county Footer - 26Dec24

Administrative Management

In addition to the County's standard suite of benefits -- such as a variety of health plan options, sick and vacation time and paid holidays -- we also offer an excellent array of benefits such as:

  • Retirement: Benefits are provided through the Orange County Employees' Retirement System (OCERS)


    Please go to the following link to find out more about Defined Benefit Pensions and OCERS Plan Types/Benefits.

    http://www.ocers.org/member_active/county_intro.htm.

  • Paid Leave: Twelve holidays per year plus sick and vacation time.
  • Health & Dependent Care Reimbursement Accounts
  • Dental Insurance: County pays 100% of employee and dependent premiums.
  • Paid Life Insurance: $100,000 life insurance policy
  • Paid Accidental & Death and Dismemberment Insurance: $100,000 AD&D insurance policy
  • Paid Short & Long Term Disability insurance programs
  • 457 Defined Contribution Program


Click here to view the Orange County Employee Benefits Home Page.



Click here for Benefits Summary Information.

01
Are you currently a Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM)? If so, please attach a copy of your CISSP and/or CISM certification to your application.
  • Yes
  • No
02
Please describe your experience in developing and implementing a comprehensive security program for a large-scale organization (e.g., 10,000 employees or more).
03
Please describe your experience in developing risk based security policies, standards, and procedures and include the size of the organization where these were developed and implemented.
04
Please list the information security domain(s) that you have experience with. Include in your response your role and scope of responsibilities for each domain and how you applied each domain within an organization the size of the County of Orange.
05
Please list your current professional licenses and certifications applicable to information security (if you do not possess any, write "N/A").
06
Please highlight your experience working in a multi agency/departmental federated environment with a variety of different security requirements. Include in your response the challenges this created?

* Required Question

Employer
Orange County

Apply

OnlineApplication

Warning! You are using Internet Explorer 8. Some features of the Online Application are not fully supported in this version. Please upgrade to a later version of Internet Explorer for optimal performance.

Loading ...