Chief Information Security Officer
Role details
Job location
Tech stack
Job description
The Office of Information Technology (OIT) is seeking a highly experienced and strategic technology leader to serve as the Chief Information Security Officer (CISO). This executive-level management position is responsible for overseeing the County's enterprise cybersecurity strategy, governance framework, security policies, standards, and programs to ensure information assets, systems, and technologies are protected against internal and external threats. The CISO serves as the County's subject matter expert on cybersecurity concepts, risk management, compliance requirements, and industry standards including ISO 27000 series, SOX, GDPR, PII, PCI, and related regulatory frameworks. The incumbent directs cybersecurity operations, security monitoring, threat assessment, incident response, cyber continuity planning, and resiliency initiatives across on-premises, cloud, and externally hosted environments supporting County applications, infrastructure, communications, endpoints, and data systems. This position develops risk-based security strategies, operational recommendations, and budget initiatives to support enterprise cybersecurity objectives and collaborates extensively with OIT technology divisions, the Office of Homeland Security, regional partners, and intergovernmental cybersecurity organizations including the COG IT Security Subcommittee and related State and regional workgroups. The position operates with considerable independence and requires exceptional leadership, sound judgment, strategic vision, and ethical conduct under the general supervision of the Chief Information Officer (CIO).
About the Agency The Office of Information Technology (OIT) provides support for all of the agencies, departments, and branches of County government. The OIT Service Desk provides information technology support and maintenance services to Prince George's County personnel. The Office of Information Technology is wholly dedicated to aligning technology efforts to support the strategic goals of the County. OIT will provide leadership, expertise, and resources in the ideation, development, and deployment of innovative technologies and streamlined processes to improve government efficiency, business interaction, and citizen access to government information and services.
Examples of Work
- Lead official for county-wide cyber and IT security strategy, policy and enforcement, Cyber office program development; develops fluid strategy and concepts regarding cyber security and data privacy.
- Develop and manage a comprehensive enterprise Cyber/IT security and risk management program.
- Lead and develop an effective and high performing Infosec team, integrated to work with the IT organization and County agencies and partners.
- Develop and recommend policies and procedures for appropriate use, and for detecting, deterring, and mitigating IT security threats; directs implementation, compliance and enforcement of enterprise-wide IT/Cyber security policy, standards and practices.
- Develop strategies for safeguarding the county's IT environment from cyber threats.
- Ensure that IT architecture and design comply with law and regulations.
- Interface with internal and external stakeholders serving as the public face for Cyber Security.
- Advise county leadership on cyber security awareness and issues.
- Advise and collaborate with the Office of Emergency Management regarding COOP, state legislation regarding cyber incident management and reporting, training and exercises, and physical security regarding access controls, policies and supporting technologies.
- Inform CIO of issues and recommend determinations.
- Advise OIT directors of IT/cyber polices, practices and protective measures regarding the IT environment and Cyber/IT security solutions.
- Respond to and addresses IT/Cyber security breaches and incidents, including overseeing the activation of the OIT IT security emergency response team and/or departmental incident response teams.
- Oversee security audits and tasks to confirm the integrity, confidentiality and availability of the enterprise's information technology environment.
- Oversee data searches that may be conducted by Infosec for MPIA, FOIA, e-discovery, document preservation and legal holds.
- Works with Office of Law, CEX Offices of IG, COS Communications, OEA, PAB and ACC, and law enforcement related to cyber incidents.
- Prepare reports and advisements.
- Ensure that tools are implemented for early threat detection to reduce the risk of attacks against the IT environment and systems.
- Conduct enforcement and compliance activities and implement threat and Cyber Security awareness campaigns.
- Conduct and/or support investigations of suspected information security misuse.
- Practice the utmost discretion in communicating security exposures, misuse and non-compliance, and communicate status and updated requirements of security matters to management as appropriate.
- Manage the IT Security Office (Infosec), establishes staff, resource requirements, defense-in-depth architecture, targets, policies and procedures, and administrative matters including development of Infosec budgets within parameters.
- Supervise staff and contractors, makes assignments, plans training and skill development; conducts coaching.
- Develop requirements for contractors and brings issues related to contractor performance to the OIT Contracts Manager., * Meet all training and performance standards and demonstrate proficiency as required by the agency.
- Wear and use agency protective apparel and equipment in the performance of their assigned duties.
- Successfully pass preemployment checks which may include reference checks, background investigations, and drug screenings.
- Be willing and able to serve as an essential employee. Essential employees are expected to report during standard or non-standard hours as operations necessitate, or during emergencies. Essential employees are expected to report or remain at work when other County employees are granted Administrative Leave.
Requirements
Do you have a valid Driver's License license?, Do you have experience in Policy Development?, Do you have a Bachelor's degree?, * Bachelor's degree from an accredited college or university in any field.
- Previous professional experience overseeing enterprise cybersecurity strategy, governance framework, security policies, standards, and programs to ensure information assets, systems, and technologies are protected against internal and external threats.
An equivalent combination of education, experience and training that demonstrate the necessary knowledge, skills, and abilities may be taken into consideration., * A valid driver's license.
Benefits & conditions
Pulled from the full job description
- 457(b)
- 403(b)
- Health insurance
- Employee discount
- Vision insurance
- Dental insurance
- Flexible spending account, A spouse (to include a same sex spouse) can be added to the health benefit plans. A marriage certificate and social security number is required to add a spouse. Children under the age of 26 are eligible for coverage under the health benefit plans. This includes stepchildren and children of the same-sex spouse. A birth certificate(s) and social security number(s) is required to add a child(ren). If you are only adding the stepchildren or child(ren) of a same-sex spouse, you will need to submit a marriage certificate. You will also need to submit the birth certificate of the child(ren) and your spouse must be listed as a parent. The premiums for health benefits are deducted on a pre-tax basis with the exception of Long-Term Disability, Extra Life Insurance and Voluntary Benefits (Short-Term Disability, Whole Life Insurance, Critical Illness, Accident Insurance, Cancer Indemnity, Hospital Indemnity Protection, Accident Indemnity Plan, Supplemental Dental and Group Legal Services). New employees must enroll in the County's health benefit plans within thirty (30) days of the hire date. The effective date of the health benefits coverage is the beginning of the month following a waiting period of forty-five (45) days from the date of hire. After enrolling in the County's benefit plans, employees may only make changes to the plans either during the open enrollment period, which occurs annually (usually each October), and/or during the year, due to a family status change (i.e., marriage, births, divorce and adoption). Employee Benefits
Prince George's County is proud to offer employees an attractive and comprehensive benefits program, including the following:
- Medical/Prescription/Dental/Vision Insurance Coverage (part time employees are eligible for medical insurance if they work 15 + hours, per week)
- Group Term Life Insurance
- Long & Short-Term Disability
- Flexible Spending Accounts
- Dependent Care Assistance Program
- Health Care Flexible Spending Account
- Paid Leave (Annual, Personal, & Sick)
- 13 Paid Holidays
- Retirement Benefits
-
Defined Benefit Pension Plan o Employer Contribution Rate-11.71%
-
Supplemental Pension Plan o Employee Contribution Rate (Pre-Tax)-3.48%
-
457(b)
-
403(b)
- Employee Discounts
- Employee Assistance Program
- Voluntary Benefits
- Critical Illness
- Whole Life Insurance
- Accident Insurance
- Legal Services