> Markdown version of [/jobs/ext/1773889-chief-information-services-security-officer](https://www.wearedevelopers.com/jobs/ext/1773889-chief-information-services-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Services Security Officer - **Company:** The Metropolitan Council - **Location:** Saint Paul, MN, United States - **Experience:** Expert - **Salary:** $134,971.0 - $219,128.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Digital Assets, Identity and Access Management, IT Management, Intrusion Detection and Prevention, PCI Data Security Standards, Security Information and Event Management, Firewalls (Computer Science), Information Technology, Hardware Infrastructure - **Published:** July 3, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17481848?backUrl=%2Fcareer%2F17481848%2FChief-Information-Services-Security-Officer-Minnesota-Saint-Paul ## About the Role Any of the following combinations in completed education (degree in Information Security, Computer Science, Information Technology, or a related field) and experience (in cybersecurity/information security leadership roles)., + Master's degree with seven (7) years of experience including five (5) years directly managing professional staff. + Bachelor's degree with nine (9) years of experience including five (5) years directly managing professional staff. + Associate degree with eleven (11) years of experience including five (5) years directly managing professional staff. + High school diploma/GED with thirteen (13) years of experience including five (5) years directly managing professional staff. What additional skills and experience would be helpful in this job (desired qualifications): + Master's degree. + CISSP/CISM/CISA certifications. + Experience and demonstrated ability to identify opportunities to integrate equity initiatives meaningfully into work products and processes. + Knowledge of: o Regulatory frameworks: HIPAA, GDPR, FISMA, CJIS, NIST, PCI-DSS, ISO. o Risk management, threat detection, and mitigation techniques. o Cloud, hybrid, and on-prem infrastructure security. o Enterprise security tools, systems, and operations. o Cybersecurity operations, risk frameworks, compliance. o High conceptual and organizational understanding of how security underpins business operations. + Skills in: o Strategic planning, budget development, and policy enforcement. o Communication and collaboration. o Project management and cross-functional team leadership. o Influencing across systems, divisions, and leadership. + Ability to: o Lead change and drive cultural transformation. o Mentor, coach, and build inclusive teams. o Handle confidential data and investigations with discretion. o Apply complex, conceptual thinking to stay ahead of evolving threats, and balance compliance, user needs, and innovation. o Use adaptive thinking and sound judgement to lead under pressure. o Hold a high level of accountability for maintaining the Council's security posture, regulatory compliance, and public trust. ## Description We are committed to hiring and supporting a diverse workforce that reflects the communities we serve. Information Services is the central IT department supporting all divisions of the Metropolitan Council. Our 140 team members provide technology, practices, and innovative solutions that enable the core services of the Council. How your work would contribute to our organization and the Twin Cities region: The Chief Information Services Security Officer (CISO) provides strategic leadership and oversight for the Council's enterprise-wide information security strategy. The CISO is responsible for safeguarding all digital assets and information systems from internal and external threats. The CISO aligns cybersecurity programs to organizational goals, ensuring that risk management, compliance, and awareness efforts are proactive, robust, and effectively integrated into business operations. The CISO also leads the information security team, ensuring operational readiness, collaboration across divisions, and continuous improvement of security posture. Acts on behalf of the CIO as needed. People Leadership The CISO leads the Information Security team, ensuring high performance through clear expectations, accountability, and continuous learning. This leader cultivates a supportive, inclusive, and agile environment that embraces change and empowers staff to contribute their perspectives and challenge assumptions. Builds team capabilities by mentoring staff, developing future leaders, and promoting diversity and inclusion in hiring and development. Strategic Leadership Develops a long-term vision and roadmap for cybersecurity aligned to the Council's digital strategy and public mission. Partners with the CIO and IS Leadership Team to shape strategy across the Information Services department. Provides guidance and decision-making leadership in IT governance, risk mitigation, architecture, and service continuity. Business Partner Engagement Serves as a trusted advisor to executive leadership and division leaders on matters of cybersecurity, privacy, and risk for all divisions. Builds collaborative relationships across the enterprise, including Legal, Compliance, HR, and Operations, to embed security best practices and ensure consistent execution of policies. Translates technical security concepts into business value and risk reduction terms. Risk Management & Compliance Oversees the design and enforcement of security policies and standards. Ensures compliance with regulatory and industry frameworks such as NIST, HIPAA, GDPR, CJIS, PCI-DSS, and ISO 27001. Leads vulnerability and risk assessments, mitigation strategies, and incident response processes. Establishes and monitors key risk indicators (KRIs) and key performance indicators (KPIs). Security Operations & Program Leadership Directs the implementation and operations of security technologies and tools, including threat detection, SIEM, endpoint protection, IAM, encryption, firewalls, and cloud security. Provides executive oversight of the incident response lifecycle, forensics investigations, and remediation activities. Continuously evaluates system resilience and recommends improvements. Budget, Vendor, and Resource Leadership Leads cybersecurity budgeting and financial planning to ensure efficient allocation of resources. Oversees vendor selection, contract negotiations, and vendor performance for cybersecurity services. Guides resource planning to align with strategic priorities and support operational execution. Security Awareness & Organizational Culture Promotes a security-first culture through education, training, and engagement. Develops awareness programs tailored to different user groups. Ensures that every staff member understands their security responsibilities. Collaborates with HR, Legal, and Communications to increase organizational maturity in handling sensitive data. What you would do in this job + Leads development and execution of the Council's enterprise security strategy and governance framework. + Serves as an advisor to the CIO, executive leadership, and Council members on cybersecurity trends, risks, and performance. + Builds and leads a high-performing Information Security team. + Ensures compliance with data privacy and cybersecurity laws and frameworks. + Evaluates emerging technologies, evolving threats, and recommend strategic improvements. + Oversees incident response planning and execution, including forensics and root cause analysis. + Develops and tracks service-level agreements (SLAs) and performance metrics. + Builds relationships with peer agencies, government entities, and cybersecurity organizations. + Prepares and presents risk reports and strategy updates to Council stakeholders. + Manages cybersecurity audits, assessments, and third-party evaluations. + Promotes an inclusive, diverse, and psychologically safe security work environment. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Tokenization of Everything: Where the Real World Meets Blockchain](https://www.wearedevelopers.com/videos/1035-tokenization-of-everything-where-the-real-world-meets-blockchain) - [Hosting a modern justice system](https://www.wearedevelopers.com/videos/332-hosting-a-modern-justice-system) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Developers are Building the Cities of the Future](https://www.wearedevelopers.com/magazine/536-developers-are-building-the-cities-of-the-future) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager)