Senior Information Security Officer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Department of Financial Protection and Innovation is recruiting for one Permanent, Full-time Information Technology Specialist II position within the Information Technology Services Division. This position is to be located in the Sacramento office. This recruitment may be used to fill subsequent vacancies of this position within the next 180 days. Under the general direction of the Chief Information Security Officer (CISO, IT Manager I) the Information Technology Specialist II will serve as department’s Senior Information Security Officer (SISO). The Senior Information Security Officer (SISO) will ensure DFPI IT systems are protected from threats, lead the response to privacy and security incidents, perform incident investigations and analysis, develop security policies and processes, and report compliance to state and federal agencies. The SISO will assist the CISO in maintaining compliance with state and federal regulations including California Civil Code, the State Administrative Manual (SAM), the Statewide Information Management Manual (SIMM), and the National Institute of Standards and Technology (NIST).
Requirements
In addition to evaluating each candidate’s relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate: Ability to analyze business impact and exposure (based on emerging security threats, vulnerabilities and risks) to recommend IT solutions. Experience and knowledge of procedures for incident handling, particularly for analyzing incident-related data and determining the appropriate response. Experience developing policies and documenting work processes to support and enforce security standards. Experience developing and maintaining technology and disaster recovery plans including preliminary planning, business impact analysis, alternate site selection, recovery strategies, and training and exercise development to support the overall Business Continuity Plan. Experience monitoring and assessing security controls in the information system on an ongoing basis, documenting changes, conducting security impact analyses, and reporting system security statuses to the organization. Ability to effectively communicate both in writing and verbally., 2. Describe your experience in developing security policies and practices and documenting work processes.
Benefits & conditions
This job requires reporting on site a minimum of 4 days per week, with the option of one day of telework with an approved agreement., The Department of Financial Protection and Innovation (DFPI) protects consumers and oversees financial service providers and products. The DFPI supervises the operations of state-licensed financial institutions, including banks, credit unions and money transmitters. Additionally, the DFPI licenses and regulates a variety of financial service providers, including securities brokers and dealers, investment advisers, payday lenders and other consumer finance lenders. The DFPI offers benefit packages, competitive salary, a robust training program and opportunities for advancement. Department Website: https://dfpi.ca.gov, State employees may be eligible for health, dental, vision and leave benefits, as well as retirement programs and other benefits. Benefit eligibility may depend on length of service and may be subject to collective bargaining agreements, which are contracts negotiated between the State of California and employee organizations that define employees’ wages, hours and conditions of employment. Other possible benefits include:
- Alternate Work Schedules
- Telework
- Reimbursement Accounts
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
11 Best Practices For PHP Security