> Markdown version of [/jobs/ext/3110283-ciso-ism](https://www.wearedevelopers.com/jobs/ext/3110283-ciso-ism). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # CISO/ISM - **Company:** Florida, Inc - **Location:** Tallahassee, FL, United States (Remote available) - **Salary:** $100,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cyber Security, Computer Engineering, Disaster Recovery, Distributed Computing Environment, Distributed Systems, Identity and Access Management, Information Security Management, PCI Data Security Standards, Phishing, Information Technology Security Auditing, Google Cloud, Cloud Platform System, Firewalls (Computer Science), Information Technology, Vulnerability Analysis - **Published:** September 27, 2026 - **Apply:** https://www.dice.com/job-detail/0928c273-323d-4cec-a4df-230441a9376f ## About the Role * Knowledge of distributed processing operations, software, procedures, and equipment; * Knowledge of Information Security, principles, and best practices; * Knowledge of problem-solving techniques; * Knowledge of computers and software; * Knowledge of the principles, practices, and techniques of computer systems analysis; * Knowledge of the principles of networking and telecommunication; * Knowledge of telecommunications principles, equipment, procedures, and terminology; * Knowledge of audit procedures; * Knowledge of the principles of cryptography and cryptanalysis; * Knowledge of application and system technology security testing; * Ability to develop and maintain policies, procedures, standards, and guidelines; * Ability to process information logically and solve problems; * Ability to develop training programs related to distributed processing operations and procedures; * Ability to monitor, troubleshoot, and resolve problems with distributed computer systems components; * Ability to identify and define user needs; * Ability to communicate effectively; * Ability to establish and maintain effective working relationships with others; * Ability to prioritize, plan, organize, and coordinate work assignments; * Ability to author technical reports; and * Ability to analyze security requirements and relate them to the appropriate security controls., * Four (4) years of information security experience with at least three (3) years responding to security incidents; OR * An associate's degree from an accredited college or university and two (2) years of experience responding to security incidents. * One (1) year of experience managing security projects, efforts, or teams. * Experience with various regulatory requirements, laws, and security frameworks, such as NIST, ISO 27001, PCI DSS, HIPAA, HITECH, SOX, GDPR, CCPA, CIS, or SOC 2. * Ability to manage a project, internal/external contractors' team, vendors, budget, and initiatives., * A bachelor's degree from an accredited college or university in information technology, computer engineering, business administration or a related field. * Industry recognized certifications such as: CISSP, CISM, CCSP, OSCP, CEH/CND, CySA+, Sec+, or related GIAC certification. * Experience securing cloud environments like Microsoft Azure, Amazon Web Services, or Google Cloud Platform. * Experience with firewalls and IAM/PAM systems and vendors. ## Description This position serves as the Chief Information Security Officer (CISO) and Information Security Manager (ISM) for the Florida Gaming Control Commission and is responsible for developing, maintaining, and enforcing the Agency's information security policies. The CISO/ISM is responsible for developing, implementing, and maintaining a strategic, comprehensive enterprise information security and IT risk management program, which includes procedures and policies designed to protect enterprise communications, systems, and assets from both internal and external threats, and enforces compliance with State and Federal requirements across all technology projects, systems, and services. Duties include, but are not limited to: * Developing, implementing, and monitoring a strategic, comprehensive enterprise information security and IT risk management program; * Assisting resource owners and IT staff in understanding and responding to security audit failures reported by auditors; * Ensuring audit trails, system logs, and other monitoring data sources are reviewed periodically to ensure compliance with policies, audit requirements, and regulatory standards; * Designing, coordinating, and overseeing security testing procedures to verify the security of systems, networks, and applications, and manage the remediation of identified risks; * Developing and enhancing an information security management framework; * Creating, maintaining, and enforcing security policies, standards, procedures, controls, and guidelines that meet State and Federal requirements; * Leading incident response activities, including detection, analysis, containment, eradication, recovery, documentation, and notifications; oversee and coordinating the CSIRT; * Conducting and coordinating vulnerability assessments, security testing, and risk remediation efforts; manage continuous threat and vulnerability management operations; * Guiding development, testing, and maintenance of disaster recovery and business continuity plans; * Overseeing identity and access management governance, including access reviews, certifications, and privileged accmanagingount monitoring; * Developing, maintaining, and measuring the effectiveness of the agency's cybersecurity awareness program, including phishing, smishing, vishing, and other human-factor risk reduction initiatives; and * Providing leadership to the enterprise's information security organization and participating in strategic technology planning and governance. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)