Manager, IT Security

Gainesville Regional Utilities
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$125,927.0 - $188,891.0
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cyber Security Information Systems Information Security Management Information Systems Security Architecture Professional Network Administration Systems Integration Enterprise Software Applications Information Technology Vulnerability Analysis

Job description

Positions allocated to this classification report to a Department Director and work under general supervision. Work in this class is distinguished from other classes by its managerial and advanced technical and operational responsibilities., Develop and maintain enterprise cybersecurity strategies, architecture, policies, standards, and procedures.

Lead risk mitigation initiatives and align security operations with organizational compliance and business needs.

Evaluate, procure, implement, and oversee security technologies and enhancements.

Assess and communicate cybersecurity risks related to vendors, third parties, and new technologies.

Monitor emerging cybersecurity threats, vulnerabilities, and industry best practices to strengthen enterprise defenses.

Direct security operations, including incident response, investigations, vulnerability assessments, penetration testing, and audits.

Ensure the confidentiality, integrity, and availability of enterprise systems, applications, and data.

Examples of Work (continued)

Manage and supervise the daily operations, staffing, training, and performance of the IT Security Team.

Prepare security performance reports, assist in the preparation and monitoring of the annual departmental budget, and recommend improvements to strengthen the organization’s security posture.

Maintain collaborative relationships with internal stakeholders, government agencies, vendors, and partner organizations; may act in the absence of the supervisor and perform other related duties as assigned., Contributes to Achieving GRU’s Mission: GRU will provide safe, reliable, competitive utility services in an environmentally responsible manner and will actively contribute to the enhancement of the quality of life in our community Customer Focus

Requirements

Bachelor’s degree from an accredited college or university with major course work in business, engineering, computer science, or a related field.

An equivalent combination of education and experience may be considered if it meets the requirements of the department.

Information Technology Infrastructure Library (ITIL) foundation certification is required within six months of start date.

Certified Information Systems Security Professional (CISSP) through the International Information System Security Certification Consortium (ISC)2 is required within six months of start date.

NIST Cybersecurity Professional Practitioner certification is required within six months of probationary period.

Experience

Eight (8) years of progressively responsible experience in security or network management or governance, which includes four (4) years of supervisory or large project management experience.

Experience with the use and application of Information Technology in the utility or municipal government is desirable., Thorough knowledge of enterprise security architecture design, security documentation, and governance frameworks.

Strong understanding of IP, TCP/IP, network administration protocols, and enterprise connectivity concepts.

Knowledge of information systems development, quality assurance, systems integration, and enterprise application environments.

Knowledge of enterprise IT systems supporting customer service, utility billing, financials, HR, payroll, budgeting, purchasing, and related governmental operations.

Strong understanding of governmental budget procedures, organizational governance, and administrative principles.

Proven analytical, research, and problem-solving skills with the ability to evaluate complex IT security issues, tools, and technologies.

Knowledge, Skills, and Abilities (continued)

Ability to prioritize, plan, organize, and execute work in high-pressure, complex, and evolving environments.

Strong communication skills with the ability to present technical concepts in business-friendly language and prepare complex technical reports.

Ability to lead, supervise, delegate, and evaluate staff, including providing ongoing instructive and corrective feedback and performance management.

Ability to collaborate effectively with executives, elected officials, department heads, external agencies, and staff while driving process improvement and organizational alignment.

Benefits & conditions

Standing or Walking - Continually Lifting or Carrying>50 lbs. - Occasionally Pushing or Pulling > 50 lbs. - Rarely/Never Reaching Overhead-Rarely/Never Keyboarding - Continually Gross Manipulation - Rarely/Never Fine Manipulation - Continually Foot or Leg Controls - Rarely/Never Driving - Occasionally Stooping, Kneeling, or Crawling - Rarely/Never Climbing - Rarely/Never Speaking - Often Hearing - Often Near Visual Acuity - Continually Far Vision Acuity - Rarely/Never Peripheral Vision - Rarely/Never Normal Color Vision - Continually

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:00 min

Designing data ingestion architecture with system integration

Eldert Grootenboer +1 · WWC 2023

10:13 min

Company culture, career paths, and technical talent acquisition

Sebastian Hans · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · WWC 2025

Videos

See all

Related articles

See all