Information Security Officer

California Department of Public Health
Vineyard, United States of America
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Compensation
$ 151K

Job location

Remote
Vineyard, United States of America

Tech stack

Artificial Intelligence
Spreadsheets
Computer Security
Text Processing
PCI Data Security Standards
Software Tools
Information Technology
CIS Benchmarks
GPT

Job description

Under general direction of the Information Technology Manager II (ITM II) Chief Information Security Officer, the Information Technology Manager I (ITM I) Information Security Officer oversees and ensures functionality of the Department of Technology's (CDT) information security program. The ITM I is responsible for developing, maintaining, and enforcing policies and processes that provide for the integrity, confidentiality and availability of the IT infrastructure and information assets produced or used by the department and its customer agencies., * Must pass a fingerprint background criminal record check completed by the Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI).

  • Works in a professional environment and is required to operate a personal computer (word processor, spreadsheet, presentation and mail communication).
  • Use technical software (as required) for monitoring a variety of security-related items, and photocopy machine and telephone system, The California Department of Technology (CDT) is the guardian of public data, a leader in information technology (IT) services and solutions and has broad responsibility and authority over all aspects of technology in California state government, including policy formation, interagency coordination, IT project oversight, information security, technology service delivery, and advocacy.

As an industry leader, we are committed to partnering with state and local government and educational entities to deliver digital services, develop innovative and responsive solutions for business needs, and provide quality assurance for state government IT projects and services. Our success and legacy of service is reliant upon our highly talented, dedicated, and diverse workforce, for it is our individual cultural diversity, backgrounds, experiences, perspectives, and unique identities that spark our collaborative strength and innovative approach to serving the State of California. Department Website: https://cdt.ca.gov/career-opportunities/job-openings, You must provide direct responses to each of the numbered items listed below. Each individual response must be numbered and include the full text of the numbered items prior to your response. Please include specific examples of your education, training, and/or experience. The SOQ header should include the Job Control #, your name, "Statement of Qualifications" and your response. Resumes, cover letters and other material will not take the place of the required SOQ. Applications without an SOQ will not be considered. Your response to the SOQ should be no more than three (3) pages in length, formatted in 11pt Arial font, and should have a one-inch margin. The SOQ serves as a key component of the examination and hiring process and will be used to evaluate your qualifications, as well as your written communication skills. The SOQ is considered a writing sample and must clearly reflect your own knowledge, skills, abilities, and experience. While tools such as artificial intelligence (AI) (e.g., ChatGPT), internet resources, or third-party reviewers may assist with research or preparation, by submitting your application you certify that your SOQ is your original work, written in your own words, and accurately represents your background and qualifications. Failure to submit an SOQ that is your own work, including the use of AI-generated or substantially AI-assisted responses that misrepresent your abilities, may result in disqualification from the examination or hiring process. If such misrepresentation is discovered after appointment, it may constitute dishonesty and could result in adverse action, up to and including dismissal from State service

  • Describe your experience identifying, assessing, and mitigating information security risks. Include a specific example of a security risk you evaluated, the recommendations you made, how you collaborated with stakeholders, and the outcome.

  • Describe your experience developing, implementing, or maintaining information security policies, standards, procedures, or compliance programs. Include the security framework(s) or regulatory requirements you worked with (e.g., NIST, ISO 27001, CIS Controls, HIPAA, CJIS, PCI DSS), your role, and the results of your efforts.

  • Describe a situation in which you responded to a cybersecurity incident, security vulnerability, or audit findings. Explain your role, how you communicated technical information to both technical and non-technical stakeholders, the actions taken to resolve the issue, and the lessons learned.

Requirements

In addition to evaluating each candidate's relative ability, as demonstrated by quality and breadth of experience, the following factors will provide the basis for competitively evaluating each candidate:

  • Interpersonal skills and the ability to communicate effectively, both verbally and in writing.
  • Experience in obtaining buy-in and providing leadership to a large group of multi-disciplinary team members who do not report directly to the ITM I.
  • Knowledge of the structure, organization, and function of a variety of technology disciplines, as well as local, State and federal initiatives and programs.
  • Ability to anticipate and manage complex issues affecting many organizations, including the ability to develop policy and integrate all aspects of a strategy to assure resolution of issues.
  • Ability to gain the confidence and trust of individuals in key positions in the Department's customer base.
  • Ability to evaluate products from multiple perspectives (customers, stakeholders, vendors, best practices) in order to develop standards for product approvals.
  • Ability to develop/obtain consensus on policy direction that will ensure continuation of the development portion of projects and help ensure successful completion.
  • Possession of current CISSP/M and ITIL Foundation and/or Manager Certificates are desired.

Apply for this position