You are viewing a preview of this job. Log in or register to view more details about this job.

Information Systems Manager (IT Security)

REQUIREMENTS AND PREFERENCES
The Broward County Board of County Commissioners is seeking qualified candidates for Information Systems Manager (IT Security) in the Enterprise Technology Services (ETS) Division. 
The ETS Division is seeking an IT Security & Compliance manager whose information role is to assess and oversee all technology-related security and compliance issues across the organization, including information security, privacy, disaster recovery, user access, data integrity, HIPAA, and Pll. This is a hands-on working manager position responsible for addressing technical issues and leading and completing projects with little to no assistance. This includes providing objective risk assessments of the County's compliance with regulatory, organizational and commercial requirements. This position will also direct the development and implementation of policies, procedures and controls to ensure that the organization's practices remain observant of all pertinent local, state, county and federal laws and industry standards. In this role, the IT compliance manager will work directly with non-IT compliance professionals such as legal, internal auditors and HR to ensure organizational alignment. Work is reviewed by an administrative superior through meetings and evaluation of program achievements. 

The ideal candidate will possess the following:
  • Knowledge and management experience in regulatory/legal compliance procedures, industry best practices and frameworks related to HIPAA, PCI, FS119, and the NIST Cyber Security Framework
  • CISSP level certification (IT security) and additional certifications to support managing a diverse set of information security initiatives
  • The ability to prioritize vulnerability risks and strategize remediation with Infrastructure, Applications, and other agency embedded IT staff
  • Ability to architect and contribute to design of IT systems and applications from a security perspective
  • Ability to architect and monitor SIEM and security logs, detect threats and propose modifications to reduce false-positives
  • Ability to lead and participate in security incident response efforts and investigations related to security incidents
  • Ability to use the following security systems and tools: OS vulnerability assessment scanner, web application vulnerability scanner, data loss prevention(DLP), log management/SIEM, URL Filtering, and public certificate authority certificate management
  • Thorough knowledge of the principles, practices and methodology of systems analysis
  • Thorough knowledge of automated systems capabilities and programming techniques
  • Considerable knowledge of the current trends and developments in field of information system technology
  • Considerable knowledge of the principles of supervision, organization and administration
  • Ability to analyze work systems and processes, and organize their components into logical systems
  • Ability to plan, coordinate and direct the work of subordinates
  • Ability to express ideas effectively

General Description
Establishes, maintains and communicates IT (information technology) procedures, policies, standards and strategic direction related to technical work and data processing systems activities, including systems analysis and programming for an agency.
Works under administrative supervision, developing and implementing programs within organizational policies, and reports major activities to executive level administrators through conferences and reports.

Minimum Education and Experience Requirements
Requires a Bachelor's degree from an accredited college or university with major coursework in computer science or closely related field.

Requires four (4) years experience in actively working, planning, managing and implementing IT Security system solutions or closely related experience, including two (2) years of supervisory experience.

Special Certifications and Licenses Required
May require possession of or eligibility to obtain basic FCIC/NCIC (Florida/National Crime Information Center) certification depending upon area of assignment.

Possess and maintain a valid Florida Class E Driver's License based on area of assignment.

Preferences
  • Master’s degree or higher in Information Systems Security or closely related field
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Cloud Security Professional (CCSP)
  • CompTIA Advanced Security Practitioner (CASP+)
  • Certified Ethical Hacker (CEH)
  • 3 + years direct hands-on experience with incident management and response
  • 3 + years proficiency in problem-solving, analytical thinking, and penetration testing methodologies
  • 3 + years direct experience with cloud security architecture, design and service orchestration
  • Four years supervisory experience
  • Cloud Security Development and/or Certification

DUTIES AND RESPONSIBILITIES

The functions listed below are those that represent the majority of the time spent working in this class. Management may assign additional functions related to the type of work of the job as necessary.
  • Manage program for vendor security due diligence for new procurements and agreements.
  • Support various County required internal and external audits for the IT portion of those audits including but not limited to HIPAA, CJIS, PCI, Internal IT Financial Audits, External IT Financial Audits, and other agency specific external audits with an IT component.
  • Interface regularly with managers and directors from various departments communicating security issues and requirements, and facilitating information security program strategy.
  • Maintain and further the organization's Information Security Program based on the NIST Cybersecurity Framework.
  • Procure/evaluate security systems for the County's network.
  • Perform IT security assessments and IT risk analysis.
  • Maintains an up-to-date understanding of security best practices through continuing education.
  • Determine, direct, and participate in the overall design, development and implementation of an agency-wide security program and strategic plan.
  • Supervise systems analysts, programmers and/or related technical staff and provide high level direction on the integration of new technologies with existing application systems.
  • Review, develop, and enforce information system standards, policies, and procedures within approved County regulations.
  • Provide technical leadership and direction in ensuring the successful integration of new methods and technologies with existing application systems.
  • Manage the daily operations of an agency's information systems group; supervises systems analysts, programmers and/or related technical staff.
  • Prepare and review requirements and cost-benefits, analyses and information system budgets; oversees vendor selection and contract negotiations.
  • Represent the agency on information system matters.
  • Perform related work as required.

WORK ENVIRONMENT

Physical Demands
Physical demands refer to the requirements for physical exertion and coordination of limb and body movement.
Performs sedentary work that involves walking or standing some of the time and involves exerting up to 10 pounds of force on a regular and recurring basis or sustained keyboard operations.

Unavoidable Hazards (Work Environment)
Unavoidable hazards refer to the job conditions that may lead to injury or health hazards even though precautions have been taken.
None.

SPECIAL INFORMATION

Americans with Disabilities Act Compliance
Broward County is an Equal Opportunity Employer. The ADA requires Broward County to provide reasonable accommodations to qualified persons with disabilities. Prospective and current employees are encouraged to discuss ADA accommodations with the Professional Standards/Human Rights Section.

Emergency Management Responsibilities
During emergency conditions, all County employees are automatically considered emergency service workers. County employees are subject to being called to work in the event of a disaster, such as a hurricane, or other emergency situation and are expected to perform emergency service duties, as assigned.

County-wide Employee Responsibilities
All Broward County employees must serve the public and fellow employees with honesty and integrity in full accord with the letter and spirit of Broward County's Employee Code of Ethics, gift, and conflict of interest policies. 
 
All Broward County employees must establish and maintain effective working relationships with the general public, co-workers, elected and appointed officials and members of diverse cultural and linguistic backgrounds, regardless of race, color, religion, sex, national origin, age, disability, marital status, political affiliation, familial status, sexual orientation, pregnancy, or gender identity and expression.