The Information Security Manager will guide security policy and participate in broader Information Security governance efforts. This role involves developing and maintaining the Information Security Management System (ISMS) in collaboration with regional information security SMEs and technical consultants. The manager will oversee and manage the ISMS, recommend appropriate mitigating controls, and oversee Information Security Risk Management activities, including risk identification, assessment, and communication to relevant stakeholders. This position provides valuable expertise and leadership directly to the governing Joint Board executive leadership, sharing metrics to reflect the performance of regional security program functions, executive risk score reports, and other guidance on information security topics. The role facilitates a committee of Information Security SMEs across Agencies to ensure regional compliance and concurrence on information security matters, recommending solutions and working from a regional perspective to achieve optimal outcomes. Collaboration with the Systems Integrator, other vendors, and partner Agencies is crucial to ensure security best practices, standards, policies, and regulatory requirements are incorporated into core payment system design, implementation, and sustainment, as well as supporting future phase projects. The manager will conduct regular security reviews of software and processes, advise on information security practices, and review/create threat models, recommending security enhancements consistent with information security strategy and evolving threats. Support for external IT security audits and assessments is also a key responsibility. The role includes developing, updating, implementing, and conducting information security training programs, managing approvals for Identity and Access Management (IAM) and Access Control Administration, and acting as Incident Commander for Security Incident Response activities when the plan is invoked. Participation in incident investigation and response, performing root-cause analysis, and preparing incident reports are essential. Evaluating change requests for potential impacts on Information Security and providing input to the Change Management process are also required. The manager will coach future Regional Operations Team (ROOT) information security personnel and stay updated on the latest information security trends, best practices, threats, and countermeasures.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager
Education Level
No Education Listed