Search jobs > Baltimore, MD > Chief information security

Deputy Chief Information Security Officer (NCS) - BCIT

Baltimore Police Department
Baltimore, Maryland, US
$105.1K-$173.3K a year
Full-time

THIS IS A NON-CIVIL SERVICE POSITION

POSTING DATE : 07 / 29 / 2024

CLOSING DATE : 10 / 29 / 2024 AT 12 : 00 MIDNIGHT

SALARY RANGE : $105,085.00 - $173,250.00 USD Annually

CLASS DESCRIPTION

The Baltimore City Office of Information and Technology (BCIT) is seeking a Deputy Chief Information Security Officer (DCISO).

The Deputy CISO works with and reports to the BCIT's Chief Information Security Office (CISO) in leading the Agency's enterprise-wide cybersecurity program and providing security oversight to the agency's information technology (IT) investments.

The Deputy CISO develops, evaluates and implements policies for agency-wide programs.

ESSENTIAL DUTIES

Leads a team of cybersecurity professionals across a broad range of disciplines including risk management, compliance / audits, incident response, security tool implementation and monitoring, analytics, threat hunting / emulation, security engineering, monitoring / detection, governance, and training.

Ensure compliance with the National Institute of Standards and Technology (NIST) Cyber Security Framework (CSF) and other applicable regulations and governing frameworks.

Oversees (designs architecture / integration, procure, configure, manage) a comprehensive suite of security tools and monitoring technologies based on a continuous review of industry best practices, security architecture designs, and gaps in the environment to support system authorization.

Continuously monitors threat detection and response, compliance, and related enterprise-level security activities. Recommends enhancements designed to integrate effectively and keep pace with evolving threats.

Develops comprehensive cybersecurity standards that align with the city’s IT policy, integrates with the security architecture, mitigates risk areas, and is based on industry-leading best practices, policy and regulations.

Ensures that BCIT has policies that guides the organization, manages compliance and risk, and defines key roles and partnerships.

  • Continuously refines the cybersecurity program by updating the city’s strategy and tactical plans across the cybersecurity program, leveraging the latest industry research, threat analysis, and lessons learned from internal practices.
  • Conducts internal security audits of all aspects of the IT architecture for compliance and to determine where vulnerabilities exits, translating findings into Plans of Action and Milestones.

Coordinates external audits to ensure BCIT has an effective compliance program that supports risk-prioritized remediation efforts.

Develops a professional cadre of cybersecurity experts through mentorship, creating and facilitating professional development opportunities, and quality reviews and feedback of work.

Ensures that employees are challenged and provided opportunities to keep pace with continuously evolving cyber threats.

Designs, refines, implements and manages a risk-based, repeatable / consistent system security strategy based on the NIST Cybersecurity Framework which includes control selection, system authorization, documenting, and remediating vulnerabilities, managing a Governance Risk and Compliance (GRC) tool, partnering with developers and stakeholders to ensure security is a part of the complete system development life cycle, and continuous monitoring.

Maintains a thoughtful risk-management framework applied to all systems and applications.

  • Leads security monitoring of all environments and incident response to cyber-attacks by designing comprehensive plans, managing routine exercises, partnering with threat experts and law enforcement, maintaining an effective security operations center, working with external vendors, as well as building and leveraging threat intelligence, the kill chain and analytics programs.
  • Creates and oversees threat hunting and emulation ("red / blue") efforts designed to detect and repair vulnerabilities across the enterprise based on a strategy tethered to risk and larger corporate future IT goals.

Determines where BCIT's architecture lacks sufficient security controls that could be exploited by an adversary.

Develops and manages an innovative and current cybersecurity training and awareness program that looks both internally at developing professionals and educating employees across BCIT.

Ensures employees at all levels receive training to prevent security mishaps and build stronger cyber awareness.

EDUCATION AND EXPERIENCE REQUIREMENTS

  • A Bachelor of Science degree in Information Technology, Computer Science, Computer Engineering or a related discipline from an accredited college or university plus seven years of cyber security or other related experience
  • Three years of supervisory responsibilities evaluating the performance, mentoring, coaching and recruiting and growing employees.
  • Excellent verbal and written communication skills.
  • An equivalent combination of education and experience. Non-supervisory experience or education may not be substituted for the required supervisory experience.

REQUIRED KNOWLEDGE, SKILLS AND ABILITIES

  • Comprehensive knowledge of cybersecurity, operational, incident response and security tools best practices.
  • Ability to supervise, plan, and monitor and grow the skills of a professional staff.
  • Ability to lead city-wide initiatives and collaborate across organizational boundaries.
  • Ability to communicate effectively with senior leaders and external stakeholders.
  • Experience with business practices, budgeting, monitoring, and support service operations for large government or business organizations.
  • Ability to perform duties with accuracy and attention to detail.
  • Understands how to build resilience in security operations leveraging the kill chain and intelligence driven defense.
  • Knowledge of project planning and scheduling; audit and compliance programs; and pertinent regulations.
  • Ability to analyze and resolve complex business problems.
  • Ability to collaborate with Subject Matter Experts (SME's) and resolve complex issues.
  • Knowledge of technology advances and trends.

Financial Disclosure :

BALTIMORE CITY IS AN EQUAL OPPORTUNITY EMPLOYER

30+ days ago
Related jobs
Promoted
Amentum
Columbia, Maryland

Maintain operational security posture for an information system or program to ensure information systems security policies, standards, and procedures are established and followed. We are seeking an Information Systems Security Officer (ISSO) 2 for a prime contract that is based out of our Columbia, ...

Promoted
Hartman Executive Advisors
Baltimore, Maryland

Hartman is seeking a Chief Information Security Officer (CISO) Financial Services Practice to provide advisory, cyber, and analysis services to a portfolio of Hartman’s Financial Services clients which primarily includes community banks and credit unions. The CISO will also lead security risk assess...

Promoted
EMTAK LLC
Annapolis Junction, Maryland

The Level 2 Information Systems Security Engineer (ISSE) shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommend mitigation strategies. ...

Promoted
Hartman Executive Advisors
Baltimore, Maryland

Hartman is seeking a Chief Information Security Officer (CISO) to provide advisory, cyber, and analysis services to a portfolio of Hartman's clients. The CISO will also lead security risk assessments, compliance audits, oversee execution of remediation activities, guide security/performance measures...

Maryland.gov
Baltimore, Maryland

The Chief Information Officer (CIO) is a pivotal leadership role responsible for the comprehensive management and strategic oversight of MSDE's Office of Information Technology (OIT) operations. Some of the primary job functions of the CIO include: Ensuring rigorous data privacy protocols and mainta...

Promoted
Hartman Executive Advisors
Cockeysville, Maryland

Delivers and executes on the short and long-term visions of the Credit Union’s technology and information security needs and goals. Administers the Credit Union’s Information Security Program. Develops and documents standards, policies and procedures to ensure optimal operational workflow efficiency...

Vets Hired
Fort Meade, Maryland

We are seeking Information Systems Security Officers (ISSO) to join us on a contract being awarded in June of 2025. Provide guidance and technical expertise on all matters that impact or effect the security of the information system. Developing, updating, and submitting the System Security Plan...

Boeing Intelligence & Analytics
Annapolis Junction, Maryland

As an Information System Security Officer (ISSO) at Boeing Intelligence & Analytics, you will be responsible for:. Demonstrated experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information as...

PLEX Solutions, LLC
Annapolis Junction, Maryland

Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university, (OR) 4 additional years of experience may be substituted for a degree. Coordinate the install of the COMSEC hardware to include the r...

Johns Hopkins Applied Physics Laboratory
Laurel, Maryland

We are seeking a dedicated Information System Security Officer to help us protect APL 's information technology infrastructure. Your primary responsibility will be providing security relevant documentation such as security CONOPS, Security Controls Traceability Matrix 's, System Security Plans, Risk...