Chief Information Security Officer
14 hours ago
Dallas
SUMMARY: The CISO will lead the development and execution of a comprehensive information and cybersecurity strategy aligned with WFSDallas’ mission. This role will oversee the protection of digital and physical assets, data of job-seekers, employers and partners, and ensure secure, reliable operations across all service channels. The CISO will be a strategic advisor to senior leadership and the board, while managing day-to-day security operations, risk management, compliance and business continuity. ESSENTIAL DUTIES AND RESPONSIBILITIES: This job description is intended to identify the essential functions of a position and should not be interpreted as all-inclusive. The employee may be required to perform or assume additional job-related responsibilities other than those stated in this job description. Typical duties include: • Develop and implement enterprise-wide information cybersecurity strategy and governance framework including policies, procedures, and training to ensure compliance and security awareness organization-wide adhering to the National Institute of Standards and Technology (NIST) 800.53 Version 5 and Texas Cybersecurity Framework (TCF)., • Lead risk assessment, regulatory compliance (federal/state grants, data privacy, workforce system regulations) and vendor/partner security oversight., • Oversee security operations: threat intelligence, vulnerability management, incident response, identity & access management, cloud/endpoint security., • Build and lead the information security team; cultivate a security-aware culture across workforce centers, staff and partner organizations., • Collaborate with IT, operations, legal, HR, training and executive leadership to embed security into all programs and services., • Evaluate and implement emerging security technologies and approaches to support digital transformation. Develops and implements agency policies for encryption of data transmissions and the erection of firewalls to conceal information as it is being transmitted and to eliminate tainted digital transfers. Serve as liaison to the Board of Directors and external stakeholders regarding security posture, incidents and audits. • Oversees cybersecurity budgets, contracts, and resource planning to ensure efficient and effective allocation of security resources., • Regularly reports cybersecurity posture, risk assessments, and incident outcomes to executive leadership and the Board., • Leads, mentors, and develops information technology and cybersecurity staff to build organizational capability and succession strength. RISK MANAGEMENT & COMPLIANCE • Identify, assess and manage information security risks across all WFSDallas’ operations—digital systems, workforce centers, training portals, partner systems., • Ensure compliance with relevant laws, regulations and standards (including federal workforce grant requirements, data privacy, state/county regulations)., • Monitors changes in state and federal legislation and advises leadership on potential impacts to agency cybersecurity posture., • Lead internal and external security audits, assessments and remedial actions., • Monitor and evaluate third-party vendor security and partner integrations. SECURITY OPERATIONS • Lead the architecture, deployment and operation of security infrastructure: network security, endpoint security, cloud security, identity & access management., • Oversee vulnerability management, threat intelligence, detection and response capabilities., • Develop and maintain incident response plan, coordinate response to security events, and lead investigations., • Collaborate with IT teams supporting WFSDallas’ centers, online portals, job-seeker data systems, and employer portals. Develops performance metrics to measure effectiveness of cybersecurity controls and drives continuous improvement across all security domains. BUSINESS CONTINUITY & DATA PROTECTION • Develop and maintain disaster recovery and business continuity plans for mission-critical systems (career services platform, job-matching system, training portals, partner integrations)., • Protect sensitive data (jobseeker information, employer information, partner data) with appropriate encryption, access controls, retention policies., • Lead the development of a data classification and handling program aligned to the organization’s operations. SUPERVISORY RESPONSIBILITIES: This position is responsible to the President. Work is performed under general guidance and supervision and according to Workforce Solutions procedures and policies. MINIMUM QUALIFICATIONS: • Bachelor’s degree in Computer Science, Information Security, Cybersecurity or similar (Master’s preferred) or equivalent combination of education and relevant work experience, • At least 10 years of progressive experience in information security/IT risk management; 5+ years in a senior leadership role., • Experience in a multi-site, multi-channel service delivery environment (preferred: public sector, non-profit, workforce systems)., • Strong working knowledge of security frameworks (e.g., NIST CSF, ISO 27001, COBIT)., • Proven ability to lead incident response and manage regulatory/compliance demands. PREFERRED QUALIFICATIONS: • Certifications such as CISSP, CISM, CISA., • Experience with managing third-party/vendor risk, cloud security, identity & access management in hybrid environments., • Excellent communication skills—capable of translating technical issues for executive/board audiences., • Demonstrated ability to align security initiatives with organizational mission and business objectives. LANGUAGE SKILLS: Ability to read and interpret documents such as safety rules, operating and maintenance instructions, and procedure manuals; ability to write routine reports and correspondence; and to effectively communicate with diverse audiences (colleagues, vendors, supplier, landlords, general public). REASONING ABILITY: Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists. Ability to interpret a variety of instructions furnished in written, oral, diagram, or schedule form. OTHER SKILLS and ABILITIES: Knowledge of general office administration; office protocol; regulations for acquisition and inventory control; use and maintenance of computer systems; organization and accurate record-keeping. Type 50-60 words per minute accurately; compose complex correspondence and documentation; operate a variety of office equipment; train others; interact with visitors, Board of Directors, and subcontractors in a professional manner. TRAVEL Due to nature of job, travel will be required approximately 30-40% of work time. Must possess own method of transportation. PHYSICAL DEMANDS: The physical demands described here are representative of those which must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear. The employee is frequently required to stand; walk; and stoop, kneel, crouch, or crawl. The employee must regularly lift and/or move up to 10 pounds, frequently lift and/or move up to 25 pounds, and occasionally lift and/or move up to 25 pounds. Specific vision abilities required by this job include close vision, distance vision, and ability to adjust focus. WORK ENVIRONMENT: The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is occasionally exposed to moving mechanical parts, fumes or airborne particles, and outside weather conditions. The noise level in the work environment is usually moderate. This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may be modified any time with or without notice or due to funding changes. Workforce Solutions Greater Dallas is an EEO/AA/Drug Free Workplace Employer and complies fully with the Americans with Disabilities Act (ADA). Auxiliary aids and services are available upon request to individuals with disabilities. This position is grant funded.