IT Security Manager
City of PhiladelphiaAbout the role
Company Description
The Office of Innovation & Technology (OIT) is the central IT agency for the City of Philadelphia headed by the Chief Information Officer (CIO). OIT oversees all major information and communications technology initiatives for the City of Philadelphia - increasing the effectiveness of the information technology infrastructure, where the services provided are advanced, optimized, and responsive to the needs of the City of Philadelphia’s businesses, residents, and visitors. OIT responsibilities include: identifying the most effective approach for implementing new information technology directions throughout city government; improving the value of the city’s technology assets and the return on the city’s technology investments; ensuring data security continuity; planning for continuing operations in the event of disruption of information technology or communications services; and supporting accountable, efficient and effective government across every city department, board, commission and agency.
The City of Philadelphia is seeking a highly motivated and experienced Information Security Manager to work in the Department of Revenue IT’s unit in support of the Chief Information Security Officer (CISO). This critical role will be responsible for ensuring the confidentiality, integrity, and availability of our information systems, with a strong focus on compliance with IRS Compliance and the NIST Cybersecurity Framework. The candidate possesses a deep understanding of security best practices, regulatory requirements, and technical expertise in implementing and maintaining security controls. The IT Security manager will also work with the owners of OT and IT services to identify and communicate risk and develop mitigation strategies for these risks. The candidate will have a background in cyber security that includes technical skills as well as experience with developing policies and procedures.
Job Description
Essential Functions
- Manage IT Security projects including implementation of an updated security program while ensuring cross-team collaboration with necessary stakeholders.
- Ensure incident response procedures are documented including identification of roles and responsibilities.
- Monitor and analyze security event data by responding to, prioritizing, and managing security events and managing security incidents from occurrence to closure, in coordination with internal and external resources.
- Schedules periodic security audits and works with outside consultants as appropriate for independent security audits.
- Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate risks.
- Develop and maintain security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
- Respond to security incidents and implement corrective actions.
- Stay abreast of the latest security trends to maintain the security of RevIT and OT systems.
- Partner with the City’s Security Team to ensure City policies are applied throughout Revenue.
- Stay up-to-date on the latest security threats, vulnerabilities, and regulatory requirements.
- Participate in security audits and compliance reviews.
- Contribute to the development and implementation of security policies and procedures.
- Perform risk assessments and identify mitigation strategies.
- Communicate security-related information effectively to both technical and non-technical audiences, performs miscellaneous job-related duties as assigned.
Qualifications
Qualifications (Education and Experience)
- Completion of a bachelor’s degree program at an accredited college or university, which has included major course work in computer science, information science, system analysis, software engineering, or a closely related field.
- Minimum of eight years of work experience, which must include at least three years of direct IT security-related experience, including exposure to the NIST Framework.
- Experience performing information security risk assessments including identifying threats, vulnerabilities, and risk.
- Experience with Vulnerability Management programs.
- Experience working with common information security tools including Endpoint Detection and Response, network filtering technologies (Web, DNS), Identity and Access Management solutions, and SIEM technologies required.
- Valid Certified Information Systems Security Professional (CISSP) credential, such as CISSP-ISSAP, CISSP-ISSEP or CISSP-ISSMP, is preferred but not required.
- Experience leading security initiatives and coordinating work across technical teams; direct people management experience pref
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s