Jobs and Careers
ME
Chief Information Services Security Officer
Metropolitan CouncilSaint Paul, United Statesfull_timeVerifiedPosted 2 Jul 2026
💰 $210,700/yr($129,780/yr – $210,700/yr)
About the role
Posting number: 2026-00152
Department: Regional Administration
Division: IS-Admin
Job classification: Chief Info Security Officer
Posting type: Open & Promotional
Categories: IT and Computers
Summary
The Regional Administration Division is accepting applications for a Chief Information Services Security Officer.We are the Metropolitan Council, the regional government for the seven-county Twin Cities metropolitan area. We plan 20 years ahead for the future of the metropolitan area and provide regional parks and trails, transportation, wastewater, and housing services.
More information about us on our website.
We are committed to hiring and supporting a diverse workforce that reflects the communities we serve.
Information Services is the central IT department supporting all divisions of the Metropolitan Council. Our 140 team members provide technology, practices, and innovative solutions that enable the core services of the Council.
How your work would contribute to our organization and the Twin Cities region:
The Chief Information Services Security Officer (CISO) provides strategic leadership and oversight for the Council's enterprise-wide information security strategy. The CISO is responsible for safeguarding all digital assets and information systems from internal and external threats. The CISO aligns cybersecurity programs to organizational goals, ensuring that risk management, compliance, and awareness efforts are proactive, robust, and effectively integrated into business operations. The CISO also leads the information security team, ensuring operational readiness, collaboration across divisions, and continuous improvement of security posture. Acts on behalf of the CIO as needed.
People Leadership
The CISO leads the Information Security team, ensuring high performance through clear expectations, accountability, and continuous learning. This leader cultivates a supportive, inclusive, and agile environment that embraces change and empowers staff to contribute their perspectives and challenge assumptions. Builds team capabilities by mentoring staff, developing future leaders, and promoting diversity and inclusion in hiring and development.
Strategic Leadership
Develops a long-term vision and roadmap for cybersecurity aligned to the Council’s digital strategy and public mission. Partners with the CIO and IS Leadership Team to shape strategy across the Information Services department. Provides guidance and decision-making leadership in IT governance, risk mitigation, architecture, and service continuity.
Business Partner Engagement
Serves as a trusted advisor to executive leadership and division leaders on matters of cybersecurity, privacy, and risk for all divisions. Builds collaborative relationships across the enterprise, including Legal, Compliance, HR, and Operations, to embed security best practices and ensure consistent execution of policies. Translates technical security concepts into business value and risk reduction terms.
Risk Management & Compliance
Oversees the design and enforcement of security policies and standards. Ensures compliance with regulatory and industry frameworks such as NIST, HIPAA, GDPR, CJIS, PCI-DSS, and ISO 27001. Leads vulnerability and risk assessments, mitigation strategies, and incident response processes. Establishes and monitors key risk indicators (KRIs) and key performance indicators (KPIs).
Security Operations & Program Leadership
Directs the implementation and operations of security technologies and tools, including threat detection, SIEM, endpoint protection, IAM, encryption, firewalls, and cloud security. Provides executive oversight of the incident response lifecycle, forensics investigations, and remediation activities. Continuously evaluates system resilience and recommends improvements.
Budget, Vendor, and Resource Leadership
Leads cybersecurity budgeting and financial planning to ensure efficient allocation of resources. Oversees vendor selection, contract negotiations, and vendor performance for cybersecurity services. Guides resource planning to align with strategic priorities and support operational execution.
Security Awareness & Organizational Culture
Promotes a security-first culture through education, training, and engagement. Develops awareness programs tailored to different user groups. Ensures that every staff member understands their security responsibilities. C
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s