Jobs and Careers
CI

Chief Information Security Officer

City of Tucson
United Statesfull_timeVerifiedPosted 27 Feb 2025
💰 $178,000/yr($102,000/yr – $178,000/yr)

About the role

Posting Close Date: 

Applicants must submit their completed application by 03-02-2025 at 11:59 p.m. MST

ABOUT THIS JOB

The Chief Information Security Officer position at the City of Tucson’s Information Technology (IT) Department is responsible for the development and implementation of a comprehensive citywide information security program. This position manages risks, ensures data protection and compliance with legal, external, and public interest obligations.

Work is performed under the supervision of the Director of Information Technology. This position exercises supervision over cybersecurity and compliance personnel.

Duties and Responsibilities

  • Develops short- and long-term strategies for optimizing the City's Information Security Plan, formulates policies to detect and mitigate threats, and advises the City Manager’s Office on data security for major IT projects. Oversees disaster recovery, business continuity, and the Cybersecurity team's budget and operations, ensuring comprehensive IT engagement and operational effectiveness. Represents the division in meetings with county, state, and advisory bodies on City data security policies and programs.

  • Collaborates with risk management and leadership to establish and maintain the City's risk register to ensure effective cybersecurity risk management and accountability tracking. Oversees citywide security policies, the Written Information Security Program (WISP), and data governance, while promoting ongoing security and privacy training across all organizational levels. Sets citywide processes for protecting electronic and physical environments and leads cross-departmental efforts to address process violations and compromised data.

  • Leads security management practices, designs secure architecture, and ensures compliance with policies while monitoring system performance. Collaborates with IT leaders to track anomalies, investigate threats, and address vulnerabilities based on prioritized response plans. Conducts audits, resolves security gaps, and manages contracts for security software and equipment and presents recommendations.

  • Oversees threat and vulnerability assessments, conducts routine network and system evaluations for abnormal behavior, and prioritizes response plans. Manages penetration testing and investigates unsecured data or systems, ensuring compliance with policies and governance. Restricts access and blocks threats in high-risk areas, working with relevant parties for swift resolution.

  • Recommends professional development for IT security staff and department data officers, coordinating training and awareness programs. Partners with the Public Information Office to guide the public on cyber hygiene and awareness. Addresses threats from bad actors misrepresenting City identities.

  • Provides supervision through clear direction, sets performance expectations, and guides the team's efforts toward achieving goals. Conducts performance reviews, offers constructive feedback, and supports employee development. Participates in the hiring process by interviewing candidates and making recommendations for new hires.

  • Performs all other duties and tasks as assigned.

Working Conditions:

Mostly office environment.

All duties and responsibilities listed are subject to change.

MINIMUM QUALIFICATIONS

Education: Bachelor's Degree
Experience: Five (5) years of directly related experience

Preferred Qualifications:

Seven (7) years in information technology or security management with five (5) years concentrated in information security. At least 4 of required 7 years in Lead or Supervisory capacity in a related functional area.
Experience in: information security principles and frameworks (NIST, ISO 27001/2), designing, implementing, and managing security programs, remote access systems (RAS), digital certificates, sniffers, Demilitarized Zones (DMZ)/Transaction Zones, Intrusion Detection/Intrusion Prevention Systems (IDS/IPS), Security Information & Event Management (SIEM), ICS/SCADA, Internet of Things(IOT), cloud security, business continuity planning, auditing, security automation and orchestration tools, Health Insurance Portability and Accountability Act(HIPAA), Criminal Justice Information Systems(CJIS), Payment Card Industry(PCI) and related regulatory compliance requirements, risk management, contract and vendor negotiation, and physical security.

Certification in: Certified Inf

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

City of Tucson

View company profile →