Job Announcement: HR2025:06 Position Title: Chief Information Security Officer (CISO) Advertising: Publicly Immediate Supervisor: Chief Information Officer (CIO) Department Director: Chief Information Officer (CIO) Department: Information Technology (I.T.) Division: Tribal Chairs Office Employment Status: Exempt Position Type: Regular FullTime Mandatory Reporter: No Background Check Required: Yes (data-sensitive)** Opening Date: Thursday, January 9, 2025 Closing Date: Open Until Filled Preference shall be given in accordance with the Title 33 (Tribal Employment Rights) of the Tribal Code/DFWP. Overview We are looking for motivated professionals who thrive on flexibility, take ownership through accountability, and are driven by a passion for innovation. In this role, you will have the opportunity to contribute your expertise, adapt to evolving challenges, and deliver impactful results that support our mission and goals. By fostering creative solutions and embracing new opportunities, you will play a key role in shaping a dynamic and forward-thinking environment. Primary Objectives The Chief Information Security Officer is a professional staff member responsible for defining, implementing, and overseeing the Poarch Band of Creek Indians' enterprise-wide information security program. This critical role ensures the protection of IT infrastructure, digital assets, and sensitive data against evolving cybersecurity threats while maintaining compliance with applicable regulations and standards. Reporting directly to the CIO, the CISO will lead the development of a strategic security vision, align security initiatives with organizational priorities, and collaborate with stakeholders to embed cybersecurity best practices across all levels of the organization. The role may include supervision of one or more security analysts as the security team grows to support the Tribes needs. The CISO will play a pivotal role in advancing a resilient, secure, and adaptive IT environment. This job description is not an all-inclusive list of the duties and responsibilities of this position. PCI Employees are expected to perform all duties and responsibilities necessary to meet the goals and objectives of applicable programs and departmental objectives, as assigned. Professional Staff of the Poarch Creek Indians will consistently demonstrate the abilities to influence, innovate, flex their style, and problem solve along with a strong commitment to embodying the core values of the Poarch Creek Indians, which include Perseverance, Opportunity, Accountability, Respect, Culture, and Honesty. Essential Functions Designs and implements a comprehensive, forward-looking information security strategy that aligns with the organizations goals, objectives, and regulatory requirements. Regularly assess and updates the strategy to address evolving threats and organizational needs. Establishes, maintains, and enforces security policies, standards, and procedures. Ensures these policies are effectively communicated and integrated into daily operations to support a culture of cybersecurity awareness and compliance. Conducts regular risk assessments to identify and mitigate potential vulnerabilities in the organizations IT systems, applications, and infrastructure. Oversees penetration testing, security audits, and vulnerability scans, and implement remediation strategies to address identified risks. Designs and manages security monitoring, threat detection, and response processes. Leads the organizations response to cybersecurity incidents, ensuring timely investigation, containment, and resolution while minimizing impact and preserving evidence for further analysis. Evaluates, selects, and implements cutting-edge security technologies to enhance the organization's defense mechanisms. Areas of focus include, but are not limited to, network security, endpoint protection, identity and access management, and data loss prevention. Ensures compliance with applicable laws, regulations, and standards, including HIPAA, NIST, PCI DSS, and others as relevant to the organization. Works with legal and compliance teams to manage security audits and certification processes. Works closely with internal stakeholders, including executives and department leaders, to ensure security initiatives align with organizational objectives. Oversees cybersecurity awareness training programs to educate staff on best practices, phishing prevention, and other critical security topics. Stays informed about emerging security trends, technologies, and threat vectors. Adapts and refines security strategies and tools to maintain a proactive stance against potential threats. Prepares regular reports and presentations on the organizations security posture, risks, and key initiatives for the CIO, executive leadership, and Tribal Council. Provides actionable recommendations to enhance cybersecurity resilience and drive informed decision-making. Oversees daily operations of security tools and technologies, such as firewalls, intrusion detection systems (IDS), and security information and event management (SIEM) systems. Reviews system alerts and logs to detect potential threats or breaches. Responds to security incidents promptly, including identifying the source, mitigating damage, and implementing recovery strategies. Conducts post-incident analysis to improve future response efforts. Conducts routine risk assessments and vulnerability scans to identify potential security gaps. Prioritizes and oversees the remediation of identified vulnerabilities. Ensures compliance with organizational security policies, standards, and procedures. Regularly reviews and updates policies to reflect changes in technology, threats, and regulations. Works closely with the IT Engineering Services and Enterprise Systems Services teams to ensure security is integrated into all technology initiatives. Provides guidance on secure system design and configuration. Monitors compliance with applicable regulations, such as NIST, HIPAA, and PCI DSS. Prepares and manages audits and reports for regulatory and compliance reviews. Leads or coordinates security awareness training programs for employees to reduce human-related risks. Addresses user questions and concerns regarding security best practices and tools. Stays updated on emerging cybersecurity threats, trends, and technologies. Implements proactive measures, such as threat hunting and penetration testing, to detect and mitigate potential risks. Tracks progress on key security initiatives and projects. Ensures alignment of daily activities with the overall cybersecurity strategy. Evaluates and manages relationships with third-party vendors providing security solutions or services. Ensures third-party providers adhere to organizational security policies and standards. Maintains detailed documentation of security incidents, investigations, and resolutions. Prepares regular reports on the organization's security posture for the CIO and executive leadership. Addresses immediate security challenges and make quick, informed decisions to protect the organization. Develops solutions for improving security measures based on analysis and feedback. Oversees the timely application of security patches and updates to ensure systems remain protected against known vulnerabilities. Participates in meetings with executives, IT teams, and other departments to discuss security-related concerns, requirements, and strategies. As a part of the Tribes commitment to community service, the employee may be asked to perform other duties in the office or field as needed to support organizational objectives. Job Requirements Bachelors degree in Cybersecurity, Information Technology, or a related field required. Masters degree in Cybersecurity, Information Assurance, or a related field preferred. Minimum of five (5) years of experience as a Chief Information Security Officer or a similar senior-level role. CISSP (Certified Information Systems Security Professional) certification required or must obtain within one (1) year from date of hire. CISM (Certified Information Security Manager) certification preferred. CRISC (Certified in Risk and Information Systems Control) certification preferred. CEH (Certified Ethical Hacker) certification preferred. GIAC certifications (e.g., GSEC, GPEN, GCFA) certification preferred. Ability to work odd and irregular hours, as needed. Must successfully pass the required criminal and character background check. Must possess a valid state drivers license and insurable driving record according to Tribal insurance guidelines. Ability to travel and participate in required training, leadership development, and other events. Ability to perform all duties and responsibilities of this position adequately and successfully. Core Competencies Required Ability to develop, implement, and oversee a comprehensive enterprise-wide cybersecurity strategy. Strong leadership skills to manage teams and influence stakeholders at all levels. In-depth knowledge of information security technologies, including firewalls, intrusion detection/prevention systems, endpoint protection, and SIEM solutions. Proficiency in cloud security, network security, encryption, and data protection methodologies. Experience conducting risk assessments and vulnerability analyses. Proficiency in designing and implementing effective mitigation strategies. Expertise in incident detection, investigation, containment, and resolution. Ability to lead incident response teams and manage complex security events effectively. Strong knowledge of regulatory frameworks and standards such as HIPAA, NIST, PCI DSS, GDPR, and others relevant to the organization. Capability to create and enforce comprehensive cybersecurity policies, standards, and guidelines. Ability to analyze complex security issues, evaluate potential risks, and recommend actionable solutions. Strong verbal and written communication skills to effectively convey technical security concepts to non-technical audiences, including executive leadership and Tribal Council members. Proficiency in creating detailed reports and strategic presentations. Proven ability to work collaboratively across departments, ensuring alignment of security initiatives with organizational priorities. Awareness of emerging cybersecurity threats, trends, and technologies. Commitment to maintaining up-to-date knowledge in the rapidly evolving field of information security. Experience supervising and mentoring staff, with the ability to build and lead an effective cybersecurity team. Ability to delegate responsibilities and foster professional growth among team members. Strong organizational skills to manage multiple security projects simultaneously. Ability to prioritize tasks and meet deadlines under pressure. Strong sense of ethics and commitment to maintaining the confidentiality, integrity, and availability of organizational information. Proactively seeks opportunities to improve processes, practice, and policy. Adapts their style to suite the situation and audience. Can read the room and act accordingly. Ability to identify root causes and easily overcomes obstacles. Must be people oriented, relate well to people from diverse backgrounds, and possess respect for others. Serve as a role model. Must possess character that earns the confidence of program participants, aspire to your highest self, and serve as a cultural ambassador to others. Compensation and Benefits The starting pay will depend on factors such as experience level and skillset. Voluntary full-time benefit offerings include the following - medical, dental, vision, and life insurance and other volunteer insurance options. We also offer an Employee Assistance Program (EAP), paid time off, paid holidays, 401K with matching, bonuses, and COLA increase. Every applicant must complete an application provided by Human Resources. A resume will not be accepted in the place of an application. **Please note ALL individuals selected for employment are required to complete a background investigation. Individuals being placed in positions designed as child-sensitive or data-sensitive must successfully complete a background check prior to employment. INDIAN PREFERENCE, SPOUSAL PREFERENCE, OR FIRST GENERATION: In the event more than one applicant meets the requirements, as stated in a job description, preference shall be given in the following order: (1) Tribal Member (2) First Generation Descendant of a Tribal Member (3) Spouse of Tribal Member (4) Indian (5) Non-Indian In the event that a position of employment is funded in whole or in part my any federal grant and/or contract or other public funding, preference shall be given in the following order: (1) Indian (2) Non-Indian In order to receive preference, the appropriate documentation must be submitted. Poarch Band of Creek Indians
...area Competitive salary, bonus incentives, and full hospital benefits IM or FM physicians available now or 2025 residents; H-1B visa sponsorship available Central Pennsylvania location; 2 hours from Pittsburgh; 3 hours from Washington, D.C. or Baltimore Our services are...
...Collaboration with the Interdisciplinary Team. Provide oversight to the food service department with routine audit for safety, sanitation,... ...Continuing Education/Weekly Town Hall meetings Extensive Network of Dietitians Referral Bonuses Inclusive Culture ABOUT...
...DESCRIPTION Amazon Music is an immersive audio entertainment service that deepens connections between fans, artists, and creators. From personalized music playlists to exclusive podcasts, concert livestreams to artist merch, Amazon Music is innovating at some of the...
...Genie Healthcare is seeking a travel nurse RN Educator for a travel nursing job in Sitka, Alaska. Job Description & Requirements ~ Specialty: Educator ~ Discipline: RN ~ Start Date: ASAP ~ Duration: 13 weeks ~36 hours per week ~ Shift: 12 hours, days...
...comfortable home like environment. Responsibilities: Care Giver: Responsible for a designated group of residents during the shift; knows where their residents are and physically checks on them throughout the shift. Observes, reports and documents symptoms and...