ESSENTIAL FUNCTIONS
1. Oversees the approval, training, and dissemination of security policies, standards, and practices.
2. Develops and enhances an information security management and control framework based on established industry standards.
3. Implements security improvements by assessing current situation, evaluating trends, anticipating requirements, recognizing problems by identifying anomalies, conducting periodic audits, and reporting violations.
4. Manages the framework for roles and responsibilities with regard to information ownership, classification, accountability and protection.
5. Facilitates information security through the implementation of an industry best practice-based governance program.
6. Maintains accountability for information security program governance through the Internet Content Filtering Management Governance Committee.
7. Creates and oversees the successful execution of the security roadmap including roles and responsibilities ensuring acceptable use policies.
8. Assesses overall information security risk posture, by measuring compliance with policy to ensure that security procedures are compliant with relevant laws, regulations and industry best practices, and initiates programs to achieve and maintain a successful cyber security posture.
9. Develops and maintains external and internal relationships to influence security policy, standards and programs and enhance secure interoperability with extended entities such as third-party software data interfaces.
10. Leverages information security investments to enhance District administration and compliance processes.
11. Creates and manages information security and risk management communications, training and awareness programs tailored to the evolving needs of the District.
12. Develops and maintains the cyber security risk assessment process, including the reporting and oversight of treatment efforts to address findings.
13. Provides strategic risk guidance for Technology projects and trusted learning environments including the evaluation and recommendation of technical controls and solutions.
14. Works with the appropriate District resources to monitor the external threat environment for emerging threats, and advises relevant stakeholders on the appropriate courses of action.
15. Leads the development and management of a comprehensive Threat and Vulnerability Management program.
16. Oversees cyber security incident response capabilities, and directs enhancements to align with industry standards.
17. Performs other duties as assigned by the Chief Information Officer.
|