Chief Information Security Officer (CISO) Job at Poarch Band of Creek Indians, Atmore, AL

OEJDejRqMFNXTHFFRjN4eUtWSjVYczJLOWc9PQ==
  • Poarch Band of Creek Indians
  • Atmore, AL

Job Description

Job Announcement: HR2025:06
Position Title: Chief Information Security Officer (CISO)
Advertising: Publicly
Immediate Supervisor: Chief Information Officer (CIO)
Department Director: Chief Information Officer (CIO)
Department: Information Technology (I.T.)
Division: Tribal Chair’s Office
Employment Status: Exempt
Position Type: Regular Full–Time
Mandatory Reporter: No
Background Check Required: Yes (data-sensitive)**
Opening Date: Thursday, January 9, 2025
Closing Date: Open Until Filled

Preference shall be given in accordance with the Title 33 (Tribal Employment Rights) of the Tribal Code/DFWP.

Overview
We are looking for motivated professionals who thrive on flexibility, take ownership through accountability, and are driven by a passion for innovation. In this role, you will have the opportunity to contribute your expertise, adapt to evolving challenges, and deliver impactful results that support our mission and goals. By fostering creative solutions and embracing new opportunities, you will play a key role in shaping a dynamic and forward-thinking environment.

Primary Objectives
The Chief Information Security Officer is a professional staff member responsible for defining, implementing, and overseeing the Poarch Band of Creek Indians' enterprise-wide information security program. This critical role ensures the protection of IT infrastructure, digital assets, and sensitive data against evolving cybersecurity threats while maintaining compliance with applicable regulations and standards. Reporting directly to the CIO, the CISO will lead the development of a strategic security vision, align security initiatives with organizational priorities, and collaborate with stakeholders to embed cybersecurity best practices across all levels of the organization. The role may include supervision of one or more security analysts as the security team grows to support the Tribe’s needs. The CISO will play a pivotal role in advancing a resilient, secure, and adaptive IT environment. This job description is not an all-inclusive list of the duties and responsibilities of this position. PCI Employees are expected to perform all duties and responsibilities necessary to meet the goals and objectives of applicable programs and departmental objectives, as assigned.

Professional Staff of the Poarch Creek Indians will consistently demonstrate the abilities to influence, innovate, flex their style, and problem solve along with a strong commitment to embodying the core values of the Poarch Creek Indians, which include Perseverance, Opportunity, Accountability, Respect, Culture, and Honesty.

Essential Functions
  •  Designs and implements a comprehensive, forward-looking information security strategy that aligns with the organization’s goals, objectives, and regulatory requirements.
  • Regularly assess and updates the strategy to address evolving threats and organizational needs.
  • Establishes, maintains, and enforces security policies, standards, and procedures.
  • Ensures these policies are effectively communicated and integrated into daily operations to support a culture of cybersecurity awareness and compliance.
  • Conducts regular risk assessments to identify and mitigate potential vulnerabilities in the organization’s IT systems, applications, and infrastructure.
  • Oversees penetration testing, security audits, and vulnerability scans, and implement remediation strategies to address identified risks.
  • Designs and manages security monitoring, threat detection, and response processes.
  • Leads the organization’s response to cybersecurity incidents, ensuring timely investigation, containment, and resolution while minimizing impact and preserving evidence for further analysis.
  • Evaluates, selects, and implements cutting-edge security technologies to enhance the organization's defense mechanisms.
  • Areas of focus include, but are not limited to, network security, endpoint protection, identity and access management, and data loss prevention.
  • Ensures compliance with applicable laws, regulations, and standards, including HIPAA, NIST, PCI DSS, and others as relevant to the organization.
  • Works with legal and compliance teams to manage security audits and certification processes.
  • Works closely with internal stakeholders, including executives and department leaders, to ensure security initiatives align with organizational objectives.
  • Oversees cybersecurity awareness training programs to educate staff on best practices, phishing prevention, and other critical security topics.
  • Stays informed about emerging security trends, technologies, and threat vectors.
  • Adapts and refines security strategies and tools to maintain a proactive stance against potential threats.
  • Prepares regular reports and presentations on the organization’s security posture, risks, and key initiatives for the CIO, executive leadership, and Tribal Council.
  • Provides actionable recommendations to enhance cybersecurity resilience and drive informed decision-making.
  • Oversees daily operations of security tools and technologies, such as firewalls, intrusion detection systems (IDS), and security information and event management (SIEM) systems.
  • Reviews system alerts and logs to detect potential threats or breaches.
  • Responds to security incidents promptly, including identifying the source, mitigating damage, and implementing recovery strategies.
  • Conducts post-incident analysis to improve future response efforts.
  • Conducts routine risk assessments and vulnerability scans to identify potential security gaps.
  • Prioritizes and oversees the remediation of identified vulnerabilities.
  • Ensures compliance with organizational security policies, standards, and procedures.
  • Regularly reviews and updates policies to reflect changes in technology, threats, and regulations.
  • Works closely with the IT Engineering Services and Enterprise Systems Services teams to ensure security is integrated into all technology initiatives.
  • Provides guidance on secure system design and configuration.
  • Monitors compliance with applicable regulations, such as NIST, HIPAA, and PCI DSS.
  • Prepares and manages audits and reports for regulatory and compliance reviews.
  • Leads or coordinates security awareness training programs for employees to reduce human-related risks.
  • Addresses user questions and concerns regarding security best practices and tools.
  • Stays updated on emerging cybersecurity threats, trends, and technologies.
  • Implements proactive measures, such as threat hunting and penetration testing, to detect and mitigate potential risks.
  • Tracks progress on key security initiatives and projects.
  • Ensures alignment of daily activities with the overall cybersecurity strategy.
  • Evaluates and manages relationships with third-party vendors providing security solutions or services.
  • Ensures third-party providers adhere to organizational security policies and standards.
  • Maintains detailed documentation of security incidents, investigations, and resolutions.
  • Prepares regular reports on the organization's security posture for the CIO and executive leadership.
  • Addresses immediate security challenges and make quick, informed decisions to protect the organization.
  • Develops solutions for improving security measures based on analysis and feedback.
  • Oversees the timely application of security patches and updates to ensure systems remain protected against known vulnerabilities.
  • Participates in meetings with executives, IT teams, and other departments to discuss security-related concerns, requirements, and strategies.
  • As a part of the Tribe’s commitment to community service, the employee may be asked to perform other duties in the office or field as needed to support organizational objectives.
Job Requirements
  •  Bachelor’s degree in Cybersecurity, Information Technology, or a related field required. Master’s degree in Cybersecurity, Information Assurance, or a related field preferred.
  • Minimum of five (5) years of experience as a Chief Information Security Officer or a similar senior-level role.
  • CISSP (Certified Information Systems Security Professional) certification required or must obtain within one (1) year from date of hire.
  • CISM (Certified Information Security Manager) certification preferred.
  • CRISC (Certified in Risk and Information Systems Control) certification preferred.
  • CEH (Certified Ethical Hacker) certification preferred.
  • GIAC certifications (e.g., GSEC, GPEN, GCFA) certification preferred.
  • Ability to work odd and irregular hours, as needed.
  • Must successfully pass the required criminal and character background check.
  • Must possess a valid state driver’s license and insurable driving record according to Tribal insurance guidelines.
  • Ability to travel and participate in required training, leadership development, and other events.
  • Ability to perform all duties and responsibilities of this position adequately and successfully.
Core Competencies Required
  • Ability to develop, implement, and oversee a comprehensive enterprise-wide cybersecurity strategy.
  • Strong leadership skills to manage teams and influence stakeholders at all levels.
  • In-depth knowledge of information security technologies, including firewalls, intrusion detection/prevention systems, endpoint protection, and SIEM solutions.
  • Proficiency in cloud security, network security, encryption, and data protection methodologies.
  • Experience conducting risk assessments and vulnerability analyses.
  • Proficiency in designing and implementing effective mitigation strategies.
  • Expertise in incident detection, investigation, containment, and resolution.
  • Ability to lead incident response teams and manage complex security events effectively.
  • Strong knowledge of regulatory frameworks and standards such as HIPAA, NIST, PCI DSS, GDPR, and others relevant to the organization.
  • Capability to create and enforce comprehensive cybersecurity policies, standards, and guidelines.
  • Ability to analyze complex security issues, evaluate potential risks, and recommend actionable solutions.
  • Strong verbal and written communication skills to effectively convey technical security concepts to non-technical audiences, including executive leadership and Tribal Council members.
  • Proficiency in creating detailed reports and strategic presentations.
  • Proven ability to work collaboratively across departments, ensuring alignment of security initiatives with organizational priorities.
  • Awareness of emerging cybersecurity threats, trends, and technologies.
  • Commitment to maintaining up-to-date knowledge in the rapidly evolving field of information security.
  • Experience supervising and mentoring staff, with the ability to build and lead an effective cybersecurity team.
  • Ability to delegate responsibilities and foster professional growth among team members.
  • Strong organizational skills to manage multiple security projects simultaneously.
  • Ability to prioritize tasks and meet deadlines under pressure.
  • Strong sense of ethics and commitment to maintaining the confidentiality, integrity, and availability of organizational information.
  • Proactively seeks opportunities to improve processes, practice, and policy.
  • Adapts their style to suite the situation and audience. Can read the room and act accordingly.
  • Ability to identify root causes and easily overcomes obstacles.
  • Must be people oriented, relate well to people from diverse backgrounds, and possess respect for others. Serve as a role model.
  • Must possess character that earns the confidence of program participants, aspire to your highest self, and serve as a cultural ambassador to others.
Compensation and Benefits
  • The starting pay will depend on factors such as experience level and skillset.
  • Voluntary full-time benefit offerings include the following - medical, dental, vision, and life insurance and other volunteer insurance options. We also offer an Employee Assistance Program (EAP), paid time off, paid holidays, 401K with matching, bonuses, and COLA increase.

Every applicant must complete an application provided by Human Resources. A resume will not be accepted in the place of an application.

**Please note ALL individuals selected for employment are required to complete a background investigation. Individuals being placed in positions designed as child-sensitive or data-sensitive must successfully complete a background check prior to employment.

INDIAN PREFERENCE, SPOUSAL PREFERENCE, OR FIRST GENERATION:

In the event more than one applicant meets the requirements, as stated in a job description, preference shall be given in the following order: (1) Tribal Member (2) First Generation Descendant of a Tribal Member (3) Spouse of Tribal Member (4) Indian (5) Non-Indian

In the event that a position of employment is funded in whole or in part my any federal grant and/or contract or other public funding, preference shall be given in the following order: (1) Indian (2) Non-Indian

In order to receive preference, the appropriate documentation must be submitted.

Job Tags

Holiday work, Full time, Contract work, Immediate start, Flexible hours,

Similar Jobs

Life Surge

Direct Response Copywriter Job at Life Surge

 ...Sell: Create high-impact copy for emails, landing pages, ads, social media, and sales funnels that drive action, not just applause. Master...  ...people need in their livesyesterday. Be the Voice of the Brand: Develop and maintain a consistent brand voice that blends... 

The Ohio State University Wexner Medical Center

Physician - radiologist / track Job at The Ohio State University Wexner Medical Center

 ...information in your candidate profile as it will transfer to your application. Job Title Physician - Radiology, Interventional Radiologist (Open Rank/Track Faculty) Department The Ohio State University College of Medicine and the Wexner Medical Center seek an... 

Delta-T Group Inc.

Staffing Coordinator Job at Delta-T Group Inc.

 ...Location: Needham, MA 02494 Date Posted: 04/05/2025 Category: Recruitment Education: High School Diploma/GED At the Delta-T Group, we offer premier referral solutions for the social-services, special-education, behavioral and allied-health fields. We have thrived... 

Colorado Autism Consultants

Registered Behavior Technician Job at Colorado Autism Consultants

 ...Registered Behavior Technician Gunnison, Colorado, US Colorado Autism Consultants is dedicated to overcoming barriers to make transformational ABA therapy equally accessible throughout our state. We're looking for Behavior Technicians with a strong work ethic and... 

Dairy Queen

Crew Person Job at Dairy Queen

 ...start at the highest rate of pay. These candidates are generally 18 years of age or older. Candidates under the age of 18 will be impacted by state restrictions on when you can work. **14- and 15-year-old candidates are limited to 18 hours per week, not allowed to work...