What are the responsibilities and job description for the Information Security Manager position at FRANKLIN COUNTY OHIO?
Organization Summary
FCDC provides cost-effective, business-driven, collaborative, and secure IT services and solutions to public service agencies throughout Ohio’s most dynamic county. Our goals are simple, but expansive: to be the most trusted enterprise technology service provider for Franklin County and a national leader in digital government services. Every day, the FCDC team empowers local government departments, agencies, teams, and nonprofits to deliver top-notch services to residents and businesses in central Ohio, and we take pride in the work they accomplish with our support.
Job Summary
The Enterprise Information Security Manager, reporting to the Chief Information Security Officer, is responsible for designing, implementing, and overseeing assigned components of the information security program and framework for the Franklin County Data Network (FCDN). This individual possesses vast experience in information security practices, secure network architecture, Internet Protocol (IP), firewalls, encryption, intrusion detection systems, web filtering, authentication, and authorization methodologies. The Enterprise Information Security Manager will assist the CISO with preserving the confidentiality, integrity, availability, and non-repudiation of County information resources by developing, deploying, and embedding information security architecture, policies, and standards. The Enterprise Information Security Manager must demonstrate practical communication skills and the ability to train others on security policies and practices. They must be able to manage staff, contractors, and services, providing technical direction as necessary.
The Security Manager’s primary focus is on work management and product ownership for the assigned individuals and security capabilities. As a secondary focus, the Security Manager will closely collaborate with the CISO in developing the Information Security Strategy and vision. In the absence of the CISO, the Security Manager may assume responsibility for leading the Information Security team.
Essential Duties and Responsibilities
Manage complex IT architecture projects with competency to preserve the confidentiality, integrity, availability, and non-repudiation of the FCDN.
Assist in developing Security strategy, policy, and roadmaps for Franklin County Technology services, software, hardware, and other physical resources (e.g., cloud, client, collaboration, virtualization, network, server, data center, etc.)
Responsible for the development, deployment, and embedding of information security architecture, policies, and standards
Collaborate with Enterprise IT and Infrastructure engineers and Enterprise Architects on planning, developing, and supporting core technologies like Azure Active Directory, local and cloud storage and sharing, collaboration, endpoint delivery and security, email systems, and more.
Coordinate the documentation, distribution, and enforcement of FCDN security policies, standards, and procedures, collaborating with key IT staff to develop and implement communication strategies for all cyber security policies and procedures.
Create and maintain cyber risk management methodologies.
Develop effective security risk and control metrics.
Responsible for leading the execution of day-to-day security operations and engineering teams.
Regularly collaborate with the directors/managers in enterprise IT, government experience, and partner experience management to ensure cohesion of planning, implementation, and communication strategies.
Keep abreast of the latest security legislation, regulations, advisories, alerts, and FCDN vulnerabilities.
Lead and develop Enterprise Information Security team members, in collaboration with People Operations, using quarterly review frameworks, 1:1 meetings, modeling of professional development behaviors, utilization of training budgets, and encouragement of cross-training opportunities
Manages direct staff functions, including activity tracking, time reporting, and performance appraisals.
Lead the vulnerability management program for the external and internal networks, servers, PCs, applications, and endpoint devices.
Lead the incident response program to address, control, and manage information security incidents, events, or security breaches.
Act as backup coordinator and communicator for Enterprise Information Security during major incidents at any time
Participating in Information Security annual strategy development, budgeting, and resource planning.
Collaborate with Enterprise Financial Services on vendor and contractor reviews, selections, purchases, renewals, and project engagements
Promote growth of FCDC services and client agency collaborations in line with FCDC's vision, mission, and values
Security Capabilities
Responsible for the effective use of the following security capabilities:
Intrusion detection and prevention tools
Vulnerability Management Solution
Firewall systems
Web and content filtering tools
Log correlation engines
Endpoint and Server Detection and Response Capabilities
Endpoint and Server Patch Management Solution
Next-Generation Security Information and Event Management (NG-SIEM)
Email Security tools
Mobile Device Management (MDM) tools
Microsoft 365 Security Capabilities
Supervisory Responsibilities
The Enterprise Information Security Manager directly supervises assigned team members within the Information Security department. In the absence of the CISO, the Security Manager may also provide the CIO with broader temporary leadership of Information Security and guidance. The Security Manager will provide the following forms of staff supervision, development, and leadership:
Set and maintain high expectations for teams and individuals in terms of work quality and quantity
Develop staff skills via ongoing assessment and utilization of training resources
Ensure the development of Information Security team members in line with FCDC standards
Actively participate in employee and contractor hiring activities for Information Security
Collaborate with People Operations as needed when taking employee disciplinary actions as outlined in FCDC policy
Demonstrate FCDC values and promote the vision and mission of the organization with staff
Heavily encourage cross-team collaboration within Information Security and across FCDC
Develop individual and team project management capacity internally and promote collaboration with Enterprise Delivery Services and Partner Experience Teams
FCDC BENEFITS
Medical, Dental, Vision and Behavioral Health, and Prescription Drug Coverage
Employee Assistance Program
Disability and Life Insurance
Ohio Public Employees Retirement System (OPERS)
Deferred Compensation
Generous Paid Time Off Accrual
Eleven Paid Holidays
Tuition Reimbursement
Company-Paid Training and Development
Commuter Program
The Franklin County Data Center is an Equal Opportunity Employer.