Salary: $173,420.70 - $209,121.28 Annually
Location : City of Long Beach, CA
Job Type: Unclassified - Full-Time, Permanent
Remote Employment: Flexible/Hybrid
Job Number: TI26-038
Department: Technology & Innovation - (UC)
Opening Date: 07/21/2026
Closing Date: 8/20/2026 11:59 PM Pacific
DESCRIPTIONAppointment to this position is expected to be at or below the midpoint
$191,270 of the salary range, however, the final amount will be carefully determined based on the candidate's knowledge, skills, qualifications, and an evaluation of internal equity within the organization.
The Department of Technology and Innovation currently has one (1) opening for a Cyber Security Officer (CSO).
THE POSITIONThe Cyber Security Officer (CSO) is a strategic and operational leader responsible for the planning, organization, and direction of the City's Cyber Security Division. Reporting directly to the Director of the Technology & Innovation Department (TID), the CSO serves as a key member of the TID management team and plays a central role in ensuring Long Beach can successfully respond to a rapidly evolving technology and threat environment. The CSO leads and develops the City's cybersecurity vision, guiding the adoption of modern security tools and practices including endpoint detection and response, privileged access management, data governance- controls, and AI governance to safeguard the City's technology, information assets, and community trust.
As the City's systems expand and become increasingly interconnected, the CSO ensures the City remains ahead of emergent threats and implements proactive measures to keep critical services, public safety systems, and resident data secure yet appropriately accessible. This includes maintaining compliance with regulatory obligations such as Criminal Justice Information Services (CJIS), the Payment Card Industry Data Security Standard (PCI DSS), and the Health Insurance Portability and Accountability Act (HIPAA). The CSO leads the technology and cybersecurity components of the City's PCI program, partnering with the Financial Management Department to support enterprise-wide PCI compliance.
Under the general direction of the Director, the CSO operates with a high degree of independence and focus, overseeing all aspects of cyber risk, security operations, enterprise tools, and policy governance. This includes citywide leadership of advanced security platforms such as SentinelOne for Endpoint Detection and Response (EDR) and threat hunting operations, CyberArk for privileged access management, and Varonis for data security, file -system monitoring, and insider risk detection. A key aspect of this role is collaborating with executive leadership and department heads to determine acceptable levels of risk, align security strategies with business needs, and implement scalable, zero trust a-ligned security architectures.
Serving as the City's primary point of contact for cyber risk and security issues, the CSO develops, recommends, and enforces cybersecurity and AI governance policies; establishes data governance best practices; and ensures that all security controls-current and future-are deployed in a deliberate, orderly, and well-architected manner. The CSO works closely with TID bureaus, business units, and external partners to cultivate a strong security culture and ensure operational practices fully align with agreed u-pon standards.
This position requires exceptional communication skills and the ability to convey complex technical and risk -related concepts to both technical and nontechnical audiences. Strong interpersonal skills, diplomacy, and relationship--building capabilities are essential for inspiring trust and shaping citywide adoption of secure practices. The ideal CSO brings a team---oriented, collaborative leadership style; is resourceful and adaptive; and is energized by guiding major organizational change and continuous security improvement.
The ideal candidate is a creative, forward-thinking leader who embodies high ethical standards, a deep understanding of government and municipal cybersecurity requirements, and a commitment to public service. They have direct experience leading modern cybersecurity programs; implementing enterprise class platforms such as SentinelOne, CyberArk, and Varonis; maturing PCI compliance programs; and advancing data governance and AI policy frameworks. They understand zero- trust principles, cloud and hybrid- environment security, identity-centric protections, and the importance of building meaningful, trust-based partnerships across diverse departments. The City seeks a CSO who can guide, influence, and collaborate across the entire organization-providing practical, actionable, and forward looking- solutions to technology risk management, security governance, and resilience.
EXAMPLES OF DUTIES The specific responsibilities of the position include:
- Develops an information security vision and strategy that is aligned to organizational priorities and enables and facilitates the City's goals and objectives and ensures stakeholder alignment.
- Creates and manages a unified and flexible, risk-based control framework to integrate and normalize the wide variety and ever-changing requirements resulting from global laws, standards and regulations
- Oversees portfolio of cyber risk and security processes and applications and originates and implements new processes and applications to ensure efficient and effective cyber security for the Citywide systems.
- Analyzes information, situations, problems, policies and procedures to define problems accurately, and identify and implement potential solutions systematically.
- Leads and continuously enhance the City's EDR operations, including threat monitoring, threat hunting, and coordinated response.
- Oversees the City's privileged access management platform, ensuring least privilege principles and secure credential vaulting.
- Manages and optimizes the City's enterprise data security operations platform including access auditing, insider risk detection, and automated remediation.
- Directs and maintains the City's PCI DSS compliance program, including assessments, quarterly scans, merchant oversight, and annual attestation.
- Governs and maintains citywide AI policy, ensuring responsible and ethical AI use aligned to regulatory guidance.
- Strengthens enterprise data governance through classification, retention, lifecycle, and controlled-access processes.
- Leads identity protection initiatives including MFA adoption, privilege reduction, and identity attack surface reduction.
- Guides cloud and hybrid environment security posture management.
- Integrates security telemetry, supports SOC operations, and improves detection and response maturity.
- Establishes, communicate, and enforce security controls in an orderly, proactive, and scalable manner.
- Develops cyber risk technology training programs for City employees.
- Prepares oral and written reports for senior management, the City Manager's office and elected officials.
- Selects, trains, evaluates, and directs subordinate staff.
- Delivers exceptional customer support and innovative technology services.
REQUIREMENTS TO FILEEducation- A bachelor's degree is required in Computer Science, Information Technology, Public Administration, Business Administration or a related field.
- Experience may be substituted for education on a year for year basis for a total of nine (9) years' experience (Four years to substitute for the degree plus the five years recent experience as explained above).
Experience- The position requires a minimum of five (5) years of recent increasingly responsible experience in cyber security, in a technology environment similar in size, scope and complexity to the City of Long Beach. A minimum of two of those years at an administrative or supervisory level with overall responsibility for budgets, personnel administration and project management.
The following are desirable:
- A master's degree in computer science, Information Technology, Public Administration, Business Administration, or a related field.
- Certification as a Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC) or equivalent information security certification.
- Prior experience with IT operations, IT infrastructure, and/or IT enterprise applications.
SELECTION PROCEDUREThis recruitment will close at 11:59 PM Pacific Time on Thursday August 20, 2026. To be considered, please submit an online application, including a cover letter, resume, and proof of education (If qualifying with a degree) in PDF format. Applications that fail to include all necessary documents will be considered incomplete and will not be taken into consideration.
Applications will be reviewed for depth and breadth of experience, and for level and relatedness of education. The most qualified candidates will be invited to participate in further selection procedures. The selected candidate may be required t