State of Florida

WT: CISO/ISM - 41500700

State of Florida • $100K — $110K *
Education, Government & Non-Profit
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • At least 4 years of experience in information security, with 3 years handling security incidents.
  • Associate's degree with 2 years of incident response experience, or equivalent experience.
  • Minimum of 1 year managing security projects or teams.
  • Familiarity with regulatory frameworks such as NIST, ISO 27001, and HIPAA.
  • Ability to manage projects, teams, vendors, and budgets effectively.

Responsibilities

  • Develop and maintain the agency's information security policies.
  • Implement a comprehensive enterprise information security risk management program.
  • Oversee security audits and ensure compliance with policies and regulations.
  • Design and manage security testing procedures to identify risks.
  • Lead incident response activities and coordinate security efforts across the agency.
  • Conduct vulnerability assessments and manage threat operations.
  • Develop cybersecurity awareness programs and training for staff.

Benefits

  • Low premium health, dental, vision, and life insurance options.
  • Generous paid personal time including annual leave, sick leave, and holidays.
  • Paid administrative leave for various civic duties and volunteer activities.
  • Family planning support with adoption benefits and leave options.
  • Employer-contributed retirement and deferred compensation plans.
  • Free basic life insurance coverage and options for family members.
  • Flexible Spending Accounts available for additional financial flexibility.
  • Tuition waivers for employees seeking further education.
Full Job Description
Requisition No: 884362

Agency: Florida Gaming Control Commission



Pay Plan: SES

Position Number: 41500700

Salary: $100,000.00 - $110,000.00 annually

Posting Closing Date: 09/29/2026

Total Compensation Estimator Tool

FLORIDA GAMING CONTROL COMMISSION

Division of Administration

Office of Information Technology

Class Title: Info Tech Business Consultant Mgr - SES

Working Title: Chief Information Security Officer/Information Security Manager

Position Number: 41500700

Hiring Salary Range: $100,000 - $110,000 annually

***Open Competitive***

*Anticipated Vacancy*

Overview:

The Florida Gaming Control Commission is responsible for exercising all regulatory and executive powers of the state with respect to legal gaming, including pari-mutuel wagering, cardrooms, slot machine facilities, oversight of gaming compacts, and other forms of gambling authorized by state law, excluding the Lottery, as well as directly enforcing Florida's gaming laws and combatting illegal gambling activities.

Position Duties and Responsibilities:

This position serves as the Chief Information Security Officer (CISO) and Information Security Manager (ISM) for the Florida Gaming Control Commission and is responsible for developing, maintaining, and enforcing the Agency's information security policies. The CISO/ISM is responsible for developing, implementing, and maintaining a strategic, comprehensive enterprise information security and IT risk management program, which includes procedures and policies designed to protect enterprise communications, systems, and assets from both internal and external threats, and enforces compliance with State and Federal requirements across all technology projects, systems, and services.

Duties include, but are not limited to:

  • Developing, implementing, and monitoring a strategic, comprehensive enterprise information security and IT risk management program;
  • Assisting resource owners and IT staff in understanding and responding to security audit failures reported by auditors;
  • Ensuring audit trails, system logs, and other monitoring data sources are reviewed periodically to ensure compliance with policies, audit requirements, and regulatory standards;
  • Designing, coordinating, and overseeing security testing procedures to verify the security of systems, networks, and applications, and manage the remediation of identified risks;
  • Developing and enhancing an information security management framework;
  • Creating, maintaining, and enforcing security policies, standards, procedures, controls, and guidelines that meet State and Federal requirements;
  • Leading incident response activities, including detection, analysis, containment, eradication, recovery, documentation, and notifications; oversee and coordinating the CSIRT;
  • Conducting and coordinating vulnerability assessments, security testing, and risk remediation efforts; manage continuous threat and vulnerability management operations;
  • Guiding development, testing, and maintenance of disaster recovery and business continuity plans;
  • Overseeing identity and access management governance, including access reviews, certifications, and privileged accmanagingount monitoring;
  • Developing, maintaining, and measuring the effectiveness of the agency's cybersecurity awareness program, including phishing, smishing, vishing, and other human-factor risk reduction initiatives; and
  • Providing leadership to the enterprise's information security organization and participating in strategic technology planning and governance.


Required Knowledge, Skills, and Abilities:
  • Knowledge of distributed processing operations, software, procedures, and equipment;
  • Knowledge of Information Security, principles, and best practices;
  • Knowledge of problem-solving techniques;
  • Knowledge of computers and software;
  • Knowledge of the principles, practices, and techniques of computer systems analysis;
  • Knowledge of the principles of networking and telecommunication;
  • Knowledge of telecommunications principles, equipment, procedures, and terminology;
  • Knowledge of audit procedures;
  • Knowledge of the principles of cryptography and cryptanalysis;
  • Knowledge of application and system technology security testing;
  • Ability to develop and maintain policies, procedures, standards, and guidelines;
  • Ability to process information logically and solve problems;
  • Ability to develop training programs related to distributed processing operations and procedures;
  • Ability to monitor, troubleshoot, and resolve problems with distributed computer systems components;
  • Ability to identify and define user needs;
  • Ability to communicate effectively;
  • Ability to establish and maintain effective working relationships with others;
  • Ability to prioritize, plan, organize, and coordinate work assignments;
  • Ability to author technical reports; and
  • Ability to analyze security requirements and relate them to the appropriate security controls.


Minimum Qualifications:
  • Four (4) years of information security experience with at least three (3) years responding to security incidents; OR
  • An associate's degree from an accredited college or university and two (2) years of experience responding to security incidents.
  • One (1) year of experience managing security projects, efforts, or teams.
  • Experience with various regulatory requirements, laws, and security frameworks, such as NIST, ISO 27001, PCI DSS, HIPAA, HITECH, SOX, GDPR, CCPA, CIS, or SOC 2.
  • Ability to manage a project, internal/external contractors' team, vendors, budget, and initiatives.


Preferred Qualifications, not required:
  • A bachelor's degree from an accredited college or university in information technology, computer engineering, business administration or a related field.
  • Industry recognized certifications such as: CISSP, CISM, CCSP, OSCP, CEH/CND, CySA+, Sec+, or related GIAC certification.
  • Experience securing cloud environments like Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
  • Experience with firewalls and IAM/PAM systems and vendors.


Where you will work:

This position is located in Tallahassee, Florida. This is not a telework position.

Applicants are required to apply through the People First system by the closing date, by applying online. All required documentation must be received by the closing date of the advertisement. If you have any questions regarding your application, you may call 1-877-562-7287.

Benefits of Working For The State of Florida:

Working for the State of Florida is more than a paycheck. The state offers a comprehensive compensation package for our employees that features a highly competitive set of benefits including:
  • Low premium health, dental, vision, life, and supplemental coverage options!
  • Paid personal time that includes annual leave, sick leave, nine paid holidays, and one personal holiday!
  • Paid administrative leave for mentoring, volunteering, voting, and more!
  • Family planning support that includes adoption benefits and paid/unpaid leave options for family and medical responsibilities!
  • Retirement plans that include employer contributions (For more information, visit www.myfrs.com)!
  • Deferred compensation plans!
  • FREE basic life insurance plus additional options for you, your spouse, and children!
  • Flexible Spending Accounts!
  • Tuition waivers!


About State of Florida

The State of Florida is a state located in the southeastern region of the United States. It is the third-most populous state and the 22nd largest by area. The state capital is Tallahassee and its largest city is Jacksonville. Florida is known for its warm climate, beautiful beaches, and tourist attractions such as Walt Disney World, Universal Studios, and the Kennedy Space Center. The state is also home to a number of universities and colleges, including the University of Florida, Florida State University, and the University of Miami.
Learn more about State of Florida

Similar Jobs

More Jobs at State of Florida

More Education, Government & Non-Profit Jobs

Find similar WT: CISO/ISM - 41500700 jobs: