Requisition No: 884362
Agency: Florida Gaming Control Commission
Pay Plan: SES
Position Number: 41500700
Salary: $100,000.00 - $110,000.00 annually
Posting Closing Date: 09/29/2026
Total Compensation Estimator ToolFLORIDA GAMING CONTROL COMMISSIONDivision of AdministrationOffice of Information TechnologyClass Title: Info Tech Business Consultant Mgr - SESWorking Title: Chief Information Security Officer/Information Security ManagerPosition Number: 41500700Hiring Salary Range: $100,000 - $110,000 annually
***Open Competitive****Anticipated Vacancy*Overview:The Florida Gaming Control Commission is responsible for exercising all regulatory and executive powers of the state with respect to legal gaming, including pari-mutuel wagering, cardrooms, slot machine facilities, oversight of gaming compacts, and other forms of gambling authorized by state law, excluding the Lottery, as well as directly enforcing Florida's gaming laws and combatting illegal gambling activities.
Position Duties and Responsibilities:This position serves as the Chief Information Security Officer (CISO) and Information Security Manager (ISM) for the Florida Gaming Control Commission and is responsible for developing, maintaining, and enforcing the Agency's information security policies. The CISO/ISM is responsible for developing, implementing, and maintaining a strategic, comprehensive enterprise information security and IT risk management program, which includes procedures and policies designed to protect enterprise communications, systems, and assets from both internal and external threats, and enforces compliance with State and Federal requirements across all technology projects, systems, and services.
Duties include, but are not limited to:
- Developing, implementing, and monitoring a strategic, comprehensive enterprise information security and IT risk management program;
- Assisting resource owners and IT staff in understanding and responding to security audit failures reported by auditors;
- Ensuring audit trails, system logs, and other monitoring data sources are reviewed periodically to ensure compliance with policies, audit requirements, and regulatory standards;
- Designing, coordinating, and overseeing security testing procedures to verify the security of systems, networks, and applications, and manage the remediation of identified risks;
- Developing and enhancing an information security management framework;
- Creating, maintaining, and enforcing security policies, standards, procedures, controls, and guidelines that meet State and Federal requirements;
- Leading incident response activities, including detection, analysis, containment, eradication, recovery, documentation, and notifications; oversee and coordinating the CSIRT;
- Conducting and coordinating vulnerability assessments, security testing, and risk remediation efforts; manage continuous threat and vulnerability management operations;
- Guiding development, testing, and maintenance of disaster recovery and business continuity plans;
- Overseeing identity and access management governance, including access reviews, certifications, and privileged accmanagingount monitoring;
- Developing, maintaining, and measuring the effectiveness of the agency's cybersecurity awareness program, including phishing, smishing, vishing, and other human-factor risk reduction initiatives; and
- Providing leadership to the enterprise's information security organization and participating in strategic technology planning and governance.
Required Knowledge, Skills, and Abilities:- Knowledge of distributed processing operations, software, procedures, and equipment;
- Knowledge of Information Security, principles, and best practices;
- Knowledge of problem-solving techniques;
- Knowledge of computers and software;
- Knowledge of the principles, practices, and techniques of computer systems analysis;
- Knowledge of the principles of networking and telecommunication;
- Knowledge of telecommunications principles, equipment, procedures, and terminology;
- Knowledge of audit procedures;
- Knowledge of the principles of cryptography and cryptanalysis;
- Knowledge of application and system technology security testing;
- Ability to develop and maintain policies, procedures, standards, and guidelines;
- Ability to process information logically and solve problems;
- Ability to develop training programs related to distributed processing operations and procedures;
- Ability to monitor, troubleshoot, and resolve problems with distributed computer systems components;
- Ability to identify and define user needs;
- Ability to communicate effectively;
- Ability to establish and maintain effective working relationships with others;
- Ability to prioritize, plan, organize, and coordinate work assignments;
- Ability to author technical reports; and
- Ability to analyze security requirements and relate them to the appropriate security controls.
Minimum Qualifications:- Four (4) years of information security experience with at least three (3) years responding to security incidents; OR
- An associate's degree from an accredited college or university and two (2) years of experience responding to security incidents.
- One (1) year of experience managing security projects, efforts, or teams.
- Experience with various regulatory requirements, laws, and security frameworks, such as NIST, ISO 27001, PCI DSS, HIPAA, HITECH, SOX, GDPR, CCPA, CIS, or SOC 2.
- Ability to manage a project, internal/external contractors' team, vendors, budget, and initiatives.
Preferred Qualifications, not required:- A bachelor's degree from an accredited college or university in information technology, computer engineering, business administration or a related field.
- Industry recognized certifications such as: CISSP, CISM, CCSP, OSCP, CEH/CND, CySA+, Sec+, or related GIAC certification.
- Experience securing cloud environments like Microsoft Azure, Amazon Web Services, or Google Cloud Platform.
- Experience with firewalls and IAM/PAM systems and vendors.
Where you will work:This position is located in Tallahassee, Florida. This is not a telework position.
Applicants are required to apply through the People First system by the closing date, by applying online. All required documentation must be received by the closing date of the advertisement. If you have any questions regarding your application, you may call 1-877-562-7287.
Benefits of Working For The State of Florida:Working for the State of Florida is more than a paycheck. The state offers a comprehensive compensation package for our employees that features a highly competitive set of benefits including:
- Low premium health, dental, vision, life, and supplemental coverage options!
- Paid personal time that includes annual leave, sick leave, nine paid holidays, and one personal holiday!
- Paid administrative leave for mentoring, volunteering, voting, and more!
- Family planning support that includes adoption benefits and paid/unpaid leave options for family and medical responsibilities!
- Retirement plans that include employer contributions (For more information, visit www.myfrs.com)!
- Deferred compensation plans!
- FREE basic life insurance plus additional options for you, your spouse, and children!
- Flexible Spending Accounts!
- Tuition waivers!