Chief Information Security Officer Job in Boston 02116, Massachusetts US

Duties:

Provide strategic and operational direction for the MassDOT Security organization. Work closely with the Chief Information and Technical Officer and other members of the MASSDOT management team in establishing strategic tactical objectives, and defining operating policies and procedures necessary to achieve departmental objectives as they relate to Information Security practices. Establish and coordinate responsibilities and project assignments to direct reports and cross-functional teams assigned to Information Security projects and programs. Lead the annual Payment Card Industry audit and attestation process, while monitoring compliance and reporting quarterly to payment processor. Lead a team of Information Security specialists and interact with all functions of IT to assure compliance and adherence to policies and practices in Information Security.

Qualifications:

MINIMUM ENTRANCE REQUIREMENTS:

Applicants must have at least (A) five years of full-time, or equivalent part-time, supervisory or managerial experience in the particular specialty (i.e. scientific, professional, or technical) and (B) of which at least two years must have been in a managerial capacity. The above entrance requirements are to be used only for positions for which educational and/or experience requirements have not been established by the General Laws. Entrance requirements established for particular positions by law must be used.

SPECIAL REQUIREMENTS: Applicants must possess current licensure and/or registration requirements established for the performance of the duties of the position.

Preferred Qualifications:

-10+ years experience in Information Technology roles with progressive management technical responsibilities.
-At least 3 years experience in a Security leadership role with groups larger than 3.
- Exceptional project management experience with large (budget, staff, complexity) multi-faceted projects.
- Very strong, hands on technical expertise in the area of information security architecture, tools (SIEM, NAC, MDM), strategy, firewalls, intrusion detection remediation, and proxy management.
- Experience defining, implementation, and adherence of information security policies / procedures and standards (PCI DSS 2.0, Commonwealth Executive Orders, MassDOT Policies).
- Interpersonal and formal communications skills.
- At least 5 years experience in the architecture, design and implementation of network security solutions in a distributed “N” tier web based environment with legacy systems.
- Must have CISSP and/or CISM certification.

Comments:

Engineering Degree preferred