Description
The Ohio Turnpike & Infrastructure Commission is seeking an experienced Cybersecurity Manager to work in the Technology Department at our Administration Building in Berea, Ohio.
If you are interested in working with us, here is some of what we can offer you :
- Salary range for this position is $98,142.72- $119,162.94 commensurate with experience.
- Medical, Dental, Vision and Prescription Benefits with employee contributions
- Company paid Life, Optional Life, AD&D, and Supplemental Insurance offered
- Participation in the Ohio Public Employees Retirement System (OPERS)
- Voluntary Deferred Compensation Plan participation
- Tuition Reimbursement Program
- Complimentary Parking
The Ohio Turnpike & Infrastructure Commission provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.
Examples of Duties
Duties / Responsibilities
Responsible for the overall management of the Commission's cybersecurity program, PCI compliance, and adherence to the NIST cybersecurity framework to ensure the availability, integrity and confidentiality of informationOversee the establishment and maintenance of information security on an automated and continuous basis within the Technology Department and across the OTIC enterprise; lead strategic information security planning based on industry-standard best practices; achieve business goals by prioritizing defense initiatives and coordinating the evaluation, deployment, and management of current and future information security technologiesAuthor and maintain necessary cybersecurity documentation including policies, information security plans, standard operating procedures (SOPs), incident response plans, playbooks, diagrams, training material, and other cybersecurity related documentation; evaluate, analyze, and monitor compliance with policies, procedures, and internal control techniques related to cyber and information securityCoordinate and manage cybersecurity initiatives across the enterprise involving business units, technology, and vendors; communicate policies, procedures, security education and awareness to OTIC management and employeesCoordinate penetration tests, vulnerability assessments; conduct cybersecurity tabletop exercises; develop information security risk mitigation plan, including leading the security incident response team in prevention, investigation, mitigation and reporting activitiesCoordinate responses to security incidents, providing timely reports during the incident and response, as well as proposing solutions to anticipate, prevent or mitigate future incidentsPerforms any other duties as may be assigned by the Chief Information Officer or Technology ManagerTypical Qualifications
Major Work Characteristics
Fluent in current information security practices and methodologies to manage ongoing cybersecurity initiatives in an enterprise environment, PCI compliance, and the NIST cybersecurity framework.Stay up to date on the latest risks and threats to enterprise technology and networks, helping to protect agency users, systems and dataDefine problems, collect data, establish facts, create action and project plans and assist with resolving technical and project issuesCreate and maintain effective working relationships with a wide diversity of individuals in a variety of circumstancesMaintain exemplary communication skills both verbally and in writing on complex technical and non-technical mattersAssist with and participate in project activities as directed by the project managerAdapt quickly to changes in priority; prioritize tasks without direct supervisionSelf-motivated, proactive and attentive to detailMaintain security and confidentiality of data and informationMinimum Qualifications
Bachelor's degree in Computer Science, Information Security, Cybersecurity, Business, Information Systems, or related degree.A minimum of 5-10 years of cybersecurity experience is required, including managing compliance and security within an organization, planning and executing security policies, and standards development.Experience with the NIST cybersecurity framework, PCI compliance standards, and security and privacy controls are required.An information security or other similar technical certification, such as Certified Information Systems Security Professional (CISSP), is highly preferred.Proven experience in researching, organizing, writing, and presenting technical information.Exceptional interpersonal, oral, and written communication skills requiredSupplemental Information
Unusual Working Conditions
The work environment is typically an office setting but will require some tasks be completed from field locations.Must be able to travel to Turnpike facilities across the state and may on occasion be required to travel out of town.Employee may be required to be on-call 24 hours, 7 days a week to maintain operations; work involves sitting for prolonged periods of time.