Talent.com
Head of Cyber Risk and Compliance (Enterprise Technology Manager)

Head of Cyber Risk and Compliance (Enterprise Technology Manager)

City of San JoséSan Jose, CA, United States
1 day ago
Job type
  • Full-time
Job description

Head of Cyber Risk and Compliance (Enterprise Technology Manager) Job Description (Refined)

The City of San Joss Information Technology Department (ITD) is seeking an experienced and forward-thinking leader to serve as the Head of Cyber Risk and Compliance (Enterprise Technology Manager) with a focus on Governance, Risk, and Compliance (GRC), Identity and Access Management (IAM), and Risk Management. Reporting to the City Information Security Officer (CISO), this role provides senior-level leadership for cybersecurity governance, regulatory compliance, access control, and enterprise risk initiatives that safeguard City services, data, and critical infrastructure.

The Head of Cyber Risk and Compliance will play a critical leadership role in strengthening the Citys security governance structure, managing enterprise risks, and ensuring effective identity and access controls across the organization. This position requires a leader who can balance regulatory compliance, security best practices, and operational needs, while fostering a culture of accountability and resilience.

Key responsibilities

  • Representing the cybersecurity program in executive meetings, steering committees, and inter-agency collaborations.
  • Collaborate with external partners, including DHS CISA, FBI, and state agencies, on compliance, risk, and threat intelligence initiatives.
  • Promote Citywide cybersecurity awareness programs, with emphasis on governance, risk, and compliance accountability.
  • Lead the planning, execution, and delivery of complex cross-functional projects, ensuring alignment with organizational priorities and stakeholder expectations.
  • Lead enterprise risk assessments, threat modeling, and business impact analyses by establishing standardized frameworks to evaluate organizational risk posture and align findings with enterprise objectives.
  • Oversee cross-departmental collaboration to identify vulnerabilities, analyze threats, assess potential impacts, and translate results into actionable mitigation strategies that inform executive decision-making.
  • Oversee regulatory compliance initiatives, ensuring continuous audit readiness and timely fulfillment of reporting requirements to meet federal, state, and industry standards.
  • Provide governance and oversight to maintain adherence to applicable framework, regulatory and certification requirements.
  • Coordinate with internal and external auditors and deliver clear risk mitigation and compliance reporting to executive leadership and regulatory bodies.
  • Integrate risk management processes into City projects, procurement, and vendor engagements.
  • Collaborate with IT operations and emergency management teams on disaster recovery and business continuity planning.
  • Lead the Citys cybersecurity GRC program, ensuring alignment with frameworks such as NIST CSF, ISO 27001, CJIS, PCI DSS, and other applicable standards.
  • Develop, implement, and enforce Citywide cybersecurity policies, standards, and procedures.
  • Provide metrics and dashboards on risk posture, policy adoption, and compliance to executive leadership.
  • Direct the Citys IAM strategy, including identity lifecycle management, SSO, MFA, and PAM.
  • Ensure secure onboarding, offboarding, and RBAC across City departments.
  • Implement and govern Zero Trust principles to reduce insider and external access risks.
  • Partner with IT and business units to advance identity governance and automation.
  • Develop and maintain the enterprise Disaster Recovery Plan as well as information systems contingency plans for each system, with tabletop exercises as required.

Salary and schedule

Hybrid telework schedule is possible, subject to change. The City is currently on a 32-hour onsite workweek.

Salary Information : The final candidates qualifications and experience shall determine the actual salary. In addition to the starting salary, employees in the Enterprise Technology Manager (ETM) classification shall also receive an approximate five percent (5%) ongoing non-pensionable compensation pay.

  • Salary Range (including the 5% NPWI) : $170,679.60 $208,855.92
  • Minimum qualifications

    Education and Experience : Bachelors degree from an accredited college or university with coursework in computer science, information systems, business administration, or closely related field AND seven (7) years of experience managing, maintaining and implementing significant technology programs, computer system infrastructure and design, network operations, security design, application development and configurations and system / servicer administration, including a combination of five (5) years of supervisory and project personnel management experience, of which at least two (2) years should be supervisory experience over a technical team.

    Required Licensing : Possession of a valid State of California drivers license. Passing the San Jose Police Department (SJPD) background check is also a condition of employment.

    Other qualifications and competencies

  • Seven or more (7+) years of experience in information security and / or compliance (FISMA, SOX, PCI, HIPAA, etc.), risk management, including threat modeling, vulnerability assessment, and / or incident response.
  • Five or more (5+) years directly managing and leading cross-functional technical cybersecurity teams.
  • Strong knowledge of regulatory frameworks and standards applicable to government, including NIST CSF, NIST 800-53, CJIS, PCI DSS, and HIPAA.
  • Proven ability to ensure audit readiness, manage internal controls, develop and enforce policies, and oversee third-party risk management programs.
  • Ability to communicate security-related concepts to a broad range of technical and non-technical audiences.
  • Experience with cloud security, secure network architecture, IAM operations, and authentication protocols (SAML, SSO, LDAP, OAuth, OpenID).
  • Possess and maintain a current cybersecurity credential (e.g., CISSP, CISA, CISM, CGEIT, CRISC) or equivalent acceptable to the City.
  • Ability to obtain and maintain SECRET Security Clearance within a reasonable period.
  • Selection process and contact

    The selection process includes evaluation of the applicants training and experience, responses to job-specific questions, and may include interviews and a practical / writing exercise. For questions about duties or the hiring process, contact Tram Nguyen at Tramt.Nguyen@.

    Employment eligibility : Federal law requires verification of eligibility to work in the United States. The City will not sponsor visa applications. Please answer all job-specific questions to be considered.

    The City of San Jos is an equal opportunity employer. Applicants are considered without regard to age, race, color, religion, sex, national origin, sexual orientation, disability, veteran status or any other unlawful consideration. Reasonable accommodations are available for applicants with disabilities.

    For more information on the Citys values and ITD culture, visit the ITD website.

    Note : Some boilerplate and extraneous postings have been removed to focus on the Head of Cyber Risk and Compliance (Enterprise Technology Manager) role and related requirements.

    #J-18808-Ljbffr

    Create a job alert for this search

    Head Of Compliance • San Jose, CA, United States

    Related jobs
    • Promoted
    Senior Enterprise Risk Manager

    Senior Enterprise Risk Manager

    LambdaSan Francisco, CA, United States
    Full-time
    We are seeking a Senior Enterprise Risk Manager to lead the design, execution, and oversight of our enterprise-wide risk management framework. You will partner with executives and business leaders t...Show moreLast updated: 4 days ago
    • Promoted
    Head of Governance, Risk and Compliance

    Head of Governance, Risk and Compliance

    Hippocratic AIPalo Alto, CA, United States
    Full-time
    Hippocratic AI has developed a safety-focused Large Language Model (LLM) for healthcare.The company believes that a safe LLM can dramatically improve healthcare accessibility and health outcomes in...Show moreLast updated: 4 days ago
    • Promoted
    Principal Engineer - Cybersecurity

    Principal Engineer - Cybersecurity

    Intuit Inc.Mountain View, CA, United States
    Full-time
    Do you take pride in protecting businesses and customers from evolving cyber threats? Join Intuit's Business Information Security Organization (BISO) to design and deliver the next generation of se...Show moreLast updated: 19 days ago
    • Promoted
    Head of Compliance, Americas

    Head of Compliance, Americas

    P2PSan Francisco, CA, United States
    Full-time
    FalconX is a pioneering team of operators, investors, and builders committed to revolutionizing institutional access to the crypto markets. Operating at the intersection of traditional finance and c...Show moreLast updated: 11 days ago
    • Promoted
    • New!
    Manager of Cyber Defense Engineering

    Manager of Cyber Defense Engineering

    Lumen TechnologiesSan Francisco, CA, US
    Full-time
    We are igniting business growth by connecting people, data and applications – quickly, securely, and effortlessly.Together, we are building a culture and company from the people up – committed to t...Show moreLast updated: 7 hours ago
    • Promoted
    Global Head of Scheme Compliance

    Global Head of Scheme Compliance

    AdyenSan Francisco, CA, United States
    Full-time
    Global Head of Scheme Compliance.Adyen provides payments, data, and financial products in a single solution for customers like Meta, Uber, H&M, and Microsoft - making us the financial technology pl...Show moreLast updated: 11 days ago
    • Promoted
    Head of Risk Management

    Head of Risk Management

    BitGoPalo Alto, CA, United States
    Full-time
    BitGo is the leading infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage.Since our foun...Show moreLast updated: 14 days ago
    • Promoted
    Head of Information Security

    Head of Information Security

    ConfidentialSan Francisco, CA, United States
    Full-time
    Join a top-tier telecommunications company that is committed to innovation and customer satisfaction.We are seeking a strategic and seasoned Head of Information Security to lead our cybersecurity i...Show moreLast updated: 2 days ago
    • Promoted
    • New!
    Senior Manager, Enterprise Risk Management

    Senior Manager, Enterprise Risk Management

    VisaSan Francisco, CA, United States
    Full-time
    Visa is a world leader in payments and technology, with over 259 billion payments transactions flowing safely between consumers, merchants, financial institutions, and government entities in more t...Show moreLast updated: 2 hours ago
    • Promoted
    Head of Risk (Non-Financial)

    Head of Risk (Non-Financial)

    Gemini Trust CompanySan Francisco, CA, US
    Full-time
    About the Company Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to ...Show moreLast updated: 4 days ago
    • Promoted
    Career Cyber Risk Management Engineer – Vulnerability Management

    Career Cyber Risk Management Engineer – Vulnerability Management

    Delta Dental Ins.San Francisco, CA, United States
    Full-time
    Career Cyber Risk Management Engineer – Vulnerability Management.Mission Street, 13th Floor, San Francisco, CA 94105; Telecommuting permissible from anywhere in the US. Bachelor’s degree or foreign ...Show moreLast updated: 1 day ago
    • Promoted
    Lead Principal - Governance Risk and Compliance

    Lead Principal - Governance Risk and Compliance

    Cloud Software Group, Inc.San Ramon, CA, United States
    Full-time
    We are seeking a highly skilled and experienced.Governance, Risk and Compliance team.The GRC specialist will play a critical role in managing and enhancing our Governance, Risk, and Compliance (GRC...Show moreLast updated: 11 days ago
    • Promoted
    Director of Cyber Security / IT Risk

    Director of Cyber Security / IT Risk

    RGPSan Francisco, CA, United States
    Full-time
    We are seeking a Director, IT Risk Assurance, with focus on cybersecurity and data privacy who will be responsible for supporting business development as well as leading, managing and, when necessa...Show moreLast updated: 1 day ago
    • Promoted
    Head of Risk (Non-Financial)

    Head of Risk (Non-Financial)

    GeminiSan Francisco, CA, United States
    Full-time
    Be among the first 25 applicants.Get AI‑powered advice on this job and more exclusive features.Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering ...Show moreLast updated: 12 days ago
    • Promoted
    Head of Security & Compliance

    Head of Security & Compliance

    PlaudSan Francisco, CA, United States
    Full-time
    Plaud is building the world's most trusted AI work companion for professionals to elevate productivity and performance through note-taking solutions, loved by over 1,000,000 users worldwide since 2...Show moreLast updated: 21 days ago
    • Promoted
    Manager - Technology Risk Consulting

    Manager - Technology Risk Consulting

    RSM US LLPSan Francisco, CA, United States
    Full-time
    We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their ful...Show moreLast updated: 4 days ago
    • Promoted
    Senior Cyber Risk Management Engineer

    Senior Cyber Risk Management Engineer

    Tranzeal IncorporatedSan Francisco, CA, United States
    Full-time
    Seeking a Senior Cyber Risk Management Capability Assessor to evaluate the effectiveness of cyber risk management capabilities, including policies, processes, and technical controls.This role will ...Show moreLast updated: 1 day ago
    • Promoted
    Head of Security and Compliance

    Head of Security and Compliance

    Staffing ScienceSan Francisco, CA, United States
    Full-time
    A rapidly growing technology company is seeking a.This individual will be the driving force behind achieving and maintaining. This is a highly visible and customer-facing role, ideal for someone who...Show moreLast updated: 28 days ago