Chief Information Security Officer (0933 Manager V) - Department of Public Health (San Francisco) Job at San Francisco Department of Public Health, San Francisco, CA

RlRSSVpvR3NjcS9zKzNmOXNHTnhjK29HR0E9PQ==
  • San Francisco Department of Public Health
  • San Francisco, CA

Job Description

Chief Information Security Officer (0933 Manager V) - Department of Public Health

Department Overview
The Department of Public Health prioritizes equitable and inclusive access to quality healthcare for its community and values the importance of diversity in its workforce. All employees work to advance equity, inclusion, and diversity with a specific lens and focus on race, ethnicity, gender, sex, sexuality, disability, and immigration status.

Role Summary

Role Description
The San Francisco Department of Public Health is seeking a dynamic and experienced cybersecurity professional to join its IT leadership team. The Chief Information Security Officer (CISO) will be responsible for developing and executing a comprehensive information security strategy that safeguards the departments systems, data, and services. The CISO leads the implementation of an enterprise-wide security program that promotes collaboration, strengthens governance, and aligns cybersecurity initiatives with organizational goals. The CISO serves as a trusted advisor to senior leadership, providing expert guidance on risk management, security investments, and policy development. The CISO oversees a team of cybersecurity professionals within the SFDPH IT division and collaborates extensively with the CISO for the City and County of San Francisco. The CISO reports directly to the Chief Information Officer (CIO).

Essential Functions

  • Provides strategic leadership in evaluating and mitigating information security threats across the organization using a structured, risk-based methodology. Advises executive leadership on identified risks and ensures timely execution of mitigation and remediation plans.
  • Directs the ongoing development of the departments information security program, including project portfolio management, incident response, policy frameworks, compliance activities, threat and vulnerability management, and thirdparty risk management.
  • Allocates and manages resources to support a robust security strategy. Identifies and advocates for strategic investments, oversees capital and operating budgets, and delivers ROI analyses and budget recommendations.
  • Partners with the Office of Compliance and Privacy Affairs to assess data security risks related to contracts, projects, artificial intelligence solutions, and other initiatives. Develops tools and interventions to mitigate risks, establishes performance metrics, and monitors compliance through audits and assessments.
  • Builds alignment and support for security goals and initiatives across internal and external stakeholders. Communicates effectively with leadership at all levels on trends, risks, and the overall effectiveness of the security program.
  • Promotes awareness and understanding of regulatory requirements across the organization. Leads or collaborates on testing and auditing activities to ensure ongoing compliance and successful certifications.
  • Analyzes security requirements and ensures compliance with industry standards such as HIPAA, NIST, and PCIDSS.
  • Establishes and maintains comprehensive policies and procedures to support effective and sustainable security operations.
  • Serves as the departments representative in securityrelated matters with City agencies and partners.
  • Continuously monitors emerging trends, technologies, and best practices in cybersecurity to ensure the departments security posture remains current and effective.

Qualifications

  • Education: Bachelors degree from an accredited college or university.
  • Experience: Five (5) years of professional healthcare information systems security experience, of which three (3) years must include supervising IT professionals.
  • Education substitution: Additional experience may be substituted for the required degree on a year-for-year basis. One (1) year is equivalent to thirty (30) semester units / fortyfive (45) quarter units.

Desirable Qualifications

  • Possession of a Certified Information Systems Security Professional (CISSP) and/or Certified Information Security Manager (CISM) certification.

How to Apply

All job applications for the City and County of San Francisco must be submitted through our online portal. Visit to begin your application process.

Equal Employment Opportunity

  • Information about the Hiring Process
  • Conviction History
  • Employee Benefits Overview
  • Equal Employment Opportunity
  • Disaster Service Workers
  • ADA Accommodation
  • Right to Work
  • Copies of Application Documents
  • Diversity Statement
  • Veterans Preference
  • Seniority Credit in Promotional Exams
#J-18808-Ljbffr

Job Tags

Full time, Work at office,

Similar Jobs

Tyson Foods

Security Guard - 2nd Shift - Waverly, NE Job at Tyson Foods

 ...SUMMARY This position is responsible for the physical security of the facility, including assignments to walking or stationary...  ...Security Officer Hours: Saturday/Sunday 6:00pm - 6:30am (Weekend night shift) Duties and Responsibilities: Checking identification... 

Cal Services

Experienced FedEx P&D Delivery Driver Job at Cal Services

 ...Join our team as an Experienced FedEx P&D Delivery Driver with a FedEx Ground Contractor. This role offers the opportunity to drive sprinter...  ...trucks, and straight trucks safely and efficiently. Ensure timely and accurate delivery of packages to local destinations.... 

RCM Healthcare Services

School Nurse / Licensed Vocational Nurse (LVN) or Registered Nurse (RN) Job at RCM Healthcare Services

 ...School Nurse / Licensed Vocational Nurse (LVN) orRegistered Nurse(RN) We are currently hiring Licensed Vocational Nurses (LVNs)and Registered Nurses (RNs)to join our dedicated school nursing team in Los Angeles. In this role, you will provide specialized care to... 

Rutland Regional Medical Center

Corporate Compliance Officer Job at Rutland Regional Medical Center

Corporate Compliance Officer The Corporate Compliance Officer is primarily responsible for leading the corporate compliance program, under the direction of leadership, including managing and implementing the compliance work plan, implementing necessary policies and procedures... 

Residence Inn - Lafayette, LA

Part Time Front Desk Agent Job at Residence Inn - Lafayette, LA

 ...Summary: We are looking for an experienced part time Front Desk Agent who will be responsible...  ...arithmetic functions using a calculator. Post charges to guest rooms and house accounts...  ...standing and movement throughout front office area* Periods of standing exceeding 50%...